On the Robustness of Split Learning against Adversarial Attacks