The final guidance for defending against adversarial machine learning offers specific solutions for different attacks, but ...