Poisoning the Well: Can We Simultaneously Attack a Group of Learning Agents?