Robustness of attack-resilient estimators