Guarantees on learning depth-2 neural networks under a data-poisoning attack