Open davidstutz opened 5 years ago
For item 5 and checking section 5.6, I believe $f$ here is supposed to be the binary success/fail indicator for an attack on an image, while $X$ is the testing dataset, and $A$ is the set of attacks. The \mean\min formulation will take into account whether an image was misclassified by any of the attacks.
Hi,
first of all, I want to say that I enjoyed reading the paper and I think it’s a useful collection of best practices. I also like the “open” character of the paper, so I thought I would leave some comments and thoughts regarding the current ArXiv version of the paper.