It's fairly normal in crypto papers to express vulnerabilities and potential vulnerabilities in base two, as so many other bits of crypto, like key sizes, etc, are also expressed in that base.
He's questioning normalisation, not base. "Just over 2^30" is a bit more intuitive than "Just under ten times 2^27".
Because in the paper they tested the attack with 1x2^27 requests, then with 2x2^27 requests, then 3x2^27, etc etc.