Google moves Gboard training into servers with verifiable access rules
Google Research has described a training system already used for English and Japanese Gboard models. Phones encrypt examples and authorize the server workloads allowed to process them. Public access policies and reproducible software let outside observers examine those permissions, while protected execution environments and differential privacy constrain data access and the outputs of training.
Artificial Intelligence··Evening
Gboard examples move through encrypted uploads
Google Research has described a federated-learning system that processes training examples inside protected server environments. Federated learning coordinates training across data supplied by multiple devices. Google says the new architecture is already used for English and Japanese models of Gboard, its mobile keyboard. Phones encrypt the examples and authorize which server workloads may access them.[1], [2]
In the previous approach, device availability and competition for local computing resources constrained training. The revised system moves that computing work to the server fleet while attaching access permissions to each workload.[1]
Published policies govern decryption
Access policies are published in Rekor, a public transparency log. A key-management service releases decryption keys only to approved workloads running in trusted execution environments, which isolate their processing from surrounding server operations. Workload identity and the declared processing policy determine access. Google’s Confidential Federated Compute repository provides reproducible software components; proprietary model architecture or preprocessing code can be loaded while the privacy logic remains fixed.[1]
Training resumes from encrypted state
A root environment coordinates the Python training loop and delegates computation to worker environments. Training-round state can be stored in encrypted form so interrupted work can resume. Analysts receive metrics and model weights protected with differential privacy, a method that limits information about individual contributions. Hardware assumptions remain part of the protection: Google identifies side-channel risks and does not provide a complete proof of software correctness. Accelerator support remains future work.[1]