Compute the gradient of the error on the user's device and ship that to a server-side centralized model to update its weights.
It's a very cool idea that has a lot of interesting applications (among which: learning large statistical user behaviors without "spying" on them).
However, there is an unspoken claim that the gradient update doesn't carry enough information about the user data to reconstruct any of it server-side.
I'm still waiting to see a formal proof of that, and my gut says, if the servers sees enough gradient updates from a given user, it's likely possible to rebuild the original data.