Adversarially Robust Generalization Requires More Data

Neural Information Processing Systems 

Even small perturbations can cause state-of-the-art classifiers with high "standard" accuracy to produce an incorrect prediction with high confidence.