Google Research has announced a next-generation Federated Learning system built on Trusted Execution Environments (TEEs) that provides externally verifiable central differential privacy guarantees. This architecture shifts client gradient computation to the server, allowing the server logic to be attested so operators no longer need to be trusted with raw data.

  • Devices encrypt training examples locally and pre-authorize access policies published in Sigstore’s Rekor transparency log.
  • A Key Management System using the RAFT consensus protocol releases keys only to workloads matching the policy.
  • A root TEE runs a Python training loop via Federated Language, delegating subtasks to worker TEEs while releasing only DP model weights.
  • Gboard launched English and Japanese next-word prediction models with stronger privacy guarantees and improved accuracy.
  • Training time is reduced from 1-2 months per model by parallelizing across machines, limited only by TEE resource availability.

The system allows external auditors to track every server workload a device could feed, ensuring that privacy-relevant logic remains hardcoded in the attested program.