Text this: 2N labeling defense method against adversarial attacks by filtering and extended class label set