Review for NeurIPS paper: Adversarial Self-Supervised Contrastive Learning

Neural Information Processing Systems 

Weaknesses: I have several major concerns on the presentations of this paper: (1) The proposed transformation smoothed inference may cause gradient obfuscation, therefore Expectation of Transformation [1] should be used to properly attack this model. Also, the details of transformation smoothed inference are missing, e.g., what transformations are used? Nonetheless, I am pretty confused about the discussion there. First of all, I am pretty confused about what comparisons are conducted there? The only useful information I found is "Compared to the semi-supervised learning methods, RoCL takes about 1/4 times faster with the same computation resources", but how about comparisons on other metrics, e.g., robustness, accuracy?