REVIEW 7 cited by
Verifiable evaluations of machine learning models using zkSNARKs
Not yet reviewed by Pith; the record is open.
This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.
SPECIMEN: schema-true, not a live event
T0 review · schema-true
One-sentence machine reading of the paper's core claim.
pith:XXXXXXXX · record.json · timestamp
Signed reviews
read the original abstract
In a world of increasing closed-source commercial machine learning models, model evaluations from developers must be taken at face value. These benchmark results-whether over task accuracy, bias evaluations, or safety checks-are traditionally impossible to verify by a model end-user without the costly or impossible process of re-performing the benchmark on black-box model outputs. This work presents a method of verifiable model evaluation using model inference through zkSNARKs. The resulting zero-knowledge computational proofs of model outputs over datasets can be packaged into verifiable evaluation attestations showing that models with fixed private weights achieve stated performance or fairness metrics over public inputs. We present a flexible proving system that enables verifiable attestations to be performed on any standard neural network model with varying compute requirements. For the first time, we demonstrate this across a sample of real-world models and highlight key challenges and design solutions. This presents a new transparency paradigm in the verifiable evaluation of private models.
Forward citations
Cited by 7 Pith papers
-
Repeated-Game Security for Restaking-Based Verifiable Inference
A one-round slashing condition is insufficient for repeated restaked inference; the paper derives the repeated-game gap and a mechanism that restores long-run incentives above a discount-factor threshold.
-
Attestable Audits: Verifiable AI Safety Benchmarks Using Trusted Execution Environments
A TEE-based protocol for cryptographically verifiable AI safety benchmark results, demonstrated on Llama-3.1 with AWS Nitro Enclaves.
-
TeleSparse: Practical Privacy-Preserving Verification of Deep Neural Networks
Pruning weights and teleporting activations before proof generation cuts ZK-SNARK prover memory by up to 67% and proof time by up to 54% on vision models at about 1% accuracy cost.
-
NiyamAI - An Intent-Bound AI Agent with Cryptographically Verifiable Guardrails using Zero-Knowledge Proofs
Niyam-AI binds agent permissions with SHA-256 and adds zk-SNARK proofs for a small Judge model's safety decisions, reporting F1 88.5% on Agent-SafetyBench, though the classifier is benchmark-adapted and the proof appl...
-
Privacy-Preserving AI Verification via Minimal Information Disclosure
MID selects verifier-facing evidence, such as telemetry or power traces, by minimizing conditional mutual information about a protected property given the authorized verification result, and demonstrates perfect held-...
-
In Which Areas of Technical AI Safety Could Geopolitical Rivals Cooperate?
Based on a four-risk typology, the paper concludes that verification mechanisms and codified protocols are the least risky areas for cooperation between geopolitical rivals on technical AI safety.
-
Private, Verifiable, and Auditable AI Systems
A thesis demonstrating partial prototypes for zk-verifiable model evaluation and privacy-preserving retrieval, and arguing these pieces can compose into end-to-end auditable AI systems.
Discussion (0). Continue with ORCID to comment.