In a lot of adversarial input stuff for AI, you're trying to get the AI to misclassify something, not necessarily to damage the AI or even change its learning at all. In Snow Crash the perceptions were definitely damaging to the perceivers, but I don't think you have to go nearly that far to have adversarial inputs!
The damage in Snow Crash just happened to be more severe than "short-term distress followed by periodic unsettlement".
Snow-crash is the first example I know of, of the attack being condensed to a bitmap and experienced solely through the optic nerve and subsequently and substantially condensed in the time domain.
Typically the sort of results of an adversarial attack against a human neural network similar to one described in snowcrash is more indicative of long term and repeated exposure to adversarial stimulus that usually starts at birth and last through sometimes as late as adulthood. Snowcrash condenses this effect and that’s whats striking and interesting.
To elaborate, the sort of adversarial attack’s I’m thinking of, are: indoctrination; gaslighting; cycles of abuse (a very nasty one that can go on for generations!); just about anything in the cia psy-ops manual, oh and I shouldn’t leave off entrapment (that’s a fun one).
Apart from psychological manipulation, of course―as already noted in another comment.