NeurIPS 2020

Diversity can be Transferred: Output Diversification for White- and Black-box Attacks

Meta Review

This paper proposes an efficient and decently general method for improving upon white and black box adversarial attacks, showing good empirical results. The reviews were initially a bit mixed, but thanks to an effective rebuttal and a satisfactory discussion between reviewers, a consensus emerged according to which the paper is undoubtedly of an acceptable standard for NeurIPS. I invite the authors to take special heed of the comments made by the reviewers (especially post-rebuttal comments by R3) in preparing the final version of this paper, as it seems like there is room for improvement based on the feedback given.