Google VaultGemma: 5 Things to Know About the AI Model That Puts Privacy First

Last week, Google Research introduced VaultGemma, an AI model which was trained on differential privacy.

Advertisement
Written by Akash Dutta, Edited by Ketan Pratap | Updated: 15 September 2025 13:51 IST
Highlights
  • Google added calibrated noise in the model to prevent memorisation
  • The model’s privacy approach comes with some performance trade-offs
  • Google said the AI model requires more compute and data

VaultGemma’s stronger privacy focus can result in lower accuracy in responses

Photo Credit: Google

Privacy has been a long-debated topic in the artificial intelligence (AI) space. While companies have taken steps to safeguard user privacy in the post-deployment phase, not a lot has been done in the pre-deployment or pre-training phase of AI models. To tackle this, Google, on Friday, released a privacy-centric large language model (LLM), which has been trained using a new privacy differential technique to ensure that the model cannot memorise sensitive information in the training phase. This measure ensures that prompt hackers cannot trick the AI into spilling identifiable information.

Google's VaultGemma: 5 Things You Should Know

1. Google's VaultGemma is a one-billion-parameter AI model. The tech giant used privacy differentiation in the pre-training phase, combining sensitive data, where the identifiers such as people's names, addresses, emails, and similar information, with calibrated noise. The noise prevents the AI model from memorising the identifier.

Advertisement

2. So, what does it really protect? VaultGemma prevents the model from memorising and regurgitating sensitive snippets such as credit card numbers or someone's address that were present in the training data. The noise-batch ratio also ensures that one document, sentence, or person's data does not influence the response generated by the model. Essentially, this training strategy would not let an attacker reliably figure out whether or not the target's data was present in the dataset.

3. The Privacy focus comes with certain performance trade-offs. The first thing it impacts is the accuracy. To increase privacy, the researchers will have to add more noise to the dataset. This means the AI model is not able to learn finer details, reducing the accuracy of responses somewhat when compared to non-private models.

Advertisement

For instance, without privacy, an AI model might know exact Shakespeare quotes, but with the differential privacy strategy, it will only capture the style but struggle in identifying the exact words.

4. There are trade-offs with compute and model size as well. To balance out the noise with performance, a model needs to be trained with larger datasets and more powerful computers. This makes differential privacy training slower and more expensive, and requires more compute.

Advertisement

Coming to the model size, Google noted that with differential privacy, a larger model size does not mean better performance, unlike what has been observed in traditional model training with scaling laws. Smaller models, when trained with the right settings, can outperform a model with more parameters. This requires a rethinking of the scaling laws of an LLM. However, not changing anything would give diminished results.

Google has also compared the performance of VaultGemma with Gemma 3 (a non-privacy model with the same parameters), and GPT-2, an older baseline model.

Advertisement

VaultGemma performance
Photo Credit: Google

 

5. So, what is the advantage to the end consumer? One privacy-focused model in itself is not going to change anything for the consumer. However, what Google has shown here is that it is possible to train and build a privacy-focused AI model that still delivers relatively decent performance.

If this standard is adopted by all major AI players, it will significantly contribute to protecting the data of people globally. This is important at a time when companies such as Google, OpenAI, and Anthropic are training their models on users' conversations.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. This AI Chatbot Can Help You Keep Track of Your Google Pay Payments
  2. Dell XPS 13 Launched in India Alongside New Dell 14S and Dell 16S Laptops
  3. Samsung Reportedly Increasing DDR4 RAM Production
  4. OpenAI's Rogue Agent Said to Have Compromised a Customer at a Second Tech Firm
  5. Redmi K100 Series Phone Visits Geekbench With This Flagship Snapdragon SoC
  6. Here's How Much the Vivo S2 Could Cost in India: See Expected Features
  7. JBL Bar 1000MK2 Review: More Than Just an Audio System
  8. Android 17 Beta Rolls Out to Motorola Edge 60 Pro With These Features
  9. Google Pixel Watch 5 Appears in Google Health App Ahead of August Launch
  10. Honor X6e Launched With 7,500mAh Battery
  1. Google Launches Gemini-Powered Ask Google Pay in India With a Dedicated In-App AI Chatbot
  2. OpenAI's Rogue Agent Compromised a Customer at a Second Tech Firm, Executive Says
  3. Honor X6e Launched With MediaTek Helio G81 Ultra SoC, 7,500mAh Battery: Price, Specifications
  4. Google Pixel Watch 5 Appears in Google Health App Ahead of August Launch
  5. Vivo S2 Price in India, Full Specifications, Design Spotted in Leaked Images Ahead on Launch
  6. Oppo Smartphone With Codename PYE110 Visits TENAA, Listing Suggests 8,000mAh Battery
  7. Samsung Galaxy Devices Get a New Security Feature With the Android 17 Update: Report
  8. Google Reportedly Rolling Out Gemini App UI Update With Easier Thinking Levels
  9. Samsung Expands RAM Production to Meet Rising Demand From Apple: Report
  10. PS Plus Monthly Games for August Announced: Dying Light 2 Stay Human: Reloaded Edition, Big Walk and Signalis
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.