{
  "metadata": {
    "forum_id": "H1g0piA9tQ",
    "review_id": "S1x0HKfqh7",
    "rebuttal_id": "S1xAN6UJT7",
    "title": "Evaluation Methodology for Attacks Against Confidence Thresholding Models",
    "reviewer": "AnonReviewer3",
    "rating": 3,
    "conference": "ICLR2019",
    "permalink": "https://openreview.net/forum?id=H1g0piA9tQ&noteId=S1xAN6UJT7",
    "annotator": "anno13"
  },
  "review_sentences": [
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 0,
      "text": "This paper proposes an evaluation method for confidence thresholding defense models, as well as a new approach for generating of adversarial examples by choosing the wrong class with the most confidence when employing targeted attacks.",
      "suffix": "\n\n",
      "review_action": "arg_structuring",
      "fine_review_action": "arg-structuring_summary",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 1,
      "text": "Although the idea behind this paper is fairly simple, the paper is very difficult to understand.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 2,
      "text": "I have no idea that what is the propose of defining a new evaluation method and how this new evaluation method helps in the further design of the MaxConfidence method.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_motivation-impact",
      "polarity": "pol_negative"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 3,
      "text": "Furthermore, the usage of the evaluation method unclear as well, it seems to be designed for evaluating the effectiveness of different adversarial attacks in Figure 2.",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_clarification",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 4,
      "text": "However, in Figure 2, it is used for evaluating defense schemes.",
      "suffix": "",
      "review_action": "arg_fact",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 5,
      "text": "Again, this confuses me on what is the main topic of this paper.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_clarity",
      "polarity": "pol_negative"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 6,
      "text": "Indeed, why the commonly used attack success ratio or other similar measures cannot be used in the case?",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_explanation",
      "aspect": "asp_substance",
      "polarity": "none"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 7,
      "text": "Intuitively, it should provide similar results to the success-failure curve.",
      "suffix": "\n\n",
      "review_action": "arg_other",
      "fine_review_action": "none",
      "aspect": "none",
      "polarity": "none"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 8,
      "text": "The paper also lacks experimental results, and the main conclusion from these results seems to be \"MNIST is not suitable for benchmarking of adversarial attacks\".",
      "suffix": "",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_result",
      "aspect": "asp_soundness-correctness",
      "polarity": "pol_negative"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 9,
      "text": "If the authors claim that the proposed MaxConfidence attack method is more powerful than the MaxLoss based attacks, they should provide more comparisons between these methods.",
      "suffix": "\n\n",
      "review_action": "arg_request",
      "fine_review_action": "arg-request_edit",
      "aspect": "asp_meaningful-comparison",
      "polarity": "pol_negative"
    },
    {
      "review_id": "S1x0HKfqh7",
      "sentence_index": 10,
      "text": "Meanwhile, the computational cost on large dataset such as ImageNet could be huge, the authors should further develop the method to make sure it works in all situations.",
      "suffix": "",
      "review_action": "arg_evaluative",
      "fine_review_action": "none",
      "aspect": "asp_substance",
      "polarity": "none"
    }
  ],
  "rebuttal_sentences": [
    {
      "review_id": "S1x0HKfqh7",
      "rebuttal_id": "S1xAN6UJT7",
      "sentence_index": 0,
      "text": "The main topic of the paper is how to evaluate models that use confidence thresholding.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_global",
        null
      ],
      "details": {}
    },
    {
      "review_id": "S1x0HKfqh7",
      "rebuttal_id": "S1xAN6UJT7",
      "sentence_index": 1,
      "text": "The primary purpose is to compare *defenses*. However, to justify the attack strategy that we propose to use, we also compare *attacks*. Specifically, we provide an experiment demonstrating that our attack actually is stronger than the baseline.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-criticism",
      "alignment": [
        "context_unknown",
        null
      ],
      "details": {}
    },
    {
      "review_id": "S1x0HKfqh7",
      "rebuttal_id": "S1xAN6UJT7",
      "sentence_index": 2,
      "text": "However, it is not really necessary to provide multiple experiments demonstrating that MaxConfidence is more powerful because the superiority of MaxConfidence is theoretically guaranteed.",
      "suffix": "",
      "rebuttal_stance": "dispute",
      "rebuttal_action": "rebuttal_reject-request",
      "alignment": [
        "context_sentences",
        [
          8,
          9
        ]
      ],
      "details": {
        "request_out_of_scope": true
      }
    }
  ]
}