Robustness to Adversarial Perturbations in Learning from Incomplete Data