Understanding Zero-Shot Adversarial Robustness for Large-Scale Models — arXiv2