$\sigma$-zero: Gradient-based Optimization of $\ell_0$-norm Adversarial Examples