Research

Google Moves Gboard Federated Learning Into Secure TEEs

Google has moved its federated learning system for Gboard into Trusted Execution Environments, providing externally verifiable privacy guarantees while accelerating model training.

MarkTechPost2 days agoResearch
Image: MarkTechPost

Google Research has deployed a next-generation federated learning system built on Trusted Execution Environments (TEEs) to train Gboard's English and Japanese next-word prediction models. This architecture marks the first time a federated learning framework has achieved what Google calls "externally verifiable central differential privacy" guarantees. By shifting client gradient computations to attestable server-side TEEs, the system bridges a long-standing trust gap where users had to rely on Google to apply privacy protections correctly.

The new system coordinates four core components to secure user data. First, devices encrypt training examples locally under an access policy published to Rekor, Sigstore's public transparency log. Second, a Key Management System (KMS) built from TEEs running the RAFT consensus protocol releases decryption keys only to verified workloads. Third, a root TEE runs a Python training loop via Federated Language, a framework derived from TensorFlow Federated, delegating subtasks to worker TEEs and releasing only differential privacy model weights. Finally, each training round saves a KMS-encrypted recovery state to handle hardware failures.

This architectural shift addresses the limitations of previous federated learning setups, which took one to two months to train a single model. By collecting all encrypted uploads before server-side training begins, Google avoids diurnal swings in device availability. To demonstrate the system's utility, Google trained an English next-word prediction model for 5,000 rounds using cohorts of 6,500 devices. Training is now parallelized across server-side machines, shifting the bottleneck from user devices to TEE resource availability and yielding significantly faster compute times.

For AI practitioners, this development offers a blueprint for building highly secure, distributed training pipelines. Google has open-sourced the core TEE binaries and Federated Language under the Apache 2.0 license, allowing developers to inspect and reproduce the builds. Unlike simulation-only frameworks like Apple's pfl-research, or production SDKs like NVIDIA FLARE and Flower, Google's production-ready framework allows developers to protect proprietary model architectures by sideloading serialized logic at runtime while keeping all privacy-relevant logic hardcoded in the attested program.

This is our own summary of reporting by MarkTechPost

More in Research