Re: So...
It's a bit more clever than that. I watermark the pictures, you use them to train a classifier (alongside other data), I can then see that your classifier was trained with these watermarked pictures. Classic steganography is I watermark the pictures and can later find the watermark because I know what I was looking for. In fact, it's almost anti-steganography, I'm silently teaching the classifier to recognise the watermark without you (the person who thinks they're training it) knowing, a bit like the apocryphal Russian-tanks scenario.