The goal of the non-targeted attack is to slightly modify source image in a way that image will be classified incorrectly by generally unknown machine learning classifier.
The goal of the targeted attack is to slightly modify source image in a way that image will be classified as specified target class by generally unknown machine learning classifier.
The goal of the defense is to build machine learning classifier which is robust to adversarial example, i.e. can classify adversarial images correctly.