Goto

Collaborating Authors

 Performance Analysis



about real-world experiments and deep density models and then answer detailed comments and questions

Neural Information Processing Systems

We thank the reviewers for their very helpful comments and suggestions. The 100% recall but very poor precision (i.e., it always predicts a shift) is expected Marginal-KS is very bad because the attack model is very strong, i.e., it mimics the marginal distribution of Thus, marginal KS will naturally fail--highlighting the limitation of prior work for this adversarial attack. F or bootstrapping, does the model need to be fit multiple times? For Gaussian, this is fairly simple. For the detection stage, the FDR was controlled below 0.05 in all See also Table 6 and 7 in appendix.



Table 1 Additional experiments in terms of classification Accuracy

Neural Information Processing Systems

We thank the reviewers for their valuable comments. We will add suggested experiments, references, and fix typos in the updated version. Take the large-scale ImageNet as an example. A3: Please refer to Table 1a and A2@R#1 for additional results on ImageNet. We see that the weights on the diagonal are higher.