Pith. sign in

REVIEW 3 major objections 5 minor 2 cited by

Zero-Knowledge Proof Frameworks: A Systematic Survey

T0 review · 3 major / 5 minor · reviewed 2026-08-08 · deepseek-v4-flash

Pith's one-line read This paper surveys 25 open-source zero-knowledge proof frameworks, benchmarks 18 configurations on two circuits, and packages each environment in Docker for reproduction.

desk verdict Useful survey with a genuinely useful Docker artifact; the benchmark rankings need reproducibility fixes before they can carry the paper's recommendations. read the letter →

arxiv 2502.07063 v3 pith:ZSRKHQYV submitted 2025-02-10 cs.CR

classification cs.CR
keywords zero-knowledgeproofszk-SNARKzk-STARKPLONKMPC-in-the-HeadVOLE-basedframeworkbenchmarkingopen-sourcesurvey
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

The paper sets out to make the zero-knowledge proof ecosystem navigable for application developers by surveying 25 open-source frameworks that together span the major constructions: zk-SNARKs, PLONK-style systems, MPC-in-the-Head, VOLE-based protocols, and zk-STARKs. It claims to be the first survey at this breadth and to include, for each framework, a working Dockerized development environment with documented code so that the same SHA-256 and matrix-multiplication experiments can be rerun. The measured quantities are trusted-setup time, prover time, verifier time, and proof size or communication cost. The payoff the authors aim for is a concrete decision procedure: a developer can look at their computation, bandwidth, and trust assumptions, and pick a framework whose measured tradeoffs match the application.

What carries the argument

The carrying mechanism is the benchmark harness rather than a single mathematical identity: two standardized circuits, run inside per-framework Docker containers on identical hardware, with four metrics recorded (setup time where applicable, prover time, verifier time, and proof size or communication). The two circuits are chosen because they represent common privacy-preserving workloads, and their constraint counts anchor the comparison across heterogeneous arithmetization schemes. The paper's own caveat that there is no completely fair way to benchmark across such different constructions is part of the methodology; the authors treat the numbers as indicative of algorithmic complexity and supply the environments so readers can re-measure for themselves.

What would settle it

Re-run the two benchmarks at a larger circuit size, for instance 256x256 matrix multiplication, on the paper's released Docker containers; if the relative ordering of prover times or proof sizes changes materially, the decision flowchart's recommendations would not transfer to larger circuits. Recording per-run variance and peak memory would also test whether the reported means are stable.

Watch

Extended reading notes

Core claim

On the paper's own terms, the central discovery is a reproducible performance and usability map of the current open-source ZKP landscape. Eighteen benchmarked configurations drawn from the 25 surveyed frameworks are measured on two circuits, 32x32 matrix multiplication with about 32,768 R1CS constraints and SHA-256 with about 59,281 constraints, in identical Docker containers on one machine, with each number the mean of 10 runs. The results show a consistent tradeoff structure rather than a single winner: zk-SNARK-style systems give the smallest proofs and cheapest verification but require a trusted setup and a relatively strong prover; zk-STARK-style systems remove the setup and are post-quantum at the price of much larger proofs; VOLE-based systems split work between prover and verifier but are designated-verifier; and MPC-in-the-Head has the fewest accessible general-purpose frameworks. The paper reads these tradeoffs as evidence that framework choice should be application-driven, and it converts the findings into a decision flowchart that routes a developer to a recommendation based on prover strength, interactivity, bandwidth, and ease-of-use preferences.

Load-bearing premise

The load-bearing premise is that the 18 measured configurations are representative of their frameworks, meaning the same high-level circuits can be implemented equivalently across very different arithmetization schemes and that a handful of runs on one machine captures the performance a developer would see.

Editorial extensions

If this is right

  • Application developers can reproduce every benchmark on their own hardware using the supplied Docker environments, removing dependency setup as a barrier to evaluating a framework.
  • For bandwidth-constrained applications that accept a trusted setup, the measurements point to zk-SNARK/PLONK-style frameworks as the practical choice because proof size and verifier time stay small and nearly constant as circuits grow.
  • For settings that require post-quantum security and no trusted setup, zk-STARK-style frameworks trade transparency for proof sizes that are orders of magnitude larger and prover runtimes that grow more steeply.
  • VOLE-based frameworks are recommended for applications that already require communication, such as distributed or federated learning, because they shift part of the computational load to the verifier.
  • The decision flowchart gives a direct route from resource constraints, such as strong-prover availability and interactivity needs, to a short list of suitable frameworks.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The paper's own analysis of the Python-frontend-to-VOLE-framework path suggests that the intermediate representation and frontend compiler can dominate end-to-end performance as much as the proving system; a fair comparison may need to separate frontend overhead from protocol cost.
  • Because the reported numbers are means over 10 runs on one machine without variance or memory logs, the ordering of close competitors should be treated as indicative; pinning repository commits and re-running with memory and variance recorded would strengthen the comparison into a durable benchmark.
  • If post-quantum security hardens into a requirement, the survey's advice would shift decisively toward transparent constructions, so recommendations should be revisited as non-interactive VOLE-based and MPC-in-the-Head frameworks mature.
  • The maintained Docker repository could grow into a community benchmark where framework authors submit their own containers, making the survey's central promise of reproducibility an ongoing property rather than a point-in-time snapshot.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

3 major / 5 minor

Summary. The manuscript surveys 25 open-source zero-knowledge proof frameworks across zk-SNARK, PLONK, MPCitH, VOLE-based, and zk-STARK constructions, evaluates their usability and accessibility, benchmarks 18 configurations on SHA-256 and 32x32 matrix multiplication, and provides Docker containers and documented examples in a public repository. The central claim is that this is the first systematic survey of open-source ZKP frameworks spanning all constructions, with accompanying open-source environments, benchmarks, and documentation.

Significance. If the quantitative comparisons are made interpretable and reproducible, this is a genuinely useful community resource. The paper ships Docker environments for a wide range of frameworks, which directly addresses a real accessibility barrier, and the qualitative usability/accessibility analysis in Section III and Table III is valuable. The framework recommendations and the decision flowchart in Figure 2, however, rest on the benchmark results in Table IV, and those results are not yet controlled or reproducible to the standard the paper's claims require.

major comments (3)
  1. [Section IV-B, Table IV] The benchmark comparability premise is load-bearing and not established. Section IV-B concedes 'there is no completely fair way to benchmark these,' but Table IV and Figure 2 use the measurements to rank frameworks and drive the recommendations in Section IV-C. The two benchmarks are characterized only by R1CS constraint counts (32,768 and 59,281 constraints), while the evaluated systems use heterogeneous arithmetizations (R1CS, PLONK gates, AIR, boolean Bristol circuits), different fields and curves, and different frontend-to-backend pipelines (e.g., Noir's ACIR and Diet Mac'n'Cheese's PicoZK/SIEVE path). Per-framework constraint counts, field and curve choices, security parameters, compiler versions, and circuit-level parameters are not reported, so the prover/verifier timings and proof sizes cannot distinguish framework capability from implementation and configuration choices.
  2. [Section I, Section IV-A, Table IV] The claimed reproducibility is not yet pinned down. Section I gives a GitHub URL without a commit hash or release tag, and Section IV-A reports only means of 10 runs, with no variance, confidence intervals, or raw logs. Table IV also contains malformed or ambiguous cells: the Noir row lacks a separate prover time despite the column structure, and footnote 2 only says setup and prover are measured together; the PLONK-FRI proof-size cells are missing. The authors should provide a pinned repository state, per-run data, environment details, and scripts/logs so that the benchmark results can be independently checked.
  3. [Section IV-C, Figure 2] The comparative recommendations go beyond what the data support. Statements such as 'GNARK-KZG achieves excellent performance', 'we recommend Emp-ZK', and the placement of RISC Zero over Miden VM and Zilch are presented as conclusions from Table IV and Figure 2. Given the comparability gaps noted in Section IV-C ('we aim to keep settings consistent ... as much as the frameworks allow'), these rankings should be made conditional or softened. In particular, the paper itself notes that Diet Mac'n'Cheese's poor results are dominated by PicoZK's SIEVE IR compilation rather than by the underlying proof system; the same kind of caveat applies to every cross-framework ranking in Table IV.
minor comments (5)
  1. [Table IV] The Zokrates rows cite reference [26] (arkworks) instead of the Zokrates reference [64]; the citation should be corrected for both the Groth16 and GM17 rows.
  2. [Table V] The LEGOSnark row lists 'Brakedown-like [77]' as the proof system, but the text in Section III-A describes LegoSNARK as implementing CP-SNARKs built on libsnark; this inconsistency should be resolved.
  3. [Section III-C, Table III] The framework is referred to as both 'Mozzarella' and 'MozZ2karella'; a single consistent name should be used throughout.
  4. [Figure 2] The flowchart text is difficult to read in the extracted version, with some labels running together; the authors should ensure the figure is legible in the final PDF and that each decision branch is clearly labeled.
  5. [Section IV-A] The hardware description ('128GB RAM, AMD Ryzen 3990X CPU desktop') omits details such as CPU frequency, memory type, Docker resource limits, and background load controls; these should be specified for reproducibility.

Circularity Check

0 steps flagged · score 0.0 of 10

No circularity: the survey's conclusions are drawn from external framework measurements, not from assumptions that presuppose those conclusions.

full rationale

This paper is a survey and benchmark study, not a derivation chain, so the circularity patterns do not apply. The central claims are that the work is the first survey of open-source ZKP frameworks spanning all constructions and that it evaluates frameworks on usability and performance. Table IV reports direct measurements of third-party frameworks running in Docker containers, and the recommendations in Figure 2 are explicitly presented as conclusions drawn from those measurements together with stated application requirements. No fitted parameter is renamed as a prediction; no quantity is defined in terms of the outcome it is supposed to establish; and no uniqueness theorem or ansatz is imported from the authors' prior work to force the choice of framework. The paper's own caveat that 'there is no completely fair way to benchmark these' (Section IV-B) is a limitation on cross-framework comparability, not an indication that the benchmark outputs are constructed by the paper's assumptions. Self-citations such as [22], [73], [88], [122], and [123] appear in discussions of applications and hardware acceleration and are not load-bearing for the survey's main comparative claims. Reproducibility gaps, such as the absence of a pinned commit hash and malformed Table IV entries, are evidence-quality concerns rather than circular-reasoning defects. The evaluation is self-contained against external benchmarks, and the recommendations are not forced by the inputs of the survey itself. Therefore no significant circularity is present.

Assumptions & free parameters 3 free parameters · 3 assumptions · 0 invented entities

This survey has no fitted model and no invented theoretical entities. The central numerical claims rest on experiment-design choices (workload sizes, 10-run means, the 18-framework subset) and on the correctness of the released Docker artifacts. The axioms listed capture those assumptions.

free parameters (3)
  • Benchmark workload sizes = 32x32 matrix multiplication; SHA-256 (59,281 R1CS constraints)
    Chosen by hand in Section IV-B as representative tasks; all performance rankings and recommendations depend on these specific workloads.
  • Number of measurement runs = 10
    Section IV-A reports means of 10 runs on a single CPU; the absence of variance means this experimental-design choice materially affects the reported rankings.
  • Benchmarked framework subset = 18 of 25 frameworks
    Section IV-B excludes frameworks without high-level APIs; Figure 2 recommendations are derived only from this selected subset.
assumptions (3)
  • domain assumption The linked GitHub repository contains functional Docker environments and benchmark code matching the reported numbers.
    The paper's reproducibility contribution (Sections I and IV-A) depends on this artifact; no commit hash or build logs are provided in the text for independent verification.
  • domain assumption The same high-level benchmark computations (32x32 matrix multiplication and SHA-256) are implemented equivalently across all 18 evaluated frameworks despite different arithmetization schemes.
    Section IV-B defines the two benchmarks; Section IV-C acknowledges there is no completely fair way to compare frameworks, so this equivalence is load-bearing.
  • domain assumption Ten runs on the AMD Ryzen 3990X give stable mean performance values.
    Section IV-A reports means without variance or confidence intervals; the rankings in Table IV assume these means are representative.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Zero-Knowledge Proof Frameworks: A Systematic Survey." pith.science (2026). https://pith.science/paper/ZSRKHQYV

@misc{pith2026250207063,
  author       = {Pith},
  title        = {Pith review of: Zero-Knowledge Proof Frameworks: A Systematic Survey},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/ZSRKHQYV}},
  note         = {Machine review of arXiv:2502.07063}
}
read the original abstract

Zero-Knowledge Proofs (ZKPs) are a cryptographic primitive that allows a prover to demonstrate knowledge of a secret value to a verifier without revealing anything about the secret itself. ZKPs have shown to be an extremely powerful tool, as evidenced in both industry and academic settings. In recent years, the utilization of user data in practical applications has necessitated the rapid development of privacy-preserving techniques, including ZKPs. This has led to the creation of several robust open-source ZKP frameworks. However, there remains a significant gap in understanding the capabilities and real-world applications of these frameworks. Furthermore, identifying the most suitable frameworks for the developers' specific applications and settings is a challenge, given the variety of options available. The primary goal of our work is to lower the barrier to entry for understanding and building applications with open-source ZKP frameworks. In this work, we survey and evaluate 25 general-purpose, prominent ZKP frameworks. Recognizing that ZKPs have various constructions and underlying arithmetic schemes, our survey aims to provide a comprehensive overview of the ZKP landscape. These systems are assessed based on their usability and performance in SHA-256 and matrix multiplication experiments. Acknowledging that setting up a functional development environment can be challenging for these frameworks, we offer a fully open-source collection of Docker containers. These containers include a working development environment and are accompanied by documented code from our experiments. We conclude our work with a thorough analysis of the practical applications of ZKPs, recommendations for ZKP settings in different application scenarios, and a discussion on the future development of ZKP frameworks.

Figures

Figures reproduced from arXiv: 2502.07063 by the authors.

Figure 1
Figure 1. Analysis of scalability of select frameworks over matrix multiplication benchmarks spanning [PITH_FULL_IMAGE:figures/full_fig_p013_1.png] view at source ↗
Figure 2
Figure 2. Flow chart to guide users to the framework that best fits [PITH_FULL_IMAGE:figures/full_fig_p014_2.png] view at source ↗

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 2 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. zk-ScalHard: Scalable and Hardware-Rooted Privacy-Preserving Authentication for Secure OTA Updates in Zonal SDVs

    cs.CR 2026-07 conditional novelty 6.5 of 10

    A PUF-rooted hierarchical ZKP protocol delivers constant-size O(1) V2I authentication for zonal SDVs and reports ~99% bandwidth and temporal-attack-surface cuts versus Uptane.

  2. Toward cryptographically verifiable authorization for autonomous AI agents: A security hypothesis, preliminary formal model, and proof-of-concept implementation

    cs.CR 2026-07 conditional novelty 6.0 of 10

    Agent authorization can be formalized as a zero-knowledge-verifiable relation binding principal, request, context, and policy, with a Groth16 proof-of-concept.

Reference graph

Works this paper leans on

148 extracted references · 79 canonical work pages · cited by 2 Pith papers

  1. [1]

    https://github.com/GaloisInc/swanky/tree/dev/die t-mac-and-cheese

    Diet Mac’n’Cheese. https://github.com/GaloisInc/swanky/tree/dev/die t-mac-and-cheese

  2. [2]

    https://github.com/hyraxZK/hyraxZK

    hyraxZK. https://github.com/hyraxZK/hyraxZK

  3. [3]

    https://github.com/imdea-software/legosnark/

    LegoSNARK. https://github.com/imdea-software/legosnark/

  4. [4]

    https://github.com/scipr-lab/libsnark

    libsnark. https://github.com/scipr-lab/libsnark

  5. [5]

    https://github.com/akosba/mirage/tree/master

    Mirage. https://github.com/akosba/mirage/tree/master

  6. [6]

    https://github.com/uvm-plaid/picozk

    PicoZK. https://github.com/uvm-plaid/picozk

  7. [7]

    https://github.com/meilof/pysnark

    PySNARK. https://github.com/meilof/pysnark

  8. [8]

    https://github.com/iden3/rapidsnark

    RapidSNARK. https://github.com/iden3/rapidsnark

Show all 148 references
  1. [9]

    https://github.com/sieve-zk/ir

    SIEVE Intermediate Representation. https://github.com/sieve-zk/ir

  2. [10]

    https://github.com/microsoft/Spartan

    Spartan. https://github.com/microsoft/Spartan

  3. [11]

    https://ristretto.group

    The Ristretto Group. https://ristretto.group

  4. [12]

    Arithmetization schemes for zk-snarks, Jan. 2023

  5. [13]

    dusk-plonk - rust, 2023

  6. [14]

    The halo2 book, 2023

  7. [17]

    https://noir-lang.org, 2023

    Introducing noir. https://noir-lang.org, 2023

  8. [18]

    Polygon miden vm overview, 2023

  9. [19]

    https://chain.link /education-hub/zero-knowledge-proof-use-cases, 2023

    Zero-knowledge proof: Applications and use cases. https://chain.link /education-hub/zero-knowledge-proof-use-cases, 2023

  10. [20]

    miden-vm, 2023

    0xPolygonMiden. miden-vm, 2023

  11. [21]

    plonky2, 2023

    0xPolygonZero. plonky2, 2023

  12. [22]

    Ahmed, N

    A. Ahmed, N. Sheybani, D. Moreno, N. B. Njungle, T. Gong, M. Kinsy, and F. Koushanfar. Amaze: Accelerated mimc hardware architec- ture for zero-knowledge applications on the edge. arXiv preprint arXiv:2411.06350, 2024

  13. [23]

    Albrecht, L

    M. Albrecht, L. Grassi, C. Rechberger, A. Roy, and T. Tiessen. Mimc: Efficient encryption and cryptographic hashing with minimal multiplicative complexity. Cryptology ePrint Archive, Paper 2016/492,

  14. [24]

    S. Ames, C. Hazay, Y . Ishai, and M. Venkitasubramaniam. Ligero: Lightweight sublinear arguments without a trusted setup. In Proceed- ings of the 2017 acm sigsac conference on computer and communica- tions security, pages 2087–2104, 2017

  15. [25]

    Aragon, M

    N. Aragon, M. Bardet, L. Bidoux, J.-J. Chi-Dom ´ınguez, V . Dyseryn, T. Feneuil, P. Gaborit, A. Joux, M. Rivain, J.-P. Tillich, et al. Ryde specifications. 2023

  16. [26]

    arkworks zksnark ecosystem, 2022

    arkworks contributors. arkworks zksnark ecosystem, 2022

  17. [27]

    Ashur and S

    T. Ashur and S. Dhooghe. Marvellous: a stark-friendly family of cryptographic primitives. Cryptology ePrint Archive , 2018

  18. [28]

    barretenberg, 2023

    AztecProtocol. barretenberg, 2023

  19. [29]

    L. Babai. Transparent (holographic) proofs. In Annual Symposium on Theoretical Aspects of Computer Science , pages 525–534. Springer, 1993

  20. [30]

    K. A. Bamberger, R. Canetti, S. Goldwasser, R. Wexler, and E. J. Zimmerman. Verification dilemmas in law and the promise of zero- knowledge proofs. Berkeley Tech. LJ, 37:1, 2022

  21. [31]

    C. Baum, L. Braun, C. D. de Saint Guilhem, M. Klooß, E. Orsini, L. Roy, and P. Scholl. Publicly verifiable zero-knowledge and post- quantum signatures from vole-in-the-head. In Annual International Cryptology Conference, pages 581–615. Springer, 2023

  22. [32]

    C. Baum, L. Braun, A. Munch-Hansen, and P. Scholl. Moz z 2 k arella: efficient vector-ole and zero-knowledge proofs over z 2 k. In Annual International Cryptology Conference , pages 329–358. Springer, 2022

  23. [33]

    C. Baum, A. J. Malozemoff, M. B. Rosen, and P. Scholl. Mac’n’cheese: Zero-knowledge proofs for boolean and arithmetic circuits with nested disjunctions. In Advances in Cryptology–CRYPTO 2021: 41st Annual International Cryptology Conference, CRYPTO 2021, Virtual Event, August 1...

  24. [34]

    J. Baylina. iden3/snarkjs, 2020

  25. [35]

    Baylina1 and M

    J. Baylina1 and M. Belle‘s. 4-bit window pedersen hash on the baby jubjub elliptic curve

  26. [36]

    Bell ´es-Mu˜noz, M

    M. Bell ´es-Mu˜noz, M. Isabel, J. L. Mu ˜noz-Tapia, A. Rubio, and J. Baylina. Circom: A circuit description language for building zero- knowledge applications. IEEE Transactions on Dependable and Secure Computing, 2022

  27. [37]

    Ben-Sasson, I

    E. Ben-Sasson, I. Bentov, Y . Horesh, and M. Riabzev. Fast reed- solomon interactive oracle proofs of proximity. In 45th international colloquium on automata, languages, and programming (icalp 2018) . Schloss Dagstuhl-Leibniz-Zentrum fuer Informatik, 2018

  28. [38]

    Ben-Sasson, I

    E. Ben-Sasson, I. Bentov, Y . Horesh, and M. Riabzev. Scalable, trans- parent, and post-quantum secure computational integrity. Cryptology ePrint Archive, 2018

  29. [39]

    Ben-Sasson, A

    E. Ben-Sasson, A. Chiesa, M. Riabzev, N. Spooner, M. Virza, and N. P. Ward. Aurora: Transparent succinct arguments for r1cs. Cryptology ePrint Archive, Paper 2018/828, 2018. https://eprint.iacr.org/2018/828

  30. [40]

    Ben-Sasson, A

    E. Ben-Sasson, A. Chiesa, E. Tromer, and M. Virza. Succinct {Non- Interactive} zero knowledge for a von neumann architecture. In 23rd USENIX Security Symposium (USENIX Security 14) , pages 781–796, 2014. 16

  31. [41]

    Benadjila, T

    R. Benadjila, T. Feneuil, and M. Rivain. Mq on my mind: Post- quantum signatures from the non-structured multivariate quadratic problem. In 2024 IEEE 9th European Symposium on Security and Privacy (EuroS&P), pages 468–485. IEEE, 2024

  32. [42]

    Benarroch, K

    D. Benarroch, K. Gurkan, R. Kahat, A. Nicolas, and E. Tromer. zkinterface, a standard tool for zero-knowledge interoperability. In 2nd ZKProof Workshop. https://docs. zkproof. org/pages/standards/acceptedworkshop2/proposal–zk-interop- zkinterface. pdf, 2019

  33. [43]

    D. J. Bernstein. Curve25519: new diffie-hellman speed records. In Public Key Cryptography-PKC 2006: 9th International Conference on Theory and Practice in Public-Key Cryptography, New York, NY, USA, April 24-26, 2006. Proceedings 9 , pages 207–228. Springer, 2006

  34. [44]

    Bettaieb, L

    S. Bettaieb, L. Bidoux, V . Dyseryn, A. Esser, P. Gaborit, M. Kulkarni, and M. Palumbi. Perk: compact signature scheme based on a new vari- ant of the permuted kernel problem. Designs, Codes and Cryptography, pages 1–27, 2024

  35. [45]

    What Is Zero-knowledge Proof and How Does It Impact Blockchain? — Binance Academy — academy.binance.com

    Binance. What Is Zero-knowledge Proof and How Does It Impact Blockchain? — Binance Academy — academy.binance.com. https: //academy.binance.com/en/articles/what-is-zero-knowledge-proof-and -how-does-it-impact-blockchain

  36. [46]

    Bitansky, R

    N. Bitansky, R. Canetti, A. Chiesa, and E. Tromer. Recursive com- position and bootstrapping for snarks and proof-carrying data. In Proceedings of the forty-fifth annual ACM symposium on Theory of computing, pages 111–120, 2013

  37. [47]

    Bonawitz, V

    K. Bonawitz, V . Ivanov, B. Kreuter, A. Marcedone, H. B. McMahan, S. Patel, D. Ramage, A. Segal, and K. Seth. Practical secure aggre- gation for privacy-preserving machine learning. In proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pages...

  38. [48]

    E. Boo, J. Kim, and J. Ko. Litezkp: Lightening zero-knowledge proof- based blockchains for iot and edge platforms. IEEE Systems Journal , 16(1):112–123, 2021

  39. [49]

    Botrel, T

    G. Botrel, T. Piellard, Y . E. Housni, I. Kubjas, and A. Tabaie. Consensys/gnark: v0.9.0, Feb. 2023

  40. [50]

    S. Bowe, J. Grigg, and D. Hopwood. Recursive proof composition without a trusted setup. Cryptology ePrint Archive , 2019

  41. [51]

    Breidenbach, C

    L. Breidenbach, C. Cachin, B. Chan, A. Coventry, S. Ellis, A. Juels, F. Koushanfar, A. Miller, B. Magauran, D. Moroz, et al. Chainlink 2.0: Next steps in the evolution of decentralized oracle networks. 2021

  42. [52]

    V . Buterin. Quadratic arithmetic programs: From zero to hero, 2023

  43. [53]

    Cammarota

    R. Cammarota. Intel heracles: Homomorphic encryption revolutionary accelerator with correctness for learning-oriented end-to-end solutions. In Proceedings of the 2022 on Cloud Computing Security Workshop , pages 3–3, 2022

  44. [54]

    Campanelli, D

    M. Campanelli, D. Fiore, and A. Querol. Legosnark: Modular design and composition of succinct zero-knowledge proofs. In Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pages 2075–2092, 2019

  45. [55]

    ˇCapko, S

    D. ˇCapko, S. Vukmirovi ´c, and N. Nedi ´c. State of the art of zero- knowledge proofs in blockchain. In 2022 30th Telecommunications Forum (TELFOR), pages 1–4. IEEE, 2022

  46. [56]

    The pantheon of zero knowledge proof development frameworks (updated!), 2023

    Celer Network. The pantheon of zero knowledge proof development frameworks (updated!), 2023

  47. [57]

    Overview Of Zero-Knowledge Blockchain Projects — Chainlink — chain.link

    Chainlink. Overview Of Zero-Knowledge Blockchain Projects — Chainlink — chain.link. https://chain.link/education-hub/zero-kno wledge-proof-projects

  48. [58]

    Chiesa, Y

    A. Chiesa, Y . Hu, M. Maller, P. Mishra, N. Vesely, and N. Ward. Marlin: Preprocessing zksnarks with universal and updatable srs. In Advances in Cryptology–EUROCRYPT 2020: 39th Annual Interna- tional Conference on the Theory and Applications of Cryptographic Techniques, Zagreb...

  49. [59]

    Chiesa, D

    A. Chiesa, D. Ojha, and N. Spooner. Fractal: Post-quantum and transparent recursive proofs from holography. Cryptology ePrint Archive, Paper 2019/1076, 2019. https://eprint.iacr.org/2019/1076

  50. [60]

    ConsenSys, Inc. gnark. https://docs.gnark.consensys.net/overview#gn ark-is-fast, 2023

  51. [61]

    Daftardar, B

    A. Daftardar, B. Reagen, and S. Garg. Szkp: A scalable accelerator architecture for zero-knowledge proofs. In Proceedings of the 2024 International Conference on Parallel Architectures and Compilation Techniques, pages 271–283, 2024

  52. [62]

    Danezis, C

    G. Danezis, C. Fournet, J. Groth, and M. Kohlweiss. Square span programs with applications to succinct nizk arguments. Cryptology ePrint Archive, Paper 2014/718, 2014. https://eprint.iacr.org/2014/718

  53. [63]

    C. D. de Saint Guilhem, E. Orsini, and T. Tanguy. Limbo: Efficient zero-knowledge mpcith-based arguments. Cryptology ePrint Archive, Paper 2021/215, 2021. https://eprint.iacr.org/2021/215

  54. [64]

    Eberhardt and S

    J. Eberhardt and S. Tai. Zokrates-scalable privacy-preserving off-chain computations. In 2018 IEEE International Conference on Internet of Things (iThings) and IEEE Green Computing and Communications (GreenCom) and IEEE Cyber, Physical and Social Computing (CP- SCom) and IEEE ...

  55. [65]

    M. Fang, X. Cao, J. Jia, and N. Gong. Local model poisoning attacks to {Byzantine-Robust} federated learning. In 29th USENIX security symposium (USENIX Security 20) , pages 1605–1622, 2020

  56. [66]

    B. Feng, L. Qin, Z. Zhang, Y . Ding, and S. Chu. Zen: An optimizing compiler for verifiable, zero-knowledge neural network inferences. Cryptology ePrint Archive , 2021

  57. [67]

    Fuchsbauer

    G. Fuchsbauer. Subversion-zero-knowledge snarks. In Public-Key Cryptography–PKC 2018: 21st IACR International Conference on Practice and Theory of Public-Key Cryptography, Rio de Janeiro, Brazil, March 25-29, 2018, Proceedings, Part I 21 , pages 315–347. Springer, 2018

  58. [68]

    G. S. Gaba, M. Hedabou, P. Kumar, A. Braeken, M. Liyanage, and M. Alazab. Zero knowledge proofs based authenticated key agreement protocol for sustainable healthcare. Sustainable Cities and Society , 80:103766, 2022

  59. [69]

    Gabizon, Z

    A. Gabizon, Z. J. Williamson, and O. Ciobotaru. Plonk: Permuta- tions over lagrange-bases for oecumenical noninteractive arguments of knowledge. Cryptology ePrint Archive, Paper 2019/953, 2019. https://eprint.iacr.org/2019/953

  60. [70]

    swanky: A suite of rust libraries for secure computation

    Galois, Inc. swanky: A suite of rust libraries for secure computation. https://github.com/GaloisInc/swanky, 2019

  61. [71]

    Ganesh, A

    C. Ganesh, A. Nitulescu, and E. Soria-Vazquez. Rinocchio: Snarks for ring arithmetic. Journal of Cryptology , 36(4):41, 2023

  62. [72]

    Gennaro, C

    R. Gennaro, C. Gentry, B. Parno, and M. Raykova. Quadratic span programs and succinct nizks without pcps. In Advances in Cryptology– EUROCRYPT 2013: 32nd Annual International Conference on the Theory and Applications of Cryptographic Techniques, Athens, Greece, May 26-30, 2013...

  63. [73]

    Ghodsi, M

    Z. Ghodsi, M. Javaheripi, N. Sheybani, X. Zhang, K. Huang, and F. Koushanfar. zprobe: Zero peek robustness checks for federated learning. In Proceedings of the IEEE/CVF International Conference on Computer Vision , pages 4860–4870, 2023

  64. [74]

    Goldreich and Y

    O. Goldreich and Y . Oren. Definitions and properties of zero- knowledge proof systems. Journal of Cryptology , 7(1):1–32, 1994

  65. [75]

    Goldwasser, Y

    S. Goldwasser, Y . T. Kalai, and G. N. Rothblum. Delegating compu- tation: interactive proofs for muggles. Journal of the ACM (JACM) , 62(4):1–64, 2015

  66. [76]

    Goldwasser, S

    S. Goldwasser, S. Micali, and C. Rackoff. The knowledge complexity of interactive proof-systems. In Providing sound foundations for cryptography: On the work of shafi goldwasser and silvio micali, pages 203–225. 2019

  67. [77]

    Golovnev, J

    A. Golovnev, J. Lee, S. Setty, J. Thaler, and R. S. Wahby. Brakedown: Linear-time and field-agnostic snarks for r1cs. In Annual International Cryptology Conference, pages 193–226. Springer, 2023

  68. [78]

    Grassi, D

    L. Grassi, D. Khovratovich, C. Rechberger, A. Roy, and M. Schofneg- ger. Poseidon: A new hash function for Zero-Knowledge proof systems. In 30th USENIX Security Symposium (USENIX Security 21) , pages 519–535. USENIX Association, Aug. 2021

  69. [79]

    J. Groth. On the size of pairing-based non-interactive arguments. In M. Fischlin and J.-S. Coron, editors, Advances in Cryptology – EUROCRYPT 2016, pages 305–326, Berlin, Heidelberg, 2016. Springer Berlin Heidelberg

  70. [80]

    Groth, M

    J. Groth, M. Kohlweiss, M. Maller, S. Meiklejohn, and I. Miers. Updatable and universal common reference strings with applications to zk-snarks. Cryptology ePrint Archive, Paper 2018/280, 2018. https://eprint.iacr.org/2018/280

  71. [81]

    Groth and M

    J. Groth and M. Maller. Snarky signatures: Minimal signatures of knowledge from simulation-extractable snarks. In Annual International Cryptology Conference, pages 581–612. Springer, 2017

  72. [82]

    Grubbs, A

    P. Grubbs, A. Arun, Y . Zhang, J. Bonneau, and M. Walfish. {Zero- Knowledge} middleboxes. In 31st USENIX Security Symposium (USENIX Security 22) , pages 4255–4272, 2022

  73. [83]

    Hab ¨ock

    U. Hab ¨ock. A summary on the fri low degree test. Cryptology ePrint Archive, 2022

  74. [84]

    Hastings, B

    M. Hastings, B. Hemenway, D. Noble, and S. Zdancewic. Sok: General purpose compilers for secure multi-party computation. In 2019 IEEE symposium on security and privacy (SP) , pages 1220–1237. IEEE, 2019. 17

  75. [85]

    Hopwood, S

    D. Hopwood, S. Bowe, T. Hornby, N. Wilcox, et al. Zcash protocol specification. GitHub: San Francisco, CA, USA , 4(220):32, 2016

  76. [86]

    Icicle: Gpu library for zk acceleration

    Ingonyama. Icicle: Gpu library for zk acceleration

  77. [87]

    Ishai, E

    Y . Ishai, E. Kushilevitz, R. Ostrovsky, and A. Sahai. Zero-knowledge from secure multiparty computation. In Proceedings of the thirty-ninth annual ACM symposium on Theory of computing , pages 21–30, 2007

  78. [88]

    Juels and F

    A. Juels and F. Koushanfar. Props for machine-learning security. arXiv preprint arXiv:2410.20522, 2024

  79. [89]

    A. Kate, G. M. Zaverucha, and I. Goldberg. Constant-size commitments to polynomials and their applications. In Advances in Cryptology- ASIACRYPT 2010: 16th International Conference on the Theory and Application of Cryptology and Information Security, Singapore, De- cember 5-9,...

  80. [90]

    J. Kilian. A note on efficient zero-knowledge proofs and arguments. In Proceedings of the twenty-fourth annual ACM symposium on Theory of computing, pages 723–732, 1992

  81. [91]

    Kosba, D

    A. Kosba, D. Papadopoulos, C. Papamanthou, and D. Song. {MIRAGE}: Succinct arguments for randomized algorithms with applications to universal {zk-SNARKs}. In 29th USENIX Security Symposium (USENIX Security 20) , pages 2129–2146, 2020

  82. [92]

    Kosba, C

    A. Kosba, C. Papamanthou, and E. Shi. xjsnark: A framework for efficient verifiable computation. In 2018 IEEE Symposium on Security and Privacy (SP) , pages 944–961. IEEE, 2018

  83. [93]

    Kothapalli, S

    A. Kothapalli, S. Setty, and I. Tzialla. Nova: Recursive zero-knowledge arguments from folding schemes. In Annual International Cryptology Conference, pages 359–388. Springer, 2022

  84. [94]

    Limbo, 2023

    KULeuven-COSIC. Limbo, 2023

  85. [95]

    S. Landau. Zero knowledge and the department of defense. Notices of the American Mathematical Society , 35(1):5–12, 1988

  86. [96]

    S. Lee, H. Ko, J. Kim, and H. Oh. vcnn: Verifiable convolutional neural network based on zk-snarks. Cryptology ePrint Archive , 2020

  87. [97]

    C. Lin, M. Luo, X. Huang, K.-K. R. Choo, and D. He. An efficient privacy-preserving credit score system based on noninteractive zero- knowledge proof. IEEE systems journal , 16(1):1592–1601, 2021

  88. [98]

    H. Lipmaa. Prover-efficient commit-and-prove zero-knowledge snarks. In Progress in Cryptology–AFRICACRYPT 2016: 8th International Conference on Cryptology in Africa, Fes, Morocco, April 13-15, 2016, Proceedings 8, pages 185–206. Springer, 2016

  89. [99]

    T. Liu, X. Xie, and Y . Zhang. Zkcnn: Zero knowledge proofs for con- volutional neural network predictions and accuracy. In Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, pages 2968–2985, 2021

  90. [100]

    T. Lu, C. Wei, R. Yu, C. Chen, W. Fang, L. Wang, Z. Wang, and W. Chen. Cuzk: Accelerating zero-knowledge proof with a faster parallel multi-scalar multiplication algorithm on gpus. Cryptology ePrint Archive, 2022

  91. [101]

    Lycklama, L

    H. Lycklama, L. Burkhalter, A. Viand, N. K ¨uchler, and A. Hithnawi. Rofl: Robustness of secure federated learning. In 2023 IEEE Sympo- sium on Security and Privacy (SP) , pages 453–476. IEEE, 2023

  92. [102]

    W. Ma, Q. Xiong, X. Shi, X. Ma, H. Jin, H. Kuang, M. Gao, Y . Zhang, H. Shen, and W. Hu. Gzkp: A gpu accelerated zero-knowledge proof system. In Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volum...

  93. [103]

    Maller, S

    M. Maller, S. Bowe, M. Kohlweiss, and S. Meiklejohn. Sonic: Zero- knowledge snarks from linear-size universal and updateable structured reference strings. Cryptology ePrint Archive, Paper 2019/099, 2019. https://eprint.iacr.org/2019/099

  94. [104]

    Home — monero - secure, private, untraceable

    Monero. Home — monero - secure, private, untraceable. https://ww w.getmonero.org, 2023

  95. [105]

    Mouris and N

    D. Mouris and N. G. Tsoutsos. Zilch: A framework for deploying transparent zero-knowledge proofs. IEEE Transactions on Information Forensics and Security, 16:3269–3284, 2021

  96. [106]

    J. L. Mu ˜noz-Tapia, M. Belles, M. Isabel, A. Rubio, and J. Baylina. Circom: A robust and scalable language for building complex zero- knowledge circuits. 2022

  97. [107]

    Round 2 additional signatures

    National Institute of Standards and Technology (NIST). Round 2 additional signatures. https://csrc.nist.gov/projects/pqc-dig-sig/rou nd-2-additional-signatures, 2020

  98. [108]

    Benchmarks in awesome-noir, 2023

    Noir-Lang. Benchmarks in awesome-noir, 2023

  99. [109]

    Ozdemir, F

    A. Ozdemir, F. Brown, and R. S. Wahby. Circ: Compiler infrastructure for proof systems, software verification, and more. In 2022 IEEE Symposium on Security and Privacy (SP) , pages 2248–2266. IEEE, 2022

  100. [110]

    Parno, J

    B. Parno, J. Howell, C. Gentry, and M. Raykova. Pinocchio: Nearly practical verifiable computation. Communications of the ACM , 59(2):103–112, 2016

  101. [111]

    Partala, T

    J. Partala, T. H. Nguyen, and S. Pirttikangas. Non-interactive zero- knowledge for blockchain: A survey. IEEE Access, 8:227945–227961, 2020

  102. [112]

    Polygon zkevm — scaling for the ethereum virtual machine

    Polygon Labs UI (Cayman) Ltd. Polygon zkevm — scaling for the ethereum virtual machine. https://polygon.technology/polygon-zkevm, 2023

  103. [113]

    Pqc-mirath

    PQC-MIRATH Consortium. Pqc-mirath. https://pqc-mirath.org/, 2023

  104. [114]

    M. O. Rabin, Y . Mansour, S. Muthukrishnan, and M. Yung. Strictly- black-box zero-knowledge and efficient validation of financial trans- actions. In International Colloquium on Automata, Languages, and Programming, pages 738–749. Springer, 2012

  105. [115]

    Introduction — risc zero developer docs, 2023

    RISC Zero, Inc. Introduction — risc zero developer docs, 2023

  106. [116]

    Roy Chowdhury, C

    A. Roy Chowdhury, C. Guo, S. Jha, and L. van der Maaten. Eiffel: Ensuring integrity for federated learning. In Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, pages 2535–2549, 2022

  107. [117]

    Samardzic, S

    N. Samardzic, S. Langowski, S. Devadas, and D. Sanchez. Accelerating zero-knowledge proofs through hardware-algorithm co-design. In 2024 57th IEEE/ACM International Symposium on Microarchitecture (MICRO), pages 366–379. IEEE, 2024

  108. [118]

    libiop, 2023

    SciprLab. libiop, 2023

  109. [119]

    SDITH. Sdith. https://sdith.org/index.html, 2023

  110. [120]

    S. Setty. Spartan: Efficient and general-purpose zksnarks without trusted setup. In Annual International Cryptology Conference , pages 704–737. Springer, 2020

  111. [121]

    Sharma, R

    B. Sharma, R. Halder, and J. Singh. Blockchain-based interoperable healthcare using zero-knowledge proofs and proxy re-encryption. In 2020 International Conference on COMmunication Systems & NET- workS (COMSNETS), pages 1–6. IEEE, 2020

  112. [122]

    Sheybani, Z

    N. Sheybani, Z. Ghodsi, R. Kapila, and F. Koushanfar. Zkrownn: Zero knowledge right of ownership for neural networks. In 2023 60th ACM/IEEE Design Automation Conference (DAC) , pages 1–6. IEEE, 2023

  113. [123]

    Sheybani, T

    N. Sheybani, T. Gong, A. Ahmed, N. B. Njungle, M. Kinsy, and F. Koushanfar. Gotta hash’em all! speeding up hash functions for zero- knowledge proof applications. arXiv preprint arXiv:2501.18780, 2025

  114. [124]

    Sidorenco, S

    N. Sidorenco, S. Oechsner, and B. Spitters. Formal security analysis of mpc-in-the-head zero-knowledge protocols. In 2021 IEEE 34th Computer Security Foundations Symposium (CSF) , pages 1–14. IEEE, 2021

  115. [125]

    ˇSimuni´c, D

    S. ˇSimuni´c, D. Bernaca, and K. Lenac. Verifiable computing applica- tions in blockchain. IEEE Access, 9:156729–156745, 2021

  116. [126]

    J. So, B. G ¨uler, and A. S. Avestimehr. Byzantine-resilient secure fed- erated learning. IEEE Journal on Selected Areas in Communications , 39(7):2168–2181, 2020

  117. [127]

    X. Sun, F. R. Yu, P. Zhang, Z. Sun, W. Xie, and X. Peng. A survey on zero-knowledge proof in blockchain. IEEE Network , 35(4):198–205, 2021

  118. [128]

    Virgo, 2023

    sunblaze ucb. Virgo, 2023

  119. [129]

    Thorpe and D

    C. Thorpe and D. C. Parkes. Zero-knowledge proofs in large trades, July 9 2009. US Patent App. 12/261,249

  120. [130]

    Threadbare, D

    B. Threadbare, D. Schmid, T. Carstens, B. Retford, D. Lubarov, A. Nagornyi, and V . Tan. Zk system benchmarking, 2023

  121. [131]

    Tillich and N

    S. Tillich and N. Smart. (bristol format) circuits of basic functions suitable for mpc and fhe, 2023

  122. [132]

    A. E. B. Tomaz, J. C. Do Nascimento, A. S. Hafid, and J. N. De Souza. Preserving privacy in mobile health systems using non-interactive zero- knowledge proof and blockchain. IEEE access , 8:204441–204458, 2020

  123. [133]

    Zilch, 2023

    TrustworthyComputing. Zilch, 2023

  124. [134]

    Viand, P

    A. Viand, P. Jattke, and A. Hithnawi. Sok: Fully homomorphic encryption compilers. In 2021 IEEE Symposium on Security and Privacy (SP), pages 1092–1108. IEEE, 2021

  125. [135]

    Viand, C

    A. Viand, C. Knabenhans, and A. Hithnawi. Verifiable fully homomor- phic encryption. arXiv preprint arXiv:2301.07041 , 2023

  126. [136]

    R. S. Wahby, Y . Ji, A. J. Blumberg, A. Shelat, J. Thaler, M. Walfish, and T. Wies. Full accounting for verifiable outsourcing. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pages 2071–2086, 2017

  127. [137]

    R. S. Wahby, I. Tzialla, A. Shelat, J. Thaler, and M. Walfish. Doubly- efficient zksnarks without trusted setup. In 2018 IEEE Symposium on Security and Privacy (SP) , pages 926–943. IEEE, 2018

  128. [138]

    X. Wang. Emp-toolkit

  129. [140]

    C. Weng, A. Coventry, S. Hussain, D. Malkhi, A. Topliceanu, X. Wang, and F. Zhang. V ole-based interactive commitments, Jan. 2023. 18

  130. [141]

    C. Weng, K. Yang, J. Katz, and X. Wang. Wolverine: fast, scalable, and communication-efficient zero-knowledge proofs for boolean and arithmetic circuits. In 2021 IEEE Symposium on Security and Privacy (SP), pages 1074–1091. IEEE, 2021

  131. [142]

    C. Weng, K. Yang, X. Xie, J. Katz, and X. Wang. Mystique: Efficient conversions for {Zero-Knowledge} proofs with applications to machine learning. In 30th USENIX Security Symposium (USENIX Security 21) , pages 501–518, 2021

  132. [143]

    H. Wu, F. Wang, et al. A survey of noninteractive zero knowledge proof system and its applications. The Scientific World Journal , 2014, 2014

  133. [144]

    K. Yang, P. Sarkar, C. Weng, and X. Wang. Quicksilver: Efficient and affordable zero-knowledge proofs for circuits and polynomials over any field. IACR Cryptol. ePrint Arch. , 2021:76, 2021

  134. [145]

    Zhang, D

    F. Zhang, D. Maram, H. Malvai, S. Goldfeder, and A. Juels. Deco: Lib- erating web data using decentralized oracles for tls. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, pages 1919–1938, 2020

  135. [146]

    Zhang, Z

    J. Zhang, Z. Fang, Y . Zhang, and D. Song. Zero knowledge proofs for decision tree predictions and accuracy. In Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, pages 2039–2053, 2020

  136. [147]

    Zhang, T

    J. Zhang, T. Liu, W. Wang, Y . Zhang, D. Song, X. Xie, and Y . Zhang. Doubly efficient interactive proofs for general arithmetic circuits with linear prover time. Cryptology ePrint Archive, Paper 2020/1247, 2020. https://eprint.iacr.org/2020/1247

  137. [148]

    Zhang, T

    J. Zhang, T. Xie, Y . Zhang, and D. Song. Transparent polynomial delegation and its applications to zero knowledge proof. In 2020 IEEE Symposium on Security and Privacy (SP) , pages 859–876. IEEE, 2020

  138. [149]

    What is ezkl?, 2023

    Zkonduit Inc. What is ezkl?, 2023. Nojan Sheybani is a Ph.D. candidate in the de- partment of Electrical and Computer Engineering (ECE) at the University of California San Diego (UCSD). His research is focused on applied cryp- tography, hardware/software co-design, and zero- k...

  139. [150]

    has shown the value of using ZKPs to build protected pipelines, or props for short, to provide verifiable, privacy- preserving access to deep web data for machine learning pipelines. This kind of secure access to deep web data is an integral part of advancing machine learning ...

  140. [2016]

    https://eprint.iacr.org/2016/492

Pith tools

Reviewed August 8, 2026 · model on record in the stance chip above.