Membership inference & gradient leakage
Attacks that determine whether a record was in the training set, or reconstruct data from gradients — evidence that FL is not inherently private enough for regulated public services. Motivates secure aggregation and differential privacy.