NeurIPS 2019
Sun Dec 8th through Sat the 14th, 2019 at Vancouver Convention Center
The paper proposes to use substitute models to improve the query count of black box attacks. All the reviewers agreed that this is an interesting paper although the proposed approach lacks theoretical justification. We encourage the authors to properly discuss the potential cost of training reference models and discuss whether that will be too expensive for large data (e.g., ImageNet) in the final version.