Google advances federated learning with tees, enhancing privacy in gboard
Google Research has unveiled a new Federated Learning (FL) system that leverages Trusted Execution Environments (TEEs) to provide externally verifiable differential privacy. This innovation marks the first time FL has achieved such privacy guarantees.
The system shifts client gradient computation to the server, making the server logic attestable and reducing reliance on trust in the operator. Gboard now utilizes this system to enhance next-word prediction models in English and Japanese with stronger privacy and improved accuracy.
The system integrates four core components, including access policies published on Rekor, and ensures that all privacy-relevant logic remains hardcoded in the attested program. The design allows external auditors to track server workloads and verify that data is not logged or inspected.
This development builds on Google’s prior confidential federated analytics work and aims to address the trust gap in earlier FL systems. Sources include Google Research blog, Confidential Federated Compute repo, and NVIDIA FLARE docs. Verified on October 4, 2026.