Review for NeurIPS paper: DVERGE: Diversifying Vulnerabilities for Enhanced Robust Generation of Ensembles

Neural Information Processing Systems 

I congratulate the authors for taking simple ideas (namely, adversarially-motivated improvements to ensembles) and showing they work well. Ensembles are a strong baseline for uncertainty and natural out-of-distribution shift, and this work takes an important step further in highlighting the benefits of averaging multiple predictions for adversarial robustness. All reviewers found the paper well-written and convincing against baselines. As 3/4 reviewers stated, I recommend adding discussion making compute complexity more explicit. Finally, as R3 states and as promised in the revision, the paper is significantly lacking in discussion and citations of related work.