Learning Universal Adversarial Perturbation by Adversarial Example