RoFL: Attestable Robustness for Secure Federated Learning