A common misconception: 'federated learning is private because the data never leaves the device.' Unfortunately, the model updates that clients send can themselves reveal information about the local data. Research has shown that gradients and model updates can be exploited to reconstruct training examples or to determine whether a specific person's data was used in training.
This motivates a layered view of privacy in FL. The first layer is the federated setting itself: raw data stays local. The second layer is secure aggregation: a cryptographic protocol that lets the server compute the sum of client updates without seeing any individual update. The third layer is differential privacy: carefully calibrated noise is added so that the final model provably reveals little about any single client's data.
Each layer has a cost. Secure aggregation adds communication and computation overhead and complicates handling clients that drop out mid-round. Differential privacy degrades model accuracy, and the trade-off between privacy budget and utility is one of the central tensions in applied FL.
The takeaway for now: FL is a privacy-enabling architecture, not a privacy guarantee. Whether a deployed system is actually private depends on which additional mechanisms are in place — a distinction that matters enormously when you read product claims or research papers.