{
  "metadata": {
    "forum_id": "S1xcx3C5FX",
    "review_id": "HkeQCAq6hQ",
    "rebuttal_id": "B1xZ6uCaT7",
    "title": "A Statistical Approach to Assessing Neural Network Robustness",
    "reviewer": "AnonReviewer2",
    "rating": 6,
    "conference": "ICLR2019",
    "permalink": "https://openreview.net/forum?id=S1xcx3C5FX&noteId=B1xZ6uCaT7",
    "annotator": "anno12"
  },
  "review_sentences": [
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 0,
      "text": "Verifying the properties of neural networks can be very difficult.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 1,
      "text": "Instead of",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 2,
      "text": "finding a formal proof for a property that gives a True/False answer, this",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 3,
      "text": "paper proposes to take a sufficiently large number of samples around the input",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 4,
      "text": "point point and estimate the probability that a violation can be found.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 5,
      "text": "Naive",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 6,
      "text": "Monte-Carlo (MC) sampling is not effective especially when the dimension is",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 7,
      "text": "high, so the author proposes to use adaptive multi-level splitting (AMLS) as a",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 8,
      "text": "sampling scheme.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 9,
      "text": "This is a good application of AMLS method.",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 10,
      "text": "Experiments show that AMLS can make a good estimate (similar quality as naive",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 11,
      "text": "MC with a large number of samples) while using much less samples than MC, on",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 12,
      "text": "both small and relatively larger models",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 13,
      "text": ".",
      "suffix": "",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 14,
      "text": "Additionally, the authors conduct",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_originality",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 15,
      "text": "sensitivity analysis and run the proposed algorithm with many different",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_originality",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 16,
      "text": "parameters (M, N, pho, etc), which is good to see.",
      "suffix": "\n\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_originality",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 17,
      "text": "I have some concerns on this paper:",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 18,
      "text": "I have doubts on applying the proposed method to higher dimensional inputs.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 19,
      "text": "In",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 20,
      "text": "section 6.3, the authors show an experiments in this case, but only on a dense",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 21,
      "text": "ReLU network with 2 hidden layers, and it is unknown if it works in general.",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 22,
      "text": "How does the number of required samples increases when the dimension of input",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 23,
      "text": "(x) increases?",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 24,
      "text": "Formally, if there exists a violation (counter-example) for a certain property,",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 25,
      "text": "and given a failure probability p, what is the upper bound of number of samples",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 26,
      "text": "(in terms of input dimension, and other factors) required so that the",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 27,
      "text": "probability we cannot detect this violation with probability less than p?",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 28,
      "text": "Without such a guarantee, the proposed method is not very useful because we",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 29,
      "text": "have no idea how confident the sampling based result is.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 30,
      "text": "Verification needs",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 31,
      "text": "something that is either deterministic, or a probabilistic result with a small",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 32,
      "text": "and bounded failure rate, otherwise it is not really a verification method.",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 33,
      "text": "The experiments of this paper lack comparisons to certified verification",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 34,
      "text": "methods. There are some scalable property verification methods that can give a",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 35,
      "text": "lower bound on the input perturbation (see [1][2][3])",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 36,
      "text": ".",
      "suffix": "",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 37,
      "text": "These methods can",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 38,
      "text": "guarantee that when epsilon is smaller than a threshold, no violations can be",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 39,
      "text": "found.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 40,
      "text": "On the other hand, adversarial attacks give an upper bound of input",
      "suffix": "\n",
      "review_action": "arg_fact",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 41,
      "text": "perturbation by providing a counter-example (violation).",
      "suffix": "",
      "review_action": "arg_fact",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 42,
      "text": "The authors should",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_meaningful-comparison",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 43,
      "text": "compare the sampling based method with these lower and upper bounds.",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_meaningful-comparison",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 44,
      "text": "For",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_meaningful-comparison",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 45,
      "text": "example, what is log(I) for epsilon larger than upper bound?",
      "suffix": "\n\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_meaningful-comparison",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 46,
      "text": "Additionally, in section 6.4, the results in Figure 2 also does not look very",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 47,
      "text": "positive - it unlikely to be true that an undefended network is predominantly",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 48,
      "text": "robust to perturbation of size epsilon = 0.1. Without any adversarial training,",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 49,
      "text": "adversarial examples (or counter-examples for property verification) with L_inf",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 50,
      "text": "distortion less than 0.1 (at least on some images) should be able to find.",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_clarity",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 51,
      "text": "It",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 52,
      "text": "is better to conduct strong adversarial attacks after each epoch and see what",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 53,
      "text": "are the epsilons of adversarial examples.",
      "suffix": "\n\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 54,
      "text": "Ideas on further improvement:",
      "suffix": "\n\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 55,
      "text": "The proposed method can become more useful if it is not a point-wise method.",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_motivation-impact",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 56,
      "text": "If given a point, current formal verification method can tell if a property is",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_motivation-impact",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 57,
      "text": "hold or not.",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_motivation-impact",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 58,
      "text": "However, most formal verification method cannot deal with a input",
      "suffix": "\n",
      "review_action": "arg_fact",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 59,
      "text": "drawn from a distribution randomly (for example, an unseen test example).",
      "suffix": "",
      "review_action": "arg_fact",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 60,
      "text": "This",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_motivation-impact",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 61,
      "text": "is the place where we really need a probabilistic verification method.",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_motivation-impact",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 62,
      "text": "The",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 63,
      "text": "setting in the current paper is not ideal because a probabilistic estimate of",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 64,
      "text": "violation of a single point is not very useful, especially without a guarantee",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 65,
      "text": "of failure rates.",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 66,
      "text": "For finding counter-examples for a property, using gradient based methods might",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 67,
      "text": "be a better way.",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 68,
      "text": "The authors can consider adding Hamiltonian Monte Carlo",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_edit",
      "aspect": "arg_other",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 69,
      "text": "to",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_edit",
      "aspect": "arg_other",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 70,
      "text": "this framework",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_edit",
      "aspect": "arg_other",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 71,
      "text": "(See [4]).",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 72,
      "text": "References:",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 73,
      "text": "There are some papers from the same group of authors, and I merged them to one.",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 74,
      "text": "Some of these papers are very recent, and should be helpful for the authors",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 75,
      "text": "to further improve their work.",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 76,
      "text": "[1] \"AI2: Safety and Robustness Certification of Neural Networks with Abstract",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 77,
      "text": "Interpretation\", IEEE S&P 2018 by Timon Gehr, Matthew Mirman, Dana",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 78,
      "text": "Drachsler-Cohen, Petar Tsankov, Swarat Chaudhuri, Martin Vechev",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 79,
      "text": "(see also \"Differentiable Abstract Interpretation for Provably Robust Neural",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 80,
      "text": "Networks\", ICML 2018.",
      "suffix": "",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 81,
      "text": "by Matthew Mirman, Timon Gehr, Martin Vechev.  They also",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 82,
      "text": "have a new NIPS 2018 paper \"Fast and Effective Robustness Certification\" but is",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 83,
      "text": "not on arxiv yet)",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 84,
      "text": "[2] \"Efficient Neural Network Robustness Certification with General Activation",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 85,
      "text": "Functions\"",
      "suffix": "",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 86,
      "text": ", NIPS 2018. by Huan Zhang, Tsui-Wei Weng, Pin-Yu Chen, Cho-Jui",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 87,
      "text": "Hsieh, Luca Daniel.",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 88,
      "text": "(see also \"Towards Fast Computation of Certified Robustness for ReLU Networks\",",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 89,
      "text": "ICML 2018 by Tsui-Wei Weng, Huan Zhang, Hongge Chen, Zhao Song, Cho-Jui Hsieh,",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 90,
      "text": "Duane Boning, Inderjit S. Dhillon, Luca Danie.)",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 91,
      "text": "[3] Provable defenses against adversarial examples via the convex outer",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 92,
      "text": "adversarial polytope, NIPS 2018. by Eric Wong, J. Zico Kolter.",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 93,
      "text": "(see also \"Scaling provable adversarial defenses\", NIPS 2018 by the same authors)",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 94,
      "text": "[4] \"Stochastic gradient hamiltonian monte carlo.\" ICML 2014. by Tianqi Chen,",
      "suffix": "\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 95,
      "text": "Emily Fox, and Carlos Guestrin.",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 96,
      "text": "============================================",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkeQCAq6hQ",
      "sentence_index": 97,
      "text": "After discussions with the authors, they agree to revise the paper according to our discussions and my primary concerns of this paper have been resolved. Thus I increased my rating.",
      "suffix": "",
      "review_action": "arg_social",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    }
  ],
  "rebuttal_sentences": [
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 0,
      "text": "4. \"The experiments of this paper lack comparisons to certified verification",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 1,
      "text": "methods. There are some scalable property verification methods that can give a",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 2,
      "text": "lower bound on the input perturbation (see [1][2][3])",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 3,
      "text": ".",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 4,
      "text": "These methods can",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 5,
      "text": "guarantee that when epsilon is smaller than a threshold, no violations can be",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 6,
      "text": "found.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 7,
      "text": "On the other hand, adversarial attacks give an upper bound of input",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 8,
      "text": "perturbation by providing a counter-example (violation).",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 9,
      "text": "The authors should",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 10,
      "text": "compare the sampling based method with these lower and upper bounds.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 11,
      "text": "For",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 12,
      "text": "example, what is log(I) for epsilon larger than upper bound?\"",
      "suffix": "\n\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 13,
      "text": "The three references and the follow-up work that you cite give different methods for obtaining a certificate-of-guarantee that a datapoint is robust in a fixed epsilon l_\\infty ball, with varying levels of scalability/generality/ease-of-implementation.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 14,
      "text": "For those datapoints where they can produce such a certificate",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 15,
      "text": ", the minimal adversarial distortion is lower-bounded by that fixed epsilon.",
      "suffix": "\n\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 16,
      "text": "This is important work to be sure, but we view it as predominantly orthogonal to ours, for which we define robustness differently, as the \u201cvolume\u201d of adversarial examples rather than the distance to a single adversarial example.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 17,
      "text": "We actively argue that the minimal adversarial distortion is not a reliable measure of neural network robustness in many scenarios, as it is dictated by the position of a single violation, and conveys nothing about the amount of violations present.",
      "suffix": "\n\n",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 18,
      "text": "Despite these being two different definitions of robustness, to try and demonstrate some comparisons between the two, we extended experiment 6.4 (already using Wong and Kolter (ICML 2018) [3]) and compared the fraction of samples for which I = P_min to the fraction that could be certified by Wong and Kolter for epsilon in {0.1, 0.2, 0.3}. We found that it wasn\u2019t possible to calculate the certificate of Wong and Kolter for epsilon = 0.2/0.3 for all epochs, or epsilon = 0.1 before a certain epoch, due to its exorbitant memory usage.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 19,
      "text": "This significant memory gain thus indicates that our approach may still have advantages when used as a method for approximately doing more classical verification, even though this was not our aim.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 20,
      "text": "Please see the updated paper for full details.",
      "suffix": "\n\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          33,
          34,
          35,
          37,
          38,
          39,
          40,
          41,
          42,
          43,
          44,
          45
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 21,
      "text": "5. \"Additionally, in section 6.4, the results in Figure 2 also does not look very",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 22,
      "text": "positive - it unlikely to be true that an undefended network is predominantly",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 23,
      "text": "robust to perturbation of size epsilon = 0.1. Without any adversarial training,",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 24,
      "text": "adversarial examples (or counter-examples for property verification) with L_inf",
      "suffix": "\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 25,
      "text": "distortion less than 0.1 (at least on some images) should be able to find.\"",
      "suffix": "\n\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 26,
      "text": "You are correct that without any robustness training it is possible to find adversarial examples with distortion less than 0.1 for some inputs.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_concede-criticism",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 27,
      "text": "This is indeed what our results show in Figure 5 in the appendices, illustrating our metric for individual samples.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_future",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 28,
      "text": "You can see for several samples that were not initially robustness to eps=0.1 perturbations (log(I) > log(P_min)), the value of log(I) decreases steadily as the robust training procedure is applied.",
      "suffix": "\n\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 29,
      "text": "It does appear, however, that the network is predominantly robust to perturbations smaller than 0.1 before robustness training.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 30,
      "text": "The curves in Figure 3 plot the values of our measure log(I) between the 25th and 75th percentile for a number of samples.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 31,
      "text": "This shows that the network is already robust to perturbations of size eps=0.1 for more than about 75% of samples before the training procedure of Kolter and Wong is applied.",
      "suffix": "\n\n",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 32,
      "text": "All the same, we agree that the original Figure 3 was confusing in this respect, and have rerun this experiment with a lower minimum threshold for log(I) to make the point clearer in the graph.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_concede-criticism",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 33,
      "text": "With this lower value of log(P_min), we see the 75 percentile of log(I) over the samples quickly decrease as robustness training proceeds for eps=0.2.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 34,
      "text": "Notably, however, log(I) is incredibly small before any of this training for eps=0.1, demonstrating how it is important to not only think in terms of whether any violations are present, but also how many: here less the proportion of violating samples is less than 10^-100 at eps=0.1 for most of the datapoints.",
      "suffix": "\n\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          46,
          47,
          48,
          49,
          50
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkeQCAq6hQ",
      "rebuttal_id": "B1xZ6uCaT7",
      "sentence_index": 35,
      "text": "We thank Reviewer 1 for their critical appraisal and helpful suggestions.",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_social",
      "alignment": [
        "context_global",
        null
      ],
      "details": {}
    }
  ]
}