Learning a subspace for clean signals can effectively suppress adversarial perturbations, improving model robustness.