Why adversarial training can hurt robust accuracy