On the Minimal Adversarial Perturbation for Deep Neural Networks with Provable Estimation Error