The Consistency of Adversarial Training for Binary Classification