Improving Transformation-based Defenses against Adversarial Examples with First-order Perturbations