Attacking the Madry Defense Model with $L_1$-based Adversarial Examples