Anti-adversarial machine learning defenses start to take root