A Constraint-Enforcing Reward for Adversarial Attacks on Text Classifiers