Summary
Proposes a defense evolver that treats system prompts as genomes, tests them against the attack corpus, and breeds successful defenses together. The fitness landscape asymmetry is severe: an attack genome succeeds if it finds ONE vulnerability; a defense genome fails if it misses ANY. Attack fitness is disjunctive; defense fitness is conjunctive, making defense search exponentially harder.