Significant paper. While it's not yet clear how well attacks designed with this method will transfer, this plausibly allows attackers to design poisons that (1) are not pointwise over the data (ie appear benign) and (2) potentially more robust to additional finetuning (ie rather than poison data s.t. a model has behavior X, an attacker can do poison data -> model is later fine-tuned -> model has behavior X).
See also:
https://x.com/smsampark/status/2043723640521597339