https://arxiv.org/pdf/1412.6572.pdf taking the sign of the gradient with respect to its input provides a really computationally easy adversarial perturbation