{
  "metadata": {
    "forum_id": "Skgge3R9FQ",
    "review_id": "H1eqf5OA3m",
    "rebuttal_id": "BJeC2_Hspm",
    "title": "Controlling Over-generalization and its Effect on Adversarial Examples Detection and Generation",
    "reviewer": "AnonReviewer1",
    "rating": 4,
    "conference": "ICLR2019",
    "permalink": "https://openreview.net/forum?id=Skgge3R9FQ&noteId=BJeC2_Hspm",
    "annotator": "anno10"
  },
  "review_sentences": [
    {
      "review_id": "H1eqf5OA3m",
      "sentence_index": 0,
      "text": "The idea of having a separate class for out-distribution is a very interesting idea but unfortunately previously explored.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_originality",
      "polarity": "pol_negative"
    },
    {
      "review_id": "H1eqf5OA3m",
      "sentence_index": 1,
      "text": "In fact, in machine learning and NLP there is the OOV class which sometimes people in computer vision also use.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_originality",
      "polarity": "pol_negative"
    },
    {
      "review_id": "H1eqf5OA3m",
      "sentence_index": 2,
      "text": "Some of the claims in the paper can be further substantiated or explored.",
      "suffix": "",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "H1eqf5OA3m",
      "sentence_index": 3,
      "text": "For example in abstract there is a simple claim that is presented too strong: We also demonstrate that training such an augmented CNN with representative out-distribution natural datasets and some interpolated samples allows it to better handle a wide range of unseen out-distribution samples and black-box adversarial examples without training it on any adversaries.",
      "suffix": "",
      "review_action": "arg_fact",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "H1eqf5OA3m",
      "sentence_index": 4,
      "text": "This claim is bigger than just CNNs and needs to be studied in a theoretical framework not an empirical one.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_negative"
    },
    {
      "review_id": "H1eqf5OA3m",
      "sentence_index": 5,
      "text": "Also, one simple way to stop these adversarial cases would be to explore using Sigmoid as opposed to softmax.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_negative"
    },
    {
      "review_id": "H1eqf5OA3m",
      "sentence_index": 6,
      "text": "In general it is very unlikely that you will be able to choose every variation of out-distribution cases.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_negative"
    },
    {
      "review_id": "H1eqf5OA3m",
      "sentence_index": 7,
      "text": "Much easier if you just try to solve the problem using a set of n Sigmoids (n total number of classes) and consider each output a probability distribution.",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_negative"
    },
    {
      "review_id": "H1eqf5OA3m",
      "sentence_index": 8,
      "text": "However, the studies in this paper are still valuable and I strongly recommend continuing on the same direction.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    }
  ],
  "rebuttal_sentences": [
    {
      "review_id": "H1eqf5OA3m",
      "rebuttal_id": "BJeC2_Hspm",
      "sentence_index": 0,
      "text": "We appreciate the reviewer 1 for his/her feedback on our paper.",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_social",
      "alignment": [
        "context_global",
        null
      ],
      "details": {}
    },
    {
      "review_id": "H1eqf5OA3m",
      "rebuttal_id": "BJeC2_Hspm",
      "sentence_index": 1,
      "text": "The reviewer mentioned: \u201cIn general it is very unlikely that you will be able to choose every variation of out-distribution cases\u201d:",
      "suffix": "\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_structuring",
      "alignment": [
        "context_sentences",
        [
          6
        ]
      ],
      "details": {}
    },
    {
      "review_id": "H1eqf5OA3m",
      "rebuttal_id": "BJeC2_Hspm",
      "sentence_index": 2,
      "text": "Actually, for training A-CNN (Augmented CNN), we did not train it on every variation of out-distribution cases, rather, we recognize a single representative out-distribution set among the available ones according to our measurement.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_sentences",
        [
          6
        ]
      ],
      "details": {}
    },
    {
      "review_id": "H1eqf5OA3m",
      "rebuttal_id": "BJeC2_Hspm",
      "sentence_index": 3,
      "text": "Then using it for training A-CNN with the aim of effectively controlling over-generalization.",
      "suffix": "\n\n\n",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_sentences",
        [
          6
        ]
      ],
      "details": {}
    },
    {
      "review_id": "H1eqf5OA3m",
      "rebuttal_id": "BJeC2_Hspm",
      "sentence_index": 4,
      "text": "The reviewer mentioned: \u201c Also, one simple way to stop these adversarial cases would be to explore using Sigmoid as opposed to softmax\u201d:",
      "suffix": "\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_structuring",
      "alignment": [
        "context_sentences",
        [
          5
        ]
      ],
      "details": {}
    },
    {
      "review_id": "H1eqf5OA3m",
      "rebuttal_id": "BJeC2_Hspm",
      "sentence_index": 5,
      "text": "We would be appreciated if the reviewer could provide us with the references that showing using only sigmoid could control such a challenging problem of adversaries.",
      "suffix": "\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_followup",
      "alignment": [
        "context_sentences",
        [
          5
        ]
      ],
      "details": {}
    },
    {
      "review_id": "H1eqf5OA3m",
      "rebuttal_id": "BJeC2_Hspm",
      "sentence_index": 6,
      "text": "Please note we did not aim to devise a method that is able to reject all adversaries.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_sentences",
        [
          5
        ]
      ],
      "details": {}
    },
    {
      "review_id": "H1eqf5OA3m",
      "rebuttal_id": "BJeC2_Hspm",
      "sentence_index": 7,
      "text": "Rather, we attempted to show that a CNN with less over-generalization is able to reject some of the adversaries while correctly classifies many of the remainder, particularly non-transferable attacks.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_sentences",
        [
          5
        ]
      ],
      "details": {}
    }
  ]
}