Interestana
Home/News/Google Research Integrates Federated Learning with TEEs
MarkTechPost••3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Google Research Integrates Federated Learning with TEEs

Google Research has unveiled a next-generation Federated Learning (FL) system that leverages Trusted Execution Environments (TEEs) to provide externally verifiable central differential privacy (DP) guarantees. This advancement addresses a significant trust gap in previous FL implementations, which were introduced by Google in 2017 to power features like next-word prediction and Smart Compose on Gboard, reply suggestions in Google Messages, and Smart Text Selection in Android. Previously, devices uploaded data for aggregation, but external parties could not verify that this data was never logged or inspected. While Secure Aggregation offered cryptographic protection, it was incompatible with advanced central DP algorithms such as matrix factorization DP-FTRL, and Google itself had to be trusted to implement DP noise correctly. The new system shifts client gradient computation to the server and makes this server logic attestable, thereby removing the need for operator trust. This TEE-based FL system builds upon Google’s prior confidential federated analytics work and integrates four core components. The process begins with data upload, where devices encrypt training examples locally and establish an access policy that specifies which TEE computations are permitted to process the data. These policies are recorded in a public transparency log. A Key Management System (KMS), itself built from TEEs running the RAFT consensus protocol, then releases encryption keys exclusively to workloads that match the defined policy. Workload execution involves a root TEE managing a Python training loop and delegating subtasks to worker TEEs, with orchestration managed by Federated Language, a derivative of TensorFlow Federated. Crucially, only DP model weights are released. The system also incorporates fault-tolerant recovery mechanisms, with each round saving a KMS-encrypted recovery state to handle potential failures of the root or worker TEEs. The privacy guarantee's verifiability stems from the publication of access policies to Rekor, Sigstore’s public transparency log. This allows external auditors to track every server workload, ensuring compliance with the established policies and enhancing the overall trustworthiness of the federated learning process. This development marks a significant step towards more secure and transparent AI model training on sensitive user data.

Original source — read the full reporting at the publisher:

Read on MarkTechPost

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next