メインコンテンツまでスキップ

Federated Learning

The Sponsor Marketplace lets AI companies train diagnostic and predictive models on real-world health data. With federated learning, you can contribute to those models and earn from it — while your raw data, and even your individual model update, never leave your device. The model comes to your data; your data never goes to the model.

This is the privacy-preserving way to participate in the data economy with the most sensitive use of all — training AI. It extends the Data Yield Protocol's "earn while keeping full control" principle from one-off compliance commitments to continuous model improvement.

How It Works

┌──────────────────────────────────────────────────────────────────────┐
│ FEDERATED LEARNING ROUND │
│ │
│ Coordinator Your Wallet (1 of thousands) │
│ ─────────── ───────────────────────────── │
│ 1. Announce a round ───────────► 2. Your wallet checks ITSELF │
│ (buyer, terms) against your consent + budget │
│ 3. You opt in (you press — │
│ or a pre-signed listing allows) │
│ 4. Your device trains locally, │
│ producing a model UPDATE │
│ ◄─────────── 5. It masks the update (secure │
│ 6. Sums thousands of aggregation) + adds calibrated │
│ masked updates → noise (differential privacy) │
│ sees only the TOTAL, ─── only the masked, noised │
│ never any individual update leaves your device ─── │
│ 7. Improves the model │
│ 8. You earn credits │
└──────────────────────────────────────────────────────────────────────┘

Core Principles

1. Your data never leaves — and neither does your update

Training happens on your device. Only a model update (not your records) is ever transmitted, and even that is cryptographically masked before it leaves: it is combined with secrets shared pairwise with other participants that cancel out only when thousands of updates are summed. The coordinator learns the sum across the cohort and nothing about any single contributor — not even Ever can inspect your individual update.

2. The trained model cannot memorize you

Secure aggregation protects your update in transit; differential privacy protects the released model. Each update is norm-clipped and calibrated noise is added, bounding — with a mathematical guarantee — how much the final model can reveal about any one person. The guarantee is user-level: it is about you, not a single record.

3. Privacy is a budget you control

Every round you join spends a small, measurable slice of your privacy budget for the period. When it is exhausted, your data goes dark until the budget renews — so no amount of querying can chip away at your anonymity. You can see exactly how much budget remains.

4. Opt-in by default — a round is an invitation, not a command

A broadcast round announcement does nothing on its own. Your wallet evaluates it against the terms you set, and by default asks you to approve each round. If you prefer, you can pre-authorize a scope (e.g., "non-commercial diabetes research, up to this much budget") by signing a listing once — and only matching rounds within that scope proceed automatically. There is no silent participation.

5. You are compensated

Each round you contribute to pays you in credits, the majority of which go to you (the rest cover the node and platform that ran the round). Compensation and terms are set per program and shown before you opt in.

6. Some buyers are excluded by design

To protect you, certain buyer classes — notably insurers and employers — are prohibited from these programs at the protocol level, regardless of price.

What the coordinator can and cannot see

Matching the zero-trust model of the rest of EDH — enforced by mathematics, not policy:

The coordinator……can…cannot
Your raw health dataNever sees it (it never leaves your device)
Your individual model updateNever sees it (masked; only the cohort sum is revealed)
The cohort aggregateSees the masked sum of thousands of updatesDecompose it into individuals
Your identityKnows a wallet joined a roundTie the aggregate to you
Your privacy budgetSpend more than your per-period cap

A node that drops mid-round (common on mobile connections) is handled without exposing anyone: surviving participants reveal only the pairwise secrets needed to cancel the missing masks — never their own data.

Status

Federated learning is forward-looking design intent, not a shipped feature, and the multimodal (image/voice/genome) form is active research. Voice- and face-derived biomarkers in particular remain research-stage and are never presented as clinical fact. Nothing here is a financial guarantee; available programs, terms, and compensation vary and are shown at opt-in. As with all of EDH, the privacy guarantees are properties of the architecture — but legal basis and health-data compliance are confirmed per jurisdiction.