If that became popular, the AIs would learn how to generate a realistic depth map along with any generated image.
The photos are cryptographically signed in the apple image pipeline so it's not as simple as just AI generating something. That said, I can't see how this is any different to all the other times we have embedded crypto keys in consumer hardware where eventually someone finds a way to extract the key and the whole thing is busted open.
> generate a realistic depth map along with any generated image.
There are already pretty good depth map generation algorithms (for a decade or so) which works on 2D images.
Generate the image, feed it to a depth map generator, viola.
However, you can't get it signed by the sensor itself. That'd be hard.
Even simpler, a 3D printed relief with an image "stamped" on it, now you effectively have a 3D image.
How would that work? I thought the premise here is that you can fool the apple camera by taking a (very carefully aligned) picture of a still image (printed out).
A depth map from the apple camera (again, signed) would show that the entire image had the same distance from the camera.