This might be the MIT paper Adversarial Examples are not Bugs, they are Features.
That is in fact what I meant :)
That is in fact what I meant :)