TLDRocket
Sign in

Google Research Moves Federated Learning Into TEEs: Gboard Now Trains With Externally Verifiable Differential Privacy

MarkTechPost Michal Sutter ● Covered by 2 sources

Google moved Gboard training into secure chip-like enclaves. That lets outsiders verify the privacy promises instead of just trusting them.

Based on reporting by MarkTechPost, Michal Sutter — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Google Research says it has rebuilt federated learning around trusted execution environments, or TEEs, and claims a first: externally verifiable central differential privacy for the system. That’s a big shift from the older setup, where devices uploaded data for immediate aggregation and everyone had to trust that nothing was logged or poked at along the way.

Federated learning has been doing real work at Google since 2017. It powers next-word prediction and Smart Compose in Gboard, reply suggestions in Google Messages, and Smart Text Selection in Android. The old privacy stack helped, especially with Secure Aggregation, but it hit a wall. It didn’t fit state-of-the-art central DP methods like matrix factorization DP-FTRL, and Google still had to be trusted to add the privacy noise correctly.

The new design pushes client gradient computation to the server, then makes that server logic attestable. Devices encrypt training examples locally and pre-authorize a specific access policy. That policy has to show up in Rekor, Sigstore’s public transparency log. A key management system built from TEEs running RAFT only releases keys to workloads whose attested code matches the policy. Inside the system, a root TEE runs a Python training loop and hands subtasks to worker TEEs, with Federated Language, derived from TensorFlow Federated, handling orchestration. Only differentially private model weights leave the enclave side.

Google says the same setup was used to launch English and Japanese next-word prediction models in Gboard, with stronger privacy guarantees and better accuracy. Two details matter here. First, uploads are gathered before server-side training starts, so the old drag from uneven device availability goes away and the system can pick an optimal participation schedule. Second, training moves onto the server and parallelizes across machines, with TEE capacity now the bottleneck instead of phones dribbling in over weeks.

Google trained the English model for 5,000 rounds with cohorts of 6,500 devices on both systems for its privacy-utility curves, and it says previous FL models often took one to two months each to train. The company reports much faster compute times on the new approach, but it does not give a single speedup number. That restraint is rare enough to be refreshing.

My take — AI-written commentary, not fact-checked reporting

This is the right kind of privacy story: boring, auditable plumbing instead of marketing confetti. The industry loves saying “trust us” and calling it security; here, at least, the receipts go into a public log. More model makers should be forced to do their privacy homework in daylight instead of behind a friendly logo.

Read more about this at: MarkTechPost

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.