Randomization matters How to defend against strong adversarial attacks