Toward verifiably private learning from federated data

📅 2026-09-25
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses the lack of externally verifiable central differential privacy guarantees and practical deployment challenges in federated learning by proposing a next-generation system leveraging Trusted Execution Environments (TEEs). By integrating key management services, transparency logs, and Python workload policies, the system achieves encrypted data management and fine-grained policy binding. It provides the first externally verifiable central differential privacy guarantees while significantly improving the privacy-utility trade-off. Experimental results demonstrate that this approach effectively increases device coverage, accelerates Gboard model training, and enhances predictive accuracy. The proposed system has been successfully deployed in a production environment.
📝 Abstract
Federated Learning (FL) allows devices with private data to collaborate in training a shared model. We present a next-generation FL system based on Trusted Execution Environments (TEEs) that addresses operational challenges associated with earlier systems and provides externally verifiable central Differential Privacy (DP) guarantees for the first time while offering a better privacy-utility tradeoff. In our system, devices upload data encrypted with keys managed by a TEE-hosted Key Management Service (KMS). The uploaded data is cryptographically tied to a policy limiting the set of Python programs that may later process the data in server-side TEEs. External parties may inspect public transparency logs to observe the set of workloads allowed by these policies. Our experimental results show that the new system improves device coverage and favorably shifts privacy-utility curves by enabling collected data to be integrated into the server-side workload at a schedule that optimizes DP guarantees and is unaffected by device availability. Our new system has been productionized, enabling models for the Android Keyboard (Gboard) to be trained faster and achieve better accuracy under smaller, now externally verifiable privacy budgets in comparison to models trained using the prior system.
Problem

Research questions and friction points this paper is trying to address.

Federated Learning
Differential Privacy
Trusted Execution Environments
Privacy-Utility Tradeoff
Verifiable Privacy
Innovation

Methods, ideas, or system contributions that make the work stand out.

Federated Learning
Trusted Execution Environments
Differential Privacy
Key Management Service
Transparency Logs
🔎 Similar Papers
No similar papers found.