No images are stored on relays. They're on separate media servers.
Something could slip through, but the relay feed is integrated into my client feed, so I tend to notice people misbehaving and block them in my mute list, and then block them on my relay.
I have an "add from follows" button for my whitelist and an "add from mutes" button for my blacklist. They could eventually auto-update, couldn't they? nostr:npub10npj3gydmv40m70ehemmal6vsdyfl7tewgvz043g54p0x23y0s8qzztl5h