Borrowed machinery that doesn't fully transfer, and says so

Borrowed machinery rarely fits perfectly, and this paper says so out loud every time it happens. A GAN-inspired defense assumes both sides are equally capable, an assumption that quietly breaks once one side is a reward-seeking agent rather than a classifier.

Five imports get this treatment, adversarial reward functions, counterexample resistance, adversarial blinding, bounded exploration, and the generalized method of moments, and each stop names the exact place the transplant quits transferring cleanly.

Concrete Problems repeatedly imports off-the-shelf machinery from adjacent fields as a candidate safety mechanism, and its own prose flags exactly where the transplant doesn't carry over cleanly. Generative adversarial networks inspire adversarial reward functions but the symmetric-capability assumption behind GANs has no analogue once one side is a reward-seeking agent. Adversarial examples motivate counterexample resistance but cover only the abstract-rewards slice of reward hacking. Adversarial blinding borrows from a different corner of adversarial ML entirely, domain-invariance training rather than robustness training, despite sitting next to counterexample resistance in the same list. Bounded exploration borrows its worst-case framing from H-infinity control without the paper spelling out the analogy. The generalized method of moments generalizes the single worked example that founds partially specified models. In every case, the import is real but partial, and the gap is the more informative half.