
Advancing provably private learning from federated data
A newly deployed federated learning system uses trusted execution environments to verify privacy guarantees externally. By shifting computation to secure servers, the design improves training speed and accuracy for mobile applications.
Published by Jin · 2 min read · 3 OCT 2026
- Toward provably private learning from federated data
- Katharine Daly and 11 other authors
- Android Keyboard (Gboard)

A new machine learning architecture aims to make privacy guarantees verifiable while improving training speed and accuracy. The system builds on federated learning — a technique where multiple decentralized devices collaborate to train a model under the coordination of a service provider without sharing raw user data.
Trusted execution environments
To remove the need to trust the server operator, the updated system leverages trusted execution environments, which are secure hardware areas that offer confidentiality and integrity. Logic running inside these environments can be remotely attested by third parties to verify that computations run exactly as intended.

The framework coordinates four primary operational concepts:
- Data upload: Client devices locally encrypt training examples and pre-authorize an access policy that dictates allowable computations.
- Key management: A consensus protocol cluster grants decryption keys only to server-side workloads matching the published access policy.
- Workload execution: A root trusted execution environment executes a Python training program and delegates subtasks to worker environments.
Source — Original announcement ↗
Worth a read?
Comments · 0