Reviews: A Fourier Perspective on Model Robustness in Computer Vision

Neural Information Processing Systems 

This paper explores a useful direction to study adversarial robustness and some experimental results add value to understanding this topic. Originality: The work seems original to me. Clarity: The presentation is mostly clear. Conversely, what are non-i.i.d ones? Do you mean training and test distributions are the same?