follows. R1, R4: The results are very specific to the particular model: Indeed it is the case that our theoretical results assume that data providers are constrained in l

Neural Information Processing Systems 

Firstly, we thank the reviewers for their valuable comments. Whilst it is not reasonable in practice to assume that data is sampled i.i.d. As previously stated, we believe our work forms a first step in achieving this goal. Note that SPGs are bilevel optimisation problems, which are, in general, NP-hard. R2: Why would the learner ever evaluate on both the manipulated and unmanipulated data in practice?: We believe that We believe that our theoretical model captures this dynamic.