Google Research has introduced a next-generation Federated Learning system that shifts compute to the server to improve training speed, accuracy, and device coverage while making privacy guarantees externally verifiable. The design uses Trusted Execution Environments (TEEs) to give remote attestation, confidentiality, and integrity to the training pipeline. Google says this closes a gap in earlier FL systems, where raw client data could be uploaded for immediate aggregation but external observers had no way to verify that it was never logged or inspected.
Under the new architecture, clients locally encrypt examples and upload them with an access policy listing the server workloads allowed to process the data. A key management system made of TEEs implementing the RAFT consensus protocol releases decryption keys only to workloads that match that policy. A root TEE then runs a Python training loop and delegates parallelizable subtasks to worker TEEs, using a framework-agnostic orchestration language called Federated Language. Only metrics and differentially private model weights are released to operators, and a KMS-encrypted recovery state allows for fault-tolerant restarts.
Google says the TEE approach also improves performance; Gboard has adopted the system and is seeing substantially faster compute times. Access policies are published to Rekor, a public transparency log, so external auditors can track the set of server-side workloads devices might participate in, and the relevant binaries are reproducibly built from open-source code in the Confidential Federated Compute repository. The post notes that these guarantees are subject to current-generation TEE limitations.