Neural networks are vulnerable to adversarial attacks, and ensembles of random transformations have been proposed to defend against them. For real-time applications of neural networks, such as ...