On the Robustness of Adversarial Training Against Uncertainty Attacks