This reads like snakeoil and if I used it i’d definitely keep it in a VM.
Assuming it does what they claim i’m sure it’s a technical masterpiece but the pictures of today will be fed to the algorithms of tomorrow which are unlikely to have the same technical limitations or quirks this team is exploiting.
Given how machine learning interprets data, I wouldn’t be very surprised if it actually worked. There are dozens of examples online, how to easily confuse AI.
However problem you mentioned still prevails. New networks could simply use Fawkes edited images as learning data, to overcome it. We also don’t know what’s happens if edited picture get’s compressed. It could destroy whatever trick it’s using.