These are the types of fun details that are totally going to be part of future history lessons (no matter which direction, positive or negative, all of this is heading towards).
Hardening production ML systems are going to be fun. I think exploiting ML will be the new kid on the block just like how we were introduced to XSS exploits. See https://github.com/cchio/deep-pwning
Trying to "harden" million-parameter models trained on a relatively small number of relevant examples will be a nightmare to make web security look easy.
Too bad... Vancouver/Whistler was an awesome place to have a conference, even if the weather was rainy and the skiing so-so. A NIPS too big to be hosted by anything but a mega-city sounds depressing.