On the Adversarial Robustness of Out-of-distribution Generalization Models