A formal proof shows no equivalence exists between adversarial risk and regularized risk in two-layer networks. Empirical results on Wide-ResNets confirm this impossibility persists in deeper, more expressive architectures.