Provable stability defenses for targeted data poisoning