On the Security of Machine Learning Beyond the Feature Space