Encoding Robustness to Image Style via Adversarial Feature Perturbations