Can AI really be protected from text-based attacks?