How robust accuracy suffers from certified training with convex relaxations