On the effectiveness of adversarial training against common corruptions