NeurIPS 2020

Practical No-box Adversarial Attacks against DNNs

Meta Review

The proposed approach to crafting attacks is original and the experiments are convincing. Please provide more qualitative examples for several magnitudes of perturbation in the final supplementary to meet the reviewers' requests. NOTE FROM PROGRAM CHAIRS: For the camera-ready version, please expand your broader impact statement to discuss the potential negative impacts of your work, as well as possible mitigations. In particular, please explain whether you believe there are risks to describing a new adversarial attack method without also proposing a defense.