NeurIPS 2020

On Adaptive Attacks to Adversarial Example Defenses

Meta Review

his paper designs adaptive attacks to many adversarial defenses and demonstrates that 13 recent defenses are actually vulnerable to adaptive attacks. The original reviews were mixed - e.g., there were concerns on the systematic design/choice of the defenses and the analysis on the experimental findings. However, after several rounds of discussions (the authors also did a good job in rebuttal). the reviewers tend to agree that this paper has its value although being not perfect. So, the final recommendation is to accept the paper to NeurIPS.