Google TEE-Based Federated Learning Breakthrough Provides Enhanced Security and Accuracy
Google Research has made significant advancements in Federated Learning (FL), a system that enables secure and decentralized machine learning. The researchers have moved FL gradient computation from client devices to attested server-side Trusted Execution Environments (TEEs). This innovation allows for externally verifiable central differential privacy guarantees, providing an added layer of security and transparency.
The new design has been implemented in Gboard, where it powers next-word prediction and Smart Compose. The system builds on Google's earlier confidential federated analytics work, coordinating four core components: data upload, Key Management System (KMS) and policy verification, workload execution, and fault-tolerant recovery.
The externally verifiable central differential privacy guarantees are made possible through the use of Rekor, Sigstore's public transparency log. This allows external auditors to track every server workload a device could feed. The KMS and data processing binaries are reproducibly buildable from open-source code, adding an extra layer of security.