MPAF: Model Poisoning Attacks to Federated Learning based on Fake Clients