{
  "metadata": {
    "forum_id": "HyMRUiC9YX",
    "review_id": "Bkl4MaqOnm",
    "rebuttal_id": "BJgtK89FCX",
    "title": "Exploring and Enhancing the Transferability of Adversarial Examples",
    "reviewer": "AnonReviewer1",
    "rating": 4,
    "conference": "ICLR2019",
    "permalink": "https://openreview.net/forum?id=HyMRUiC9YX&noteId=BJgtK89FCX",
    "annotator": "anno0"
  },
  "review_sentences": [
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 0,
      "text": "This paper addresses the problem of adversarial transferability, i.e. the ability that an adversarial example generated by one model can successfully fool another model.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 1,
      "text": "There are numerous papers on this topic recently, such as Fawzi'15, Liu'17, Dong'18, Athalye'18...",
      "suffix": "\n",
      "review_action": "arg_fact",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 2,
      "text": "The authors propose tot study two types of factors that might influence transferability: model-specific parameters and smoothness of loss surface for constructing adversarial examples.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 3,
      "text": "Two experimental studies are made for each influence factor from existing architectures.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 4,
      "text": "Another attack strategy aiming at smoothing the loss surface is proposed, an experimental evaluation shows the effectiveness of the proposed method.",
      "suffix": "\n\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 5,
      "text": "Pros",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 6,
      "text": "-the proposed experimental studies can be interesting to the community",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 7,
      "text": "-many interesting illustrations are provided.",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_positive"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 8,
      "text": "Cons",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 9,
      "text": "-The conclusions of the study were suggested by previous papers or are rather expected: adversarial transfer is not symmetric: Deep models less transferable than shallow ones, averaging gradient is better",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_originality",
      "polarity": "pol_negative"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 10,
      "text": "-I find the experimental studies a bit limited and I would expect larger studies which would have improve the interest of the paper.",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 11,
      "text": "-Only two influence factors are studied, again the paper would be more interesting with a more general study",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "Bkl4MaqOnm",
      "sentence_index": 12,
      "text": "The paper has an interesting potential but seems a bit limited in its present form.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    }
  ],
  "rebuttal_sentences": [
    {
      "review_id": "Bkl4MaqOnm",
      "rebuttal_id": "BJgtK89FCX",
      "sentence_index": 0,
      "text": "Thank you for the comments.",
      "suffix": "",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_social",
      "alignment": [
        "context_global",
        null
      ],
      "details": {}
    },
    {
      "review_id": "Bkl4MaqOnm",
      "rebuttal_id": "BJgtK89FCX",
      "sentence_index": 1,
      "text": "We provide the feedbacks below.",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_structuring",
      "alignment": [
        "context_in-rebuttal",
        null
      ],
      "details": {}
    },
    {
      "review_id": "Bkl4MaqOnm",
      "rebuttal_id": "BJgtK89FCX",
      "sentence_index": 2,
      "text": "- Indeed there are a huge number of papers on adversarial examples, but specifically only a small fraction  of them are",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          9
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Bkl4MaqOnm",
      "rebuttal_id": "BJgtK89FCX",
      "sentence_index": 3,
      "text": "about the  transferability of adversarial examples .",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          9
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Bkl4MaqOnm",
      "rebuttal_id": "BJgtK89FCX",
      "sentence_index": 4,
      "text": "Understanding why adversarial examples can transfer from one model to another model is a much harder problem, which is a rather unexplored area.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          9
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Bkl4MaqOnm",
      "rebuttal_id": "BJgtK89FCX",
      "sentence_index": 5,
      "text": "Indeed we do not provide a perfect explanation in this submission, however the factors we have considered and the well-designed numerical investigations could be helpful for future studies on this topic.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_sentences",
        [
          10,
          11
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Bkl4MaqOnm",
      "rebuttal_id": "BJgtK89FCX",
      "sentence_index": 6,
      "text": "In addition, the works Fawzi'15 and Athalye'18 did not talk about the issue of adversarial transferability.",
      "suffix": "\n\n",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_sentences",
        [
          1,
          9
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Bkl4MaqOnm",
      "rebuttal_id": "BJgtK89FCX",
      "sentence_index": 7,
      "text": "- Could you be more specific on what do you expect for \"larger studies\" and \"general study\u201d?  This will be helpful for improving our work.",
      "suffix": "",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_followup",
      "alignment": [
        "context_sentences",
        [
          10,
          11
        ]
      ],
      "details": {}
    }
  ]
}