Review for NeurIPS paper: Towards More Practical Adversarial Attacks on Graph Neural Networks