Defending against Reverse Preference Attacks is Difficult