Back to Blog

What Is Federated Learning and How Google Uses It for Ad Targeting

PB

Patrick Bushe

February 26, 2026 · 5 min read

Federated learning is a way to train machine learning models on data that stays on people's devices. Instead of collecting everyone's data on a server, the model is sent to the devices, learns locally, and only the changes to the model are sent back and combined.

How it works

  1. A server sends the current model to many devices.
  2. Each device improves the model using its own data, such as what you type.
  3. Devices send back only the model updates, not the raw data.
  4. The server combines updates from many devices into a better model, and the cycle repeats.

Extra protections are often added: secure aggregation, so the server only sees combined updates, and differential privacy, which adds noise so individual contributions are harder to pick out.

Where Google uses it

Google introduced federated learning publicly in 2017 with Gboard, its Android keyboard, to improve suggestions without uploading what people type. It has since been used for features such as next-word prediction and voice activation on phones.

FLoC: federated learning in name only

In 2021, Google tested FLoC, "Federated Learning of Cohorts", in Chrome as a replacement for third-party cookies in advertising. Chrome grouped people into cohorts with similar browsing, and sites could read your cohort to target ads. Despite the name, it worked mainly by clustering browsing history on the device rather than through federated learning in the usual sense.

Privacy groups and other browsers objected that cohorts could still reveal sensitive interests and help fingerprint users. Google dropped FLoC in January 2022 in favor of the Topics API, and in October 2025 announced it was retiring Topics along with most other Privacy Sandbox ad features. See the Topics API.

Is federated learning private?

It's more private than sending raw data to a server, but not perfect:

  • Researchers have shown that model updates can sometimes leak details about the data they came from.
  • The company still decides what the model learns and how it's used.
  • Protections like differential privacy reduce, but don't remove, the risk.

Ad targeting today

With third-party cookies still available in Chrome and Privacy Sandbox mostly retired, ad targeting relies largely on cookies, logins, first-party data and tracking methods that avoid cookies. See the third-party cookie timeline.

What you can do

  • Review Google's ad settings at myadcenter.google.com and turn off personalized ads.
  • Block third-party cookies in Chrome. See a Chrome privacy checklist.
  • Ghost Browser makes random background visits so the interest profile built from your browsing is less accurate.

More Tools by Patrick Bushe

Free Chrome extensions to boost your productivity and privacy