Third-year progress talk on building predictive models that are robust to adversarial attacks on tabular data. Frames adversarial attacks as software testing for machine learning models and shows why perturbations on tabular data are more noticeable than on images.