Someone on reddit mentioned the possibility of an exploit using polymorphism for an unintended class to be serialized.
ClassSerialize
|
ClassPleaseDontSerialize: ClassSerialize
I will need to add a specific 'opt-out' attribute for children or an attribute property on the type declaring to ignore children for serialization.