But it feels like you’d need to demonstrate this with some construction that’s actually adversarially robust, which seems difficult.
I agree it’s kind of difficult.
Have you seen Nicholas Carlini’s Game of Life series? It starts by building up logical gates up to a microprocessor that factors 15 in to 3 x 5.
Depending on the adversarial robustness model (e.g. every second the adversary can make 1 square behave the opposite of lawfully), it might be possible to make robust logic gates and circuits. In fact the existing circuits are a little robust already—though not at the tune of 1 square per tick, that’s too much power for the adversary.
On Chrome on a Mac you can just C-f in the PDF, it just OCRs automatically. I didn’t have this problem.