Why would this be the case. Why would software output from a model magically have greater protection than the software the model trained on.