Researchers demonstrate new attacks against federated learning in Google's GBoard next word prediction model, showing that user-typed words and sentences can be recovered with high accuracy despite privacy protections like mini-batches and local noise.