Model-Targeted Poisoning Attacks: Provable Convergence and Certified Bounds