It makes sense because the protective mechanism depends on the AI ingesting the picture as-is, with the added noise.
If the ingestion workflow alters the picture sufficiently, the protection could be lost, same as DRM qualities are lost if someone alters the data-stream by recording what is shown on the screen of the display device.