How adversarial attacks can disrupt seemingly stable accurate classifiers