Exploiting the Layered Intrinsic Dimensionality of Deep Models for Practical Adversarial Training