Review for NeurIPS paper: On the Loss Landscape of Adversarial Training: Identifying Challenges and How to Overcome Them

Neural Information Processing Systems 

Weaknesses: - What is the definition of error and robust error? Is it just 1-accuracy or something else? - Proposition 1 and its proof are not clear to me. In particular, the paragraph after Prop. 1 is confusing. You haven't yet even defined g_\eps(x, W), and it's unclear to me why the version space V_\eps is defined in terms of g_\eps(x,W). Can't we simply define the version space as a function of x and W rather than including the nebulously defined function g_\eps?