Images perturbed subtly to be misclassified by neural networks, called *adversarial examples*, have emerged as a technically deep challenge and an important concern for several application domains. Most research on adversarial examples takes as its …