Data overload
When the model is fed with faces maybe we should be feeding it generated fake faces instead of poisoned real faces.
There exist systems to generate fake faces. You can generate and publish many more fake faces than real faces exist. Each recognition program has a limited capacity to discriminate. That is the threshold you must reach. So, if 1 in 50 faces published online is a real face, then you reduce the chances of you being in the set. Generate a data overload by improving the generators.