Robustness, Privacy, and Generalization of Adversarial Training