Steering a byte-CNN malware classifier to a benign verdict with an adversarial comment, then escaping a Java SecurityManager through the trusted MethodHandles lookup
Turning a CKKS Chebyshev sign oracle into a 50-bit binary search using ciphertext additions only, with exact rational interval tracking
Declaring an axiom to fabricate false proofs, turning Lean 4 proof-carrying array accessors into arbitrary memory reads, and forging a closure object to call readFile