1 post
FL aggregation is blind to participant intent. Malicious clients can embed backdoors or reconstruct private training data from gradients.