NeurIPS 2020

GreedyFool: Distortion-Aware Sparse Adversarial Attack

Meta Review

This paper proposes a method to generate L0 adversarial examples. The method is efficient and better than simple baseline attacks, but the evaluation is not thorough with respect to prior l0 attacks, and artificially weakens the comparison to PGD/CW by restricting the number of iterations. However, the reviewers by and large liked the paper and found the method useful. The rebuttal addressed many of the concerns and the updated paper likely will better reflect the novel contributions of the defense. The fact that this method is efficient, while still performing roughly on par with optimization attacks, indicates better optimization L0 attacks should be possible as well.