Comments on the main proof strategy
–Neural Information Processing Systems
We thank the reviewer for the insightful comments on the proof. We will clarify better in the main text notions like "overparamaterise" or "fully trained". We further evaluate the robustness of deep ensembles on a subset of the NNs employed in Section 5.3. Table 1: FGSM and PGD attacks on the network employed in Section 5.2. For deterministic NNs Theorem 1 does not hold.
Neural Information Processing Systems
Feb-9-2026, 22:01:06 GMT
- Technology: