{
  "metadata": {
    "forum_id": "HyMRUiC9YX",
    "review_id": "HkehbJYgnQ",
    "rebuttal_id": "HkliEwcY07",
    "title": "Exploring and Enhancing the Transferability of Adversarial Examples",
    "reviewer": "AnonReviewer3",
    "rating": 6,
    "conference": "ICLR2019",
    "permalink": "https://openreview.net/forum?id=HyMRUiC9YX&noteId=HkliEwcY07",
    "annotator": "anno10"
  },
  "review_sentences": [
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 0,
      "text": "Summary.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 1,
      "text": "The authors empirically investigate the influence of the architecture and the capacity of an NN-model on the transferability of adversarial examples.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 2,
      "text": "They also study the influence of the smoothness.",
      "suffix": "",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 3,
      "text": "From the obtained results, they propose the smoothed gradient attack showing improvements on the transferability of adversarial examples.",
      "suffix": "\n\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 4,
      "text": "Pros.",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 5,
      "text": "* Robustness of neural nets is a challenging problem of interest for ICLR",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 6,
      "text": "* The paper is well written",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 7,
      "text": "* The experimental study is convincing",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 8,
      "text": "* The experimental results for the smoothed gradient attacks are promising",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 9,
      "text": "Cons.",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 10,
      "text": "* The results of the experimental study are somehow expected",
      "suffix": "\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 11,
      "text": "* the idea of smoothing gradients is not new",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_originality",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 12,
      "text": "Evaluation.",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 13,
      "text": "The experimental study of the transferability of adversarial examples is well designed.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 14,
      "text": "Experimental protocol is convincing.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 15,
      "text": "The smoothed gradient attacks improve many previously proposed attacks.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_positive"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 16,
      "text": "Therefore, my opinion is rather positive. But, as a non expert in the field, I am not completely convinced by the novelty of the approach.",
      "suffix": "\n\n",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_originality",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 17,
      "text": "Some details.",
      "suffix": "\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_heading",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 18,
      "text": "Typos: That l8 abstract; systems l9 intro; and l2 related work; directly evaluation l2 Section4, must has l-10 p4;",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_typo",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 19,
      "text": "* the choice \\sigma = 15 in Section 6.2 should be justified by the following study",
      "suffix": "\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_experiment",
      "aspect": "asp_substance",
      "polarity": "pol_negative"
    },
    {
      "review_id": "HkehbJYgnQ",
      "sentence_index": 20,
      "text": "* \\sigma is not given in Figure 3(a)",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    }
  ],
  "rebuttal_sentences": [
    {
      "review_id": "HkehbJYgnQ",
      "rebuttal_id": "HkliEwcY07",
      "sentence_index": 0,
      "text": "Thank you for approving our contribution to understanding the transferability of adversarial examples.",
      "suffix": "\n\n",
      "rebuttal_stance": "nonarg",
      "rebuttal_action": "rebuttal_social",
      "alignment": [
        "context_global",
        null
      ],
      "details": {}
    },
    {
      "review_id": "HkehbJYgnQ",
      "rebuttal_id": "HkliEwcY07",
      "sentence_index": 1,
      "text": "We agree with that the smoothing gradient idea, especially the Gaussian smoothing technique, is not new, since the smoothing strategy could be used in many different scenarios.",
      "suffix": "",
      "rebuttal_stance": "concur",
      "rebuttal_action": "rebuttal_concede-criticism",
      "alignment": [
        "context_sentences",
        [
          11
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkehbJYgnQ",
      "rebuttal_id": "HkliEwcY07",
      "sentence_index": 2,
      "text": "However, we motivate and derive the idea of smoothing the gradient based on our novel understanding on the transferability of adversarial examples between two models.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_sentences",
        [
          11
        ]
      ],
      "details": {}
    },
    {
      "review_id": "HkehbJYgnQ",
      "rebuttal_id": "HkliEwcY07",
      "sentence_index": 3,
      "text": "To the best of knowledge, we are the first to derive and apply this technique to enhance the transferability of adversarial examples, whose significant improvement is also confirmed by our intensive experiments.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_sentences",
        [
          11
        ]
      ],
      "details": {}
    }
  ]
}