Once a detector is good, you can train a model to adjust its outputs to cause false negatives from the detector. Then the cycle repeats. It's a cat and mouse game basically.
The only proper way I see is a system that is based ob cryptographic signatures. This ia easier said than done ofc.
OMG this took me way too long to get. They replace the substring "ass" 😭😭