{
  "metadata": {
    "forum_id": "HyMRUiC9YX",
    "review_id": "SJg6llgw2X",
    "rebuttal_id": "r1ltev9YCQ",
    "title": "Exploring and Enhancing the Transferability of Adversarial Examples",
    "reviewer": "AnonReviewer2",
    "rating": 6,
    "conference": "ICLR2019",
    "permalink": "https://openreview.net/forum?id=HyMRUiC9YX&noteId=r1ltev9YCQ",
    "annotator": "anno10"
  },
  "review_sentences": [
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 0,
      "text": "The paper explores how the architecture, smoothness of the decision boundary and test accuracy of a model impacts the transferability of examples produced from it.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 1,
      "text": "The paper provides a couple of novel insights, such as the asymmetry when transferring adversarial examples from one model to another.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 2,
      "text": "In addition, a novel method is proposed to enhance the transferability of adversarial examples from any model, through using smoothed gradients.",
      "suffix": "\n\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 3,
      "text": "The experiments seem to show that the effect is rather large, and also makes the examples more robust to other transformations such as JPEG compression.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 4,
      "text": "Overall, these are interesting insights that could lead to further developments in making models more robust to adversarial examples.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 5,
      "text": "In particular, deriving adversarial examples that are both transferable and resilient to certain usual image transformations shows that the scope of the issue with adversarial examples may be even greater than what is understood today.",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 6,
      "text": "The paper is rather clear.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_positive"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 7,
      "text": "Unfortunately, it is riddled with grammatical errors and should be proof-read carefully. A lot of singular/plurals are off, and some formulations are odd or downright unclear.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 8,
      "text": "Some examples (there are way too many to report them all):",
      "suffix": "\n\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 9,
      "text": "- \"Transfer-based attackS ... since they ...*",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 10,
      "text": "- \"of adversarial exampleS ...\"",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 11,
      "text": "- \"from model A can transfer to model B\"",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 12,
      "text": "- \"less transferable than *those from* a shallow model\"?",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 13,
      "text": "- \"investigations, We \": don't capitalize",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 14,
      "text": "- \"the averaging *has* a smoothing effect\"",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 15,
      "text": "- \"our motivation are\"",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 16,
      "text": "- \"contributed it to\"",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 17,
      "text": "- \"available *to the* adversary\"",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 18,
      "text": "- \"crafting adversarial perturbationS\"",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 19,
      "text": "- \"directly evaluation\"",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 20,
      "text": "- \"be fixed 100\"",
      "suffix": "\n\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 21,
      "text": "Pros:",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 22,
      "text": "- Transferability and robustness of adversarial examples is a very important problem",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 23,
      "text": "- Interesting insights, esp. the construction and evaluation of examples that are more resilient to certain image transformations",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_originality",
      "polarity": "pol_positive"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 24,
      "text": "- Experimental results are convincing",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_positive"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 25,
      "text": "Cons:",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 26,
      "text": "- Contribution overall may be a bit limited",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_negative"
    },
    {
      "review_id": "SJg6llgw2X",
      "sentence_index": 27,
      "text": "- Grammatical errors and odd formulations all over the place",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    }
  ],
  "rebuttal_sentences": [
    {
      "review_id": "SJg6llgw2X",
      "rebuttal_id": "r1ltev9YCQ",
      "sentence_index": 0,
      "text": "Thank you for the appreciation on the novelty of our paper.",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_social",
      "alignment": [
        "context_global",
        null
      ],
      "details": {}
    },
    {
      "review_id": "SJg6llgw2X",
      "rebuttal_id": "r1ltev9YCQ",
      "sentence_index": 1,
      "text": "- We have carefully proofread the manuscript and fixed the typos in the revised version. Could reviewer be more specific about the odd formulations, so that we can improve them?",
      "suffix": "",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_followup",
      "alignment": [
        "context_sentences",
        [
          27
        ]
      ],
      "details": {}
    }
  ]
}