Fine, then let's refer to the initial data collection/training as 'compilation attacks' going forward.
...or maybe we stop defaulting to adversarial paradigms for every conceivable situation.