Efficacy of improving data with adversarially robust models

How well do these data improving techniques do when tested with adversarially robust models? Is there any difference?