Apply randomization in KNN to make the adversary harder to attack the classifier | IEEE Conference Publication | IEEE Xplore