Adversarial examples within the training distribution: A widespread challenge