If someone wanted to buy it, I'm sure reality defender has protection especially because you can predict adversarial guesses.
It would be trivial for them to build "this user is sending progressively more realistic, rapid responses" if they haven't built that already.
Working in a similar area (bot detection) I think it's very difficult to proactively stop such targeted attacks, but maybe in this space you can do something interesting like duplicate detection across a consortium.
But what I find more interesting is how you prevent someone from training a model adversarially via one of your legitimate customers.
Wouldn't any of your customers that use your service to make a decision about something uploaded by a user be an attack vector?