[2205.10022] Towards Consistency in Adversarial Classification