Yes, these are “adversarial patches” in image classification, like https://arxiv.org/abs/1712.09665 . Similarly you can take these adversaries and add them to your own larger model, in an arms race.
I mean, “differential cryptanalysis” doesn’t go through AD, but I would be surprised if it’s not possible to get pretty close to a discrete analogue to AD using bit flips instead of differential and abstract interpretation.