AI Briefing
KOSign in

Google Research Introduces TEE-Based Federated Learning System for Provably Private Training

·2026.10.02 09:00

Key point

Gboard has already adopted the new system, achieving faster training speeds and stronger privacy guarantees for next-word prediction models.

1 / 4

Details

Google Research has announced a new Federated Learning (FL) system that leverages Trusted Execution Environments (TEEs) to provide externally verifiable privacy guarantees. By shifting computation to the server, the system improves training speed, accuracy, and device coverage while ensuring that data anonymization is fully verifiable and auditable.

Architecture and Verification

The system coordinates four core operational concepts to ensure privacy and integrity:

  • Data upload: Client devices encrypt training examples and upload them, pre-authorizing an access policy that defines which TEE computations can process the data. These policies are published to a public transparency log.
  • KMS and policy verification: A Key Management System (KMS) cluster, using the RAFT consensus protocol, releases decryption keys only to server-side TEE workloads that match the published access policies.
  • Workload execution: A root TEE executes a Python training loop, delegating parallel tasks to worker TEEs. The logic is expressed using Federated Language, an open-source orchestration language derived from TensorFlow Federated.
  • Fault-tolerant recovery: The system saves a KMS-encrypted recovery state after each training round, allowing recovery from failures without leaking sensitive information.

Strengthening Privacy Guarantees

This new system addresses limitations in previous FL approaches by removing the need to trust the server operator. In earlier systems, external observers could not verify that data was never logged or inspected. The new TEE-based approach ensures that:

  • Only metrics and differentially private model weights are visible to workload operators.
  • Encrypted training data is decrypted and processed only within TEEs for a limited time.
  • Access policies are published to Rekor, a public transparency log, allowing external auditors to track all potential server-side workloads.
  • Binaries can be reproducibly built from open-source code in the Confidential Federated Compute repository.

Impact on Gboard

Gboard has deployed this system to launch English and Japanese next-word prediction models. The shift to server-side computation mitigates diurnal availability constraints, allowing for dynamic optimization of device participation schedules. This has resulted in significantly faster training times compared to the previous system, which often took 1-2 months due to device limitations. The new architecture also supports stronger privacy guarantees and improved model accuracy.

This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.

Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.