Origins of Low-dimensional Adversarial Perturbations