Understanding Adversarial Robustness from Feature Maps of Convolutional Layers