On Breaking Deep Generative Model-based Defenses and Beyond