Understanding Generalization in Adversarial Training via the Bias-Variance Decomposition