[2408.10647] Privacy-preserving Universal Adversarial Defense for Black-box Models