If the neural network thinks a truck is a frog is it not recognising the vertical edges?
Seeing the intermediate layer images would be interesting to see where in the process it failed.
I keep thinking how kids often learn through labelled cartoon images. There the outline is more important.
Perhaps we could pre-train networks first on outlines of images. Make sure that these are capable of handling adversarial techniques and then build from there.