Complete AI Training

AI news ·

Google announces a federated learning system with externally verifiable privacy guarantees

Google deployed a federated learning system using Trusted Execution Environments to train Gboard models with externally verifiable privacy guarantees. Training time dropped from one to two months per model to a speed limited only by server-side TEE resources.

Share

Google has deployed a new Federated Learning (FL) system that shifts computation to the server and uses Trusted Execution Environments (TEEs) to provide externally verifiable privacy guarantees. The system, detailed in a paper published October 2, 2026, is already training next-word prediction models for Gboard with stronger privacy protections and faster training times than the company's previous FL infrastructure.

The new design addresses a persistent tension in federated learning: how to prove to outside auditors that uploaded device data is never logged or inspected. Earlier systems relied on trust in the server operator, or used cryptographic protections that were incompatible with the strongest differential privacy (DP) techniques. The TEE-based approach lets external verifiers inspect the exact code running on Google's servers, confirming that data is processed exactly as described and that only anonymized results are released.

How the TEE-based system works

The system coordinates four operational components. Client devices encrypt training examples locally and upload them with a pre-authorized access policy that specifies which TEE computations can process the data. A Key Management System, built on a cluster of TEEs running the RAFT consensus protocol, only releases decryption keys to server-side workloads that match the access policy. A root data processing TEE then executes the training loop, delegating parallelizable subtasks to worker TEEs. At the end of each round, the program saves an encrypted recovery state to handle intermittent failures without leaking additional information.

All access policies are published to Rekor, a public transparency log, so external auditors can track the full set of server-side workloads that devices might participate in. The KMS and data processing binaries can be reproducibly built from open source code in the Confidential Federated Compute repository. To protect proprietary model architectures while preserving auditability, the TEEs support sideloading serialized information at runtime - as long as all privacy-relevant logic remains hardcoded in the Python program, strong verifiable guarantees hold.

Practical gains for Gboard models

Gboard has used the new system to launch English and Japanese next-word prediction models. Training times dropped substantially. In the previous FL system, training could take one to two months per model, constrained by device availability, on-device compute, and competition for device resources. By collecting all uploads before running server-side training and parallelizing computation across many machines, bottlenecks shifted to the server. The only current limitation is TEE resource availability.

The system also mitigates problems caused by diurnal variations in device availability. Because the server can dynamically calculate the optimal device participation schedule at execution time, the team achieved stronger DP guarantees with smaller noise multipliers. In experiments training an English next-word prediction model for 5,000 rounds with cohorts of 6,500 devices, the new system produced measurably better privacy-utility tradeoffs.

Expanding beyond FL training

The infrastructure can execute arbitrary Python workloads in a verifiable manner, not just FL training loops. Google researchers are experimenting with synthetic data generation and exploring combinations with other specialized data processing TEEs, including those designed for LLM inference. The team also expects future TEE hardware and ongoing research into mitigating side-channel observations to offer deeper protections against malicious server-side attacks. "We anticipate that systems like ours may one day come with full proofs of correctness of the software implementations of the DP algorithms and system components," the authors write.

Why this matters for research, government, and regulated sectors

For organizations that handle sensitive data - healthcare systems, government agencies, legal firms, and research institutions - the ability to train machine learning models without exposing raw data has long been appealing in theory but difficult to verify in practice. This work demonstrates that externally auditable privacy guarantees can coexist with production-scale model training. The combination of public transparency logs, reproducible builds, and TEE-based execution provides a template for how institutions might one day collaborate on shared models while offering regulators and the public proof that individual records were never exposed. The code and whitepaper are available for review, allowing security and privacy teams to evaluate the approach against their own compliance requirements.

Share