Vulnerability Under Adversarial Machine Learning: Bias or Variance?