
## Detecting Adversarial Examples Is (Nearly) As Hard As Classifying Them
Florian Tramer
Keywords: 
ICML/2022/Proceedings/16167 - Detecting Adversarial Examples Is (Nearly) As Hard As Classifying Them.pdf
Project URL: nan

### Implementation
_Given the documentation given by the authors on the method, how much time investment would it be to re-implement the method from scratch?_

[10]

The authors do not share their implementation. 

### Data
_Given the data description in the documentation, how much effort take to either: Find the same dataset the authors used, or similar datasets and defend the comparability, or acquire one from scratch?_

[5]

(3/3)

The authors use three public data sets. No details shared.

### Configuration 
_Given the (hyper)parameters, including semantic parameters, of the method: How much effort would it take to acquire the algorithm configurations used for their results, and compare against their budgetary constraints?_

[1]

The authors survey other works and share their configurations in table 1. 

### Experimental Procedure
_Given the experimental set-up of the work, how difficult is it to set up a new experiment, similar to those presented in the original work, with the same procedure?_

[3]

The authors provide the formula for their metric in equation 4 and in the caption of table 1. The results are single model/run. No details regarding training/test set.

### Expertise
_How much effort would it take to acquire the expertise required to reproduce the work independently relying on the available documentation?_

[6]

Requires expertise in robustness and adversarial attacks.
