It would be amazing if this could become the future, but as someone working in the adversarial robustness space I find it difficult to believe a system like this wouldn't be susceptible to adversarial patching...especially with whitebox access. It's been shown by Nicolas Carlini that nearly all adversarial defenses can be broken or are inherently flawed.
Very curious to see what makes this anti-spoofing algo different, will read the paper with interest.
Very curious to see what makes this anti-spoofing algo different, will read the paper with interest.