Research questionHow can we measure label-preserving adversarial vulnerability separately from ordinary misclassification in high-dimensional classifiers?High-dimensional classifiers can misclassify because they learn imperfectly from limited data, even without being vulnerable to meaningful perturbations. Separating these ordinary errors from perturbations that preserve the ground-truth label is necessary for interpreting adversarial sensitivity.