Revisiting character-level adversarial attacks