NeurIPS 2020

Input-Aware Dynamic Backdoor Attack

Meta Review

The reviewers for this paper are either on the fence about its merits or in favour of acceptance. While normally, this would make for a borderline paper, there are a few factors that give me confidence it is safe to include in the conference. All reviewers agree the method is novel, and the results and interesting. The outstanding concerns regarding the comparison are, I believe, decently addressed in the rebuttal. Even if they are not, the novelty of this method means it will at least provide solid grounds for discussion for people interested in adversarial and backdoor attacks. On the basis of the reviews, discussion, and rebuttal, I am happy to take a punt on an imperfect but interesting paper and recommend it is accepted. Pros: * Interesting and novel method * Impressive results * Room for improvement, but proves the concept