This means only images sent to me by friends should get through my SA rules so I wouldn't mind if I had some really harsh image rules as long as they let through images sent using everyday e-mail software.
Do you control the server? How is SA getting invoked?
I ask because with MIMEDefang it does some structural analysis (eg. MIME type and filename checking) before calling the heavy-weight SA, and you could block images with MD more cheaply than with the later SA pass.
