[2401.16352] Adversarial Training on Purification (AToP): Advancing Both Robustness and Generalization