Manipulating a Learning Defender and Ways to Counteract