OpenAI: Adversarial robustness does not transfer between perturbation types — defense evaluation must span multiple attack vectors | SignalBreak | SignalBreak