Research

Google Launches TEE-Based Federated Learning System

Google has introduced a new federated learning system that uses Trusted Execution Environments to shift computation to servers, accelerating training times while guaranteeing user privacy.

Google Research4 days agoResearch
Image: Google Research

Google Research has unveiled a next-generation federated learning system that utilizes hardware-based Trusted Execution Environments (TEEs) to offer verifiable data anonymization. By moving the heavy lifting of gradient computation from user devices to secure server-side TEEs, the system overcomes traditional bottlenecks like device battery, local processing power, and daily availability cycles. Gboard has already deployed this architecture to train its English and Japanese next-word prediction models, achieving significantly faster training times and improved accuracy.

The system coordinates four main operations: encrypted data upload, key management verification, workload execution, and fault-tolerant recovery. Client devices encrypt their data and pre-authorize an access policy, which is published to Rekor, a public transparency log. A Key Management System running a RAFT consensus protocol inside a TEE cluster only releases decryption keys to authorized workloads. The training loop runs via Federated Language, an open-source orchestration language derived from TensorFlow Federated. To demonstrate the system's efficiency, Google trained an English next-word prediction model for 5,000 rounds using cohorts of 6,500 devices, showing stronger privacy guarantees and smaller noise multipliers.

For machine learning practitioners, this architecture fundamentally changes the constraints of decentralized training. Previously, training federated models could take one to two months due to limited on-device resources and diurnal variations in device connection. Shifting computation to the server allows developers to train much larger models without taxing user hardware. Furthermore, the system supports dynamic sideloading of proprietary model architectures and preprocessing logic at runtime. This allows organizations to protect their intellectual property while keeping the core privacy-relevant code open, verifiable, and reproducible via the Confidential Federated Compute GitHub repository. Google is also experimenting with using this infrastructure for synthetic data generation and large language model inference.

This is our own summary of reporting by Google Research

More in Research