On the (Un-)Avoidability of Adversarial Examples