That's the point of the challenge: "are there unknown properties of models allowing us to construct a poison for any network given enough input-output pairs".
The very point of CS as an academic discipline is _generalization_.