685bfde03eb646c27ed565881917c71c-AuthorFeedback.pdf

Neural Information Processing Systems 

Variance of 1/d is chosen so that the noise is of the same order as size of the domain, i.e., Gaussian distribution with variance 1/d is close to a uniform distribution over the unit ball. This clipping is done for ease of presentation and to ensure that no matter what the original distribution over X was, the Gaussian convolution has most of its density within the ball of radius 2. Qualitatively similar results can be achieved even without this clipping or with clipping to X which would be necessary if we restrict the adversary to only use instances in X.