Google Research has unveiled a federated learning system that relocates gradient computation from user phones into server-side trusted execution environments (TEEs). The design is already deployed for Gboard, and it changes how privacy protections are verified: instead of trusting on-device behavior alone, external observers can now audit the central differential privacy mechanism.
The system publishes access policies to Sigstore's Rekor log and uses reproducible builds for its binaries. That combination lets third parties confirm that the TEEs enforce the stated policy and that the code running inside them matches what was published, rather than relying on Google's word alone. The move is notable because differential privacy in federated learning has often been treated as a black box; here, the guarantees become checkable.
According to the source, this is a step toward making federated learning systems more transparent and accountable. The focus is specifically on Gboard's training pipeline, but the underlying approach could extend to other products where privacy guarantees need to be independently verified.