Mesh Talk to us
FAQ: frequently asked questions

Your questions about confidential federated learning, our answers

In brief

A page to answer the recurring questions: what confidential federated learning is, whether your data leaves, whether a collective model beats solo, what you lose by not centralizing, what you keep when you leave, how source quality is handled, what it costs, how long, and where GDPR sits. Each time, we tell apart what is built from what is on the roadmap.

Frequently asked questions

What is confidential federated learning?

It is a way of training an AI model together without ever pooling the data. Instead of moving data to a central model, the model is sent to the data: each actor trains locally, on its own data, and shares only the learned parameters. Raw data never leaves its holder. → full definition.

Does my data leave my premises?

No. Raw data is neither copied, transferred nor pooled elsewhere. Only the learned parameters circulate, and their transport is end-to-end encrypted. The coordinator sees encrypted model updates, never the raw data. The mechanism itself guarantees this, not an added promise. → detail on security.

Is a collective model better than one trained alone?

On our three real public datasets, the collective's model gains 6 to 8 AUC points over the average of what the standalone actors get, and the gain is positive in all twenty-one runs of the bench: it uses signals a lone actor cannot see. It is a mechanism demonstration, to be validated on your own data in a pilot. We do not promise to systematically beat solo: the size of the gain depends on the data and the use case, and is measured before any commitment.

What do I lose by not centralizing the data?

Nothing measurable. On the three public datasets of the bench, the federated model sits 0.3 AUC point at most from the model you would get by gathering all the data in one place, while the uncertainty of such a measurement is at least six times larger: the gap cannot be told apart from statistical noise. The collective's gain, by contrast, can: 6 to 8 AUC points over the average of the standalone actors, three to four times that uncertainty. Keeping the data at home therefore costs no performance, and it avoids the data transfer that blocks the project. → the demonstration and its figures.

Do I keep the model if I leave the collective or if Mesh disappears?

Yes, for the technical copy. The model is distributed to each member that receives it: a light artefact that runs on its own premises, offline, and that Mesh never retains. It keeps working even if you leave or if Mesh disappears. One nuance: collective re-training stops without the collective. What continues is the model as it was when you left, which you can then train privately on your own data. → detail on model ownership.

How do you guard against a rotten training source?

Two levels, to be told apart. What is built: parameter transport is end-to-end encrypted, and nothing raw circulates. What is on the roadmap: robustness to malicious or poisoning contributions (robust aggregation, secure aggregation) is not yet deployed. Source quality is also handled upstream, through consortium governance and the framing of the common vocabulary. → detail on security and source quality.

Who is in the consortium, and who sees what?

It is the consortium's governance that defines who sees what: the scope of exchanges, the access rules and the composition are set in the agreement between participants, at framing. Technically, each actor only accesses its own data and the aggregated model, never another's data. → see how a project works.

What does it cost?

Billing rests on a one-time setup and then an annual licence per member, from three actors onward. The structure is public; the amount is discussed case by case and compared against the value estimated for your organization. To size that value, see the ROI calculator.

How long does a project take?

The actual duration is the bootstrap: bringing together at least three actors ready to co-train a model usually takes 6 to 12 months. That is a sales cycle, not a delivery lead time. The pilot comes afterwards, once the consortium is formed. → how a project works.

Is federated learning GDPR-compliant?

It helps compliance without guaranteeing it. By keeping data with its holder, it natively applies data minimisation, which eases compliance: the EDPS (TechDispatch #1/2025) notes this, under conditions. Final compliance depends on the concrete deployment and is validated, case by case, with a lawyer. → detail on sovereignty and GDPR.

A question not covered here?

We answer directly, no mandatory meeting: describe your case, we send you the useful material.

contact (at) meshuniverse.fr