Towards Better Understanding of Training Certifiably Robust Models against Adversarial Examples