On the Effectiveness of Adversarial Training on Malware Classifiers