let's look at this a little sceptically
So looking at this through a commentards cynical gaze all they have managed to do is make a classifier fail to classify something? /slowhandclap
I can do that without trying :)
If read the article correctly (all bullshit bingo no explanations) it works by submitting subtly iffy subjects for classification? Wasn't sure from the explanation if it's just one shot or it needs to be built up over time.
But let's look at workable real world scenarios.
1. Corrupt iPhoneX faceid - requires Physical access - you are screwed anyway.
2. Hijack any ML on a phone - requires at least dodgy App access - ie same as any other malware.
3. Hijack PC ML requires browser or app hijack.
So basically whilst the execution mechanism of the attack is novel the access mechanisms are the usual bog standard ones.
So this is just a novel injection style attack and the usual protections still apply.
Mark as interesting but ultimately low risk.