Quantifying the preferential direction of the model gradient in adversarial training with projected gradient descent. (July 2023)