{
  "metadata": {
    "forum_id": "HylTBhA5tQ",
    "review_id": "Hygsieas2X",
    "rebuttal_id": "rkxhfWj1C7",
    "title": "The Limitations of Adversarial Training and the Blind-Spot Attack",
    "reviewer": "AnonReviewer2",
    "rating": 7,
    "conference": "ICLR2019",
    "permalink": "https://openreview.net/forum?id=HylTBhA5tQ&noteId=rkxhfWj1C7",
    "annotator": "anno4"
  },
  "review_sentences": [
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 0,
      "text": "This paper provides some insights on influence of data distribution on robustness of adversarial training.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 1,
      "text": "The paper demonstrates through a number of analysis that the distance between the training an test data sets plays an important role on the effectiveness of adversarial training.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 2,
      "text": "To show the latter, the paper proposes an approach to measure the distance between the two data sets using combination of nonlinear projection (e.g. t-SNE), KDE, and K-L divergence.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 3,
      "text": "The paper also shows that under simple transformation to the test dataset (e.g. scaling), performance of adversarial training reduces significantly due to the large gap between training and test data set.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 4,
      "text": "This tends to impact high dimensional data sets more than low dimensional data sets since it is much harder to cover the whole ground truth data distribution in the training dataset.",
      "suffix": "\n\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 5,
      "text": "Pros:",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 6,
      "text": "- Provides insights on why adversarial training is less effective on some datasets.",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 7,
      "text": "- Proposes a metric that seems to strongly correlate with the effectiveness of adversarial training.",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_positive"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 8,
      "text": "Cons:",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 9,
      "text": "- Lack of theoretical analysis. It could have been nice if the authors could show the observed phenomenon analytically on some simple distribution.",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 10,
      "text": "- The marketing phrase \"the blind-spot attach\" falls short in delivering what one may expect from the paper after reading it.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 11,
      "text": "The paper would read much better if the authors better describe the phenomena based on the gap between the two distribution than using bling-spot.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 12,
      "text": "For some dataset, this is beyond a spot, it could actually be huge portion of the input space!",
      "suffix": "\n\n",
      "review_action": "arg_fact",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 13,
      "text": "Minor comments:",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 14,
      "text": "- I believe one should not compare the distance shown between the left and right columns of Figure 3 as they are obtained from two different models.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_negative"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 15,
      "text": "Though the paper is not suggesting that, it would help to clarify it in the paper.",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_edit",
      "aspect": "asp_clarity",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 16,
      "text": "Furthermore, it would help if the paper elaborates why the distance between the test and training dataset is smaller in an adversarially trained network compared to a naturally trained network.",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_edit",
      "aspect": "asp_clarity",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 17,
      "text": "- Are the results in Table 1 for an adversarially trained network or a naturally trained network?",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_clarification",
      "aspect": "asp_clarity",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 18,
      "text": "Either way, it could be also interesting to see the average K-L divergence between an adversarially and a naturally trained network on the same dataset.",
      "suffix": "\n",
      "review_action": "arg_fact",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "Hygsieas2X",
      "sentence_index": 19,
      "text": "- Please provide more visualization similarly to those shown in Fig 4.",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_edit",
      "aspect": "asp_clarity",
      "polarity": "none"
    }
  ],
  "rebuttal_sentences": [
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 0,
      "text": "Thank you for your insightful comments to help us improve our paper.",
      "suffix": "",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_other",
      "alignment": [
        "context_global",
        null
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 1,
      "text": "First of all, we would like to mention that we add more experiments on two additional state-of-the-art strong and certified defense methods, and observe that they are also vulnerable to our proposed attacks.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_done",
      "alignment": [
        "context_global",
        null
      ],
      "details": {
        "request_out_of_scope": true
      }
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 2,
      "text": "Please see our reply to all reviewers.",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_other",
      "alignment": [
        "context_in-rebuttal",
        null
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 3,
      "text": "Here are our responses to your concerns in \u201cCons\u201d and \u201cMinor comments\u201d.",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_structuring",
      "alignment": [
        "context_sentences",
        [
          8,
          13
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 4,
      "text": "Although we were not able to provide theoretical analysis in this paper, our proposed attacks are very effective on state-of-the-art adversarial training methods, and we believe our conclusions",
      "suffix": "\n",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          9
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 5,
      "text": "Currently, there is relatively few theoretical analysis in this field in general, and many analysis makes unpractical assumptions.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          9
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 6,
      "text": "We believe our results can inspire other researcher\u2019s theoretical research.",
      "suffix": "\n\n",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_mitigate-criticism",
      "alignment": [
        "context_sentences",
        [
          9
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 7,
      "text": "Regarding the \u201cblind-spot attack\u201d phrase, we are open to suggestions from the reviewers.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_concede-criticism",
      "alignment": [
        "context_sentences",
        [
          10
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 8,
      "text": "Other phrases we considered including \u201cevasion attack\u201d, \u201cgeneralization gap attack\u201d and \u201cscaling attack\u201d. Which one do you think is a better option?",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_followup",
      "alignment": [
        "context_sentences",
        [
          10
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 9,
      "text": "Regarding the distances in Figure 3:",
      "suffix": "\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_structuring",
      "alignment": [
        "context_sentences",
        [
          14,
          15,
          16
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 10,
      "text": "Thanks for raising this concern.",
      "suffix": "",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_social",
      "alignment": [
        "context_sentences",
        [
          14,
          15,
          16
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 11,
      "text": "We have added a note to clarify this issue.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_by-cr",
      "alignment": [
        "context_sentences",
        [
          14,
          15,
          16
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 12,
      "text": "The difference in distance can be partially explained by the sparsity in an adversarially trained model.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          14,
          15,
          16
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 13,
      "text": "As suggested in [1], the adversarially trained model by Madry et al. tends to find sparse features (see Figure 5 in [1]), where many components are zero.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          14,
          15,
          16
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 14,
      "text": "Thus, the distances tend to be overall smaller.",
      "suffix": "\n\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          14,
          15,
          16
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 15,
      "text": "Regarding the results in Table 1:",
      "suffix": "\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_structuring",
      "alignment": [
        "context_sentences",
        [
          17,
          18
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 16,
      "text": "In our old version, we only used the adversarially trained network.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          17,
          18
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 17,
      "text": "In our revision, we added K-L divergence computed from both adversarially trained and naturally trained networks.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_answer",
      "alignment": [
        "context_sentences",
        [
          17,
          18
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 18,
      "text": "Additionally, we also add a new distance metric proposed by AnonReviewer1.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_done",
      "alignment": [
        "context_sentences",
        [
          2
        ]
      ],
      "details": {
        "request_out_of_scope": true
      }
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 19,
      "text": "The K-L divergences by both networks, as well as the newly added distance metric, show similar observations.",
      "suffix": "\n\n",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_done",
      "alignment": [
        "context_sentences",
        [
          2
        ]
      ],
      "details": {
        "request_out_of_scope": true
      }
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 20,
      "text": "Regarding adding more visualizations:",
      "suffix": "\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_structuring",
      "alignment": [
        "context_sentences",
        [
          19
        ]
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 21,
      "text": "We added some more visualizations in Fig 10 in the appendix.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_done",
      "alignment": [
        "context_sentences",
        [
          19
        ]
      ],
      "details": {
        "request_out_of_scope": true
      }
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 22,
      "text": "It is worth noting that the Linf distortion metric used in adversarial training is sometimes not a good metric to reflect visual differences.",
      "suffix": "",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_other",
      "alignment": [
        "context_in-rebuttal",
        null
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 23,
      "text": "However, the test images under our proposed attack indeed have much smaller Linf distortions.",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_other",
      "alignment": [
        "context_in-rebuttal",
        null
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 24,
      "text": "We hope that we have answered all your questions, and we are glad to discuss with you if you have any further concerns about our paper.",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_social",
      "alignment": [
        "context_global",
        null
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 25,
      "text": "[1] Tsipras, Dimitris, et al. \"Robustness may be at odds with accuracy.\" arXiv preprint arXiv:1805.12152 (2018).",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_other",
      "alignment": [
        "context_in-rebuttal",
        null
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 26,
      "text": "Thank you!",
      "suffix": "\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_social",
      "alignment": [
        "context_global",
        null
      ],
      "details": {}
    },
    {
      "review_id": "Hygsieas2X",
      "rebuttal_id": "rkxhfWj1C7",
      "sentence_index": 27,
      "text": "Paper 1584 Authors",
      "suffix": "",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_other",
      "alignment": [
        "context_in-rebuttal",
        null
      ],
      "details": {}
    }
  ]
}