Google has introduced a federated-learning architecture designed to make its privacy protections externally verifiable while moving more computation from phones to protected server hardware. Gboard is already using the system, which Google says substantially reduces compute time compared with its previous approach.
Federated learning trains a shared model from data held across many devices. In the new design, devices encrypt training examples and authorize only specified computations. Those access policies must appear in a public transparency log. A key-management cluster releases decryption keys only to server workloads running the approved code inside trusted execution environments, or TEEs.
A TEE isolates code and data from the rest of a machine. Its software can be remotely attested, allowing clients or auditors to verify what is running. Google combines several TEEs for key management, data processing and aggregation so that only anonymized outputs leave the protected workflow. The company says this arrangement can improve device coverage and model accuracy because phones perform less of the training work.
The guarantees still depend on the security properties and limitations of current TEE hardware. Google presents the design as stronger and more auditable privacy infrastructure, not as a claim that protected hardware eliminates every possible leak or implementation failure.