On the (Im)Possibility of Private Machine Learning through Instance Encoding