@glassbottommeg @mcc That's the thing, though. The text models don't retain the expression of any text, just statistics on the probability of tokens following tokens.
So, yeah, you can do it - but a lot of people (dozens? hundreds? thousands?) have to use the same trick the same way, otherwise the model could never reproduce it.
@Dancer @mcc true, I guess there's kinda no way of effectively poisoning code. Since you can't introduce single pixel changes that do nothing to the image visually but corrupt the AI.