Pith. sign in

REVIEW 4 major objections 7 minor 120 references

Engineering Trustworthy Machine-Learning Operations with Zero-Knowledge Proofs

T0 review · 4 major / 7 minor · reviewed 2026-08-07 · deepseek-v4-flash

Pith's one-line read A systematic survey maps zero-knowledge ML verification to lifecycle phases and finds inference dominates, with data and training under-explored.

desk verdict A genuinely useful survey synthesis with a real gap map, but the headline inference-dominance claim needs sensitivity analysis and the paper has internal inconsistencies that must be fixed. read the letter →

arxiv 2505.20136 v1 pith:GB6JYF4Z submitted 2025-05-26 cs.SE cs.CR

classification cs.SEcs.CR
keywords zero-knowledgeproofsmachinelearningverificationMLOpslifecycletrustworthyAIverifiableinferencesystematicliteraturereviewZKMLOpsEUAct
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

This paper tries to establish where zero-knowledge proofs (ZKPs) stand in machine-learning verification by running two systematic literature reviews. The first review distills ZKP protocols into five properties—non-interactivity, transparent setup, standard representations, succinctness, and post-quantum security—that matter for proving computations in ML pipelines. The second review maps ZKP-enhanced ML applications onto a four-phase MLOps lifecycle adapted from the Team Data Science Process (data and preprocessing; training and offline metrics; inference; online metrics). The headline finding is distributional: twelve papers address inference verification, while only two address data and preprocessing and four address training and offline metrics, so the field's center of gravity sits at inference—which matters because regulated AI needs tamper-proof evidence for the earlier stages where bias and data misuse originate. The paper also claims that the literature is converging on a unified zero-knowledge machine-learning operations (ZKMLOps) framework for trustworthy AI, a claim that depends on how representative the surveyed corpus is.

What carries the argument

The central object is the four-phase MLOps verification lifecycle derived from the Team Data Science Process (TDSP): Data and Preprocessing Verification, Training and Offline Metrics Verification, Inference Verification, and Online Metrics Verification. Every surveyed ZKP-enhanced ML application is bucketed into one or more of these phases, and every protocol is scored against a five-property suitability model for ML (non-interactivity, transparent setup, standard representations, succinctness, post-quantum security). The phase assignment carries the argument: it converts a heterogeneous set of surveyed works into a distribution showing inference dominating and early stages under-served, and it supplies the structure on which the convergence-to-ZKMLOps claim rests.

What would settle it

Re-run the second systematic review with the excluded preprint archive included and with the ten deferred federated-learning papers labeled by the same four phases, then recompute the phase counts. If inference verification no longer outnumbers the other three phases combined, or if data and training labels grow to match the twelve inference labels, the paper's central distributional claim and the ZKMLOps convergence trend would be contradicted by its own method.

Watch

Extended reading notes

Core claim

On its own terms, the paper's central claim is that ZKP research for machine learning is not uniformly distributed across the MLOps lifecycle and is not heading in several directions at once. It claims current work concentrates on inference verification—proving that a deployed model produced a given prediction from a given input without revealing model or data—while the data preprocessing and training stages, where bias and data misuse originate, remain underexplored. It further claims that the reviewed systems, despite different protocols and models (decision trees, SVMs, CNNs, LLMs, recommender systems), are partial realizations of a single emerging pattern: a unified ZKMLOps framework that uses ZKPs for correctness, integrity, and privacy across the pipeline, aligned with principles of trustworthy AI and with the EU AI Act's demand for auditable evidence. The support is a systematic mapping: of the analyzed contributions, 12 carry inference-verification labels, 4 carry training/offline-metrics labels, 4 carry online-metrics labels, and only 2 carry data-preprocessing labels, with several works spanning more than one phase.

Load-bearing premise

The load-bearing premise is that two exclusions—dropping preprint-archive results from the ML review and deferring ten federated-learning papers that do use ZKP—do not change the distribution of work across lifecycle phases; if they do, the inference-dominance claim and the convergence trend lose support.

Editorial extensions

If this is right

  • If the mapping is right, teams building verifiable ML-as-a-service should expect the most mature off-the-shelf tooling to cover inference correctness, not training or data provenance.
  • Regulators and auditors cannot yet rely on end-to-end cryptographic evidence covering data ingestion through deployment; the early stages are open gaps that future work must fill.
  • The five-property protocol screen gives adopters a concrete checklist—non-interactive, transparent setup, standard representations, succinct, post-quantum—for choosing a proof system.
  • Research effort should shift toward training proofs and data-preprocessing proofs, the two stages where the survey finds the fewest systems.
  • The convergence claim implies that new ZKML systems will increasingly reuse and extend a shared framework rather than invent per-model protocols.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The phase counts are computed only after excluding a preprint archive from the ML review and deferring ten federated-learning papers that do use ZKP; if those works largely verify local updates or data properties, the 'inference dominates' headline could be a corpus effect rather than a field property.
  • A direct test of the convergence claim is to run the same four-phase bucketing with the deferred papers included: a still-inference-heavy distribution would strengthen ZKMLOps, while a balanced one would suggest the framework is imposed by the survey design.
  • The paper's three-class structure (enabling technologies, applied verification, trustworthy AI) reads as a prediction that future systems will increasingly be positioned as components of a shared verification stack, not as standalone protocols.
Share X Bluesky LinkedIn Reddit HN

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

4 major / 7 minor

Summary. The paper presents two systematic literature reviews. The first surveys zero-knowledge proof (ZKP) protocols and distills five properties that the authors argue are critical for applying ZKPs to machine-learning verification: non-interactivity, transparent setup, standard representations, succinctness, and post-quantum security. The second surveys ZKP-enhanced ML applications and maps them onto a four-phase adaptation of the Team Data Science Process (TDSP): Data & Preprocessing, Training & Offline Metrics, Inference, and Online Metrics. Based on this mapping, the paper claims that current research is concentrated on inference verification, that data preprocessing and training are underexplored, and that the literature is converging toward a unified framework the authors call ZKMLOps.

Significance. If the distributional and convergence claims are correct, the paper provides a useful structured map of a rapidly growing research area and a plausible set of open problems for the software-engineering community. The TDSP-based lifecycle framing, the per-work categorization of verification objectives, models, and protocols, and the provision of a replication package are strengths that go beyond a typical narrative survey. The protocol-suitability criteria, while contestable, give practitioners a concrete checklist for selecting ZKP schemes. However, the central empirical claims are only as strong as the corpus on which they are computed, and the current manuscript leaves the most important corpus decisions insufficiently justified and internally inconsistent in places.

major comments (4)
  1. [§4.2.1, §6.1, §6.3.1] The headline claim that ZKP-enhanced ML research primarily focuses on inference verification while data preprocessing and training remain underexplored is computed from a corpus that excludes the Cryptology ePrint Archive (based on an asserted pilot in §4.2.1) and defers all 10 federated-learning papers that employ ZKP techniques (§6.1). The phase counts in §6.3.1 (2 data, 4 training, 12 inference, 4 online) are derived only from the 17 MLaaS papers. Since FL-ZKP work is largely concerned with training updates, aggregation integrity, and data properties, restoring these papers could materially shift the counts toward earlier lifecycle stages. The authors should either include these excluded works in the phase analysis or provide a documented, reproducible sensitivity analysis showing that the distribution and the convergence narrative are robust to the exclusions.
  2. [Abstract, §5, §5.8, §8] The paper gives three different accounts of the 'key properties' of ZKP protocols. The Abstract and §5.8 list non-interactivity, transparent setup, standard representations, succinctness, and post-quantum security; the opening of §5 lists seven dimensions (interactivity, guarantees, setup, representation, post-quantum security, succinctness, theoretical performance); and §8 lists 'interactivity, guarantees, setup requirements, computational representation, and succinctness' as the five core properties. Since Figure 4 and §6.3.1 grade the surveyed ML works against the §5.8 criteria, the criteria must be stated consistently and the Figure 4 result ('no phase is fully compliant') should be tied to a single, well-defined property list.
  3. [Table 1, §5.5] Table 1 marks Marlin and Spartan as 'Post-Quantum Sec. Yes', but §5.5 states that SNARK-based protocols such as Groth16, Plonk, and Marlin rely on elliptic-curve and pairing assumptions and therefore 'cannot be considered post-quantum secure'. This is a direct internal contradiction in a table that is central to the protocol-suitability analysis. The table should be corrected or the text should explain why Marlin and Spartan are exceptions, with citations.
  4. [§6.1, §6.2, References] The analyzed set is described as the 17 MLaaS papers [87]–[103], but §6.2 discusses Garg et al. [107] without including it in that set, and the range [87]–[103] contains [95] (Lu et al.), which receives no analysis paragraph. The reference list also contains duplicates: [63] and [89] are both ZEN, and [94] and [105] are both zkCNN. These inconsistencies make it difficult to verify the paper's phase counts and to reproduce the corpus from the text. Please align the enumerated corpus with the papers actually analyzed and consolidate duplicate references.
minor comments (7)
  1. [§4.2.1] The ePrint exclusion would be easier to evaluate if the pilot study were reported with concrete numbers, such as the number of hits screened and the reasons for exclusion, rather than the one-sentence assertion of 'a lack of directly relevant work'.
  2. [Figure 4] The heatmap-style figure reports 25%, 50%, 75%, and 100% compliance but does not define how a paper is scored as satisfying a property; a short scoring rubric in the text would make the figure reproducible.
  3. [Table 2] The Wolverine row contains 'NA' for all three performance columns without explanation, and the GKR entries are ambiguous about whether the costs are per round or total; adding a footnote would clarify the table.
  4. [§6.1] The text says '31 papers on MLaaS' and then '30 papers addressing MLaaS' in the same paragraph; the count should be reconciled.
  5. [Figure 2] The label 'Succintness' in Figure 2 is misspelled; it should read 'Succinctness'.
  6. [§8] The conclusion's list of 'five core ZKP properties' does not match the abstract or §5.8; this should be fixed as part of the consistency pass.
  7. [Replication package] The replication package is referenced with a tinyurl; for a journal submission, a persistent identifier such as a DOI or a repository link would be more durable.

Circularity Check

0 steps flagged · score 0.0 of 10

No significant circularity: the survey's protocol-suitability rubric and ZKMLOps convergence classification are interpretive survey apparatus, not predictions that reduce by construction to their own inputs.

full rationale

This paper is a two-part systematic literature review with no fitted parameters and no equations linking inputs to outputs, so the canonical circularity patterns (self-definitional derivations, fitted parameters renamed as predictions, self-citation chains) do not arise. The five protocol-suitability properties in Section 5.8 are presented as an analytic rubric derived from the protocol survey, and using that rubric in Section 6.3.1 and Figure 4 to grade the 17 MLaaS papers is standard survey practice: the 'no phase is fully compliant' result is a consequence of the authors' chosen criteria, not a prediction statistically forced by a fit. The ZKMLOps convergence claim in Section 6.3.2 is an interpretive classification of the surveyed papers into three author-defined classes (Enabling Technologies, Applied Verification, Trustworthy AI) and into the four TDSP-derived lifecycle phases; it is a synthesis judgment, not a derivation that equals its input by definition. The excluded corpora—the Cryptology ePrint Archive in Section 4.2.1 and the ten FL papers using ZKP techniques in Section 6.1—pose a corpus-representativeness and correctness risk for the 'inference dominance' and 'training gap' findings, but sampling scope is not circularity. No load-bearing self-citations, imported uniqueness theorems, or ansatz-by-citation patterns were found. Accordingly, the appropriate finding is no significant circularity.

Assumptions & free parameters 3 free parameters · 4 assumptions · 1 invented entities

The paper makes no numeric fits. Its burden is conceptual: the headline findings depend on hand-chosen evaluation criteria (five properties), a hand-built phase bucketing of TDSP, and a corpus with two exclusions (ePrint in the ML SLR, and 10 FL ZKP papers). The ZKMLOps framework is an invented conceptual entity whose only evidence is the authors' own categorization.

free parameters (3)
  • Five-property suitability criteria
    Non-interactivity, transparent setup, standard representations, succinctness, and post-quantum security are selected by the authors as the criteria for ZKP-ML suitability (Section 5.8); no external benchmark justifies this exact choice, and Section 8 lists a different set of five.
  • TDSP bucketing into four verification phases
    The nine TDSP phases are collapsed into four verification buckets (Figure 1); the bucketing is a modeling choice that shapes all phase counts and the 'inference dominant' conclusion.
  • Corpus size and composition = 57 papers (30 protocols; 17 MLaaS ZKP papers analyzed)
    The counts depend on inclusion and exclusion decisions, including excluding Cryptology ePrint Archive from the ML review (Section 4.2.1) and deferring 10 FL papers that use ZKP (Section 6.1); different corpus boundaries would change the phase distribution and the convergence finding.
assumptions (4)
  • domain assumption The 30 selected protocol papers are representative of ZKP protocol landscapes relevant to ML.
    Screening discarded papers that merely apply ZKPs without novel protocol insight (Section 4.1.2); this boundaries the Table 1 and Table 2 characterization.
  • domain assumption The 57-paper corpus (with ePrint excluded and 10 FL ZKP papers deferred) is representative enough for the inference-dominance and convergence findings.
    Section 4.2.1 excludes ePrint after a pilot study; Section 6.1 defers 10 FL ZKP papers; the central distributional claims depend on these boundaries.
  • ad hoc to paper The five key properties are the correct criteria for ZKP-ML suitability.
    Section 5.8 asserts the criteria, which are then used to grade the corpus in Figure 4, partly determining the 'no full compliance' finding.
  • ad hoc to paper The convergence toward ZKMLOps is a property of the literature, not an artifact of the categorization.
    Section 6.3.2 and Figure 5; the three-class scheme (Enabling, Applied, Trustworthy AI) is the authors' construction, and the convergence conclusion is drawn from that scheme.
invented entities (1)
  • ZKMLOps framework
    purpose: Unified conceptual framework for ZKP-based verification across the MLOps lifecycle.
    Named and defined in Section 6.3.2; its evidence is the authors' own categorization of 17 papers in Figure 5, not an independently testable prediction.

how reviews work

0 comments
Cite this review

Pith. "Pith review of Engineering Trustworthy Machine-Learning Operations with Zero-Knowledge Proofs." pith.science (2026). https://pith.science/paper/GB6JYF4Z

@misc{pith2026250520136,
  author       = {Pith},
  title        = {Pith review of: Engineering Trustworthy Machine-Learning Operations with Zero-Knowledge Proofs},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/GB6JYF4Z}},
  note         = {Machine review of arXiv:2505.20136}
}
read the original abstract

As Artificial Intelligence (AI) systems, particularly those based on machine learning (ML), become integral to high-stakes applications, their probabilistic and opaque nature poses significant challenges to traditional verification and validation methods. These challenges are exacerbated in regulated sectors requiring tamper-proof, auditable evidence, as highlighted by apposite legal frameworks, e.g., the EU AI Act. Conversely, Zero-Knowledge Proofs (ZKPs) offer a cryptographic solution that enables provers to demonstrate, through verified computations, adherence to set requirements without revealing sensitive model details or data. Through a systematic survey of ZKP protocols, we identify five key properties (non-interactivity, transparent setup, standard representations, succinctness, and post-quantum security) critical for their application in AI validation and verification pipelines. Subsequently, we perform a follow-up systematic survey analyzing ZKP-enhanced ML applications across an adaptation of the Team Data Science Process (TDSP) model (Data & Preprocessing, Training & Offline Metrics, Inference, and Online Metrics), detailing verification objectives, ML models, and adopted protocols. Our findings indicate that current research on ZKP-Enhanced ML primarily focuses on inference verification, while the data preprocessing and training stages remain underexplored. Most notably, our analysis identifies a significant convergence within the research domain toward the development of a unified Zero-Knowledge Machine Learning Operations (ZKMLOps) framework. This emerging framework leverages ZKPs to provide robust cryptographic guarantees of correctness, integrity, and privacy, thereby promoting enhanced accountability, transparency, and compliance with Trustworthy AI principles.

Figures

Figures reproduced from arXiv: 2505.20136 by the authors.

Figure 1
Figure 1. At the top, the diagram depicts the nine phases of the TDSP model [ [PITH_FULL_IMAGE:figures/full_fig_p005_1.png] view at source ↗
Figure 2
Figure 2. Core properties of ZKP protocols in the context of ML tasks. Each [PITH_FULL_IMAGE:figures/full_fig_p008_2.png] view at source ↗
Figure 3
Figure 3. ZKP-Enhanced ML applications in the MLOps verification lifecycle. [PITH_FULL_IMAGE:figures/full_fig_p012_3.png] view at source ↗
Figures from the paper (2 more)
Figure 4
Figure 4. Figure 4: ZKP Protocols suitability to ML Applications for every MLOps [PITH_FULL_IMAGE:figures/full_fig_p012_4.png]
Figure 5
Figure 5. Figure 5: Emerging structure of ZKML contributions, showing convergence [PITH_FULL_IMAGE:figures/full_fig_p013_5.png]

Discussion (0). Sign in to comment.

Reference graph

Works this paper leans on

120 extracted references · 71 canonical work pages

  1. [87]

    Zero- Knowledge Proofs of Training for Deep Neural Networks,

    K. Abbaszadeh, C. Pappas, J. Katz, and D. Papadopoulos, “Zero- Knowledge Proofs of Training for Deep Neural Networks,” in Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’24. New York, NY , USA: Association for Computing Machinery , Dec. 2024, pp. 4316–4330

  2. [103]

    V eriML: Enabling Integrity Assurances and Fair Payments for Machine Learning as a Service,

    L. Zhao, Q. Wang, C. Wang, Q. Li, C. Shen, and B. Feng, “V eriML: Enabling Integrity Assurances and Fair Payments for Machine Learning as a Service,”IEEE T ransactions on Parallel and Distributed Systems, vol. 32, no. 10, pp. 2524–2540, Oct. 2021

  3. [107]

    Succinct zero knowledge for floating point computations,

    S. Garg, A. Jain, Z. Jin, and Y . Zhang, “Succinct zero knowledge for floating point computations,” in Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security, 2022, pp. 1203–1216

  4. [95]

    An Efficient and Extensible Zero-knowledge Proof Framework for Neural Networks,

    T. Lu, H. Wang, W. Qu, Z. Wang, J. He, T. Tao, W. Chen, and J. Zhang, “An Efficient and Extensible Zero-knowledge Proof Framework for Neural Networks,” 2024

  5. [63]

    Zen: An optimizing compiler for verifiable, zero-knowledge neural network inferences,

    B. Feng, L. Qin, Z. Zhang, Y . Ding, and S. Chu, “Zen: An optimizing compiler for verifiable, zero-knowledge neural network inferences,” Cryptology ePrint Archive, 2021

  6. [89]

    ZEN: An Optimizing Compiler for V erifiable, Zero-Knowledge Neural Network Inferences,

    B. Feng, L. Qin, Z. Zhang, Y . Ding, and S. Chu, “ZEN: An Optimizing Compiler for V erifiable, Zero-Knowledge Neural Network Inferences,” 2021

  7. [94]

    zkCNN: Zero Knowledge Proofs for Convolutional Neural Network Predictions and Accuracy ,

    T. Liu, X. Xie, and Y . Zhang, “zkCNN: Zero Knowledge Proofs for Convolutional Neural Network Predictions and Accuracy ,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’21. New York, NY , USA: Association for Computing Machinery , Nov . 2021, pp. 2968–2985. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING TO A...

  8. [105]

    zkcnn: Zero knowledge proofs for convolutional neural network predictions and accuracy ,

    T. Liu, X. Xie, and Y . Zhang, “zkcnn: Zero knowledge proofs for convolutional neural network predictions and accuracy ,” in Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security, 2021, pp. 2968–2985

Show all 120 references
  1. [1]

    Autonomous car driving using deep learning,

    N. Darapaneni, P . R. R, A. Reddy Paduri, E. Anand, K. Rajarathinam, P . T. Eapen, S. K, and S. Krishnamurthy , “Autonomous car driving using deep learning,” in2021 2nd International Conference on Secure Cyber Computing and Communications (ICSCCC), 2021, pp. 29–33

  2. [2]

    Machine learning methods for predictive analytics in health care,

    A. Bansal, A. K. Shukla, and S. Bansal, “Machine learning methods for predictive analytics in health care,” in2021 10th International Conference on System Modeling & Advancement in Research T rends (SMART), 2021, pp. 258–262

  3. [3]

    Ai governance in the public sector: Three tales from the frontiers of automated decision-making in demo- cratic settings,

    M. Kuziemski and G. Misuraca, “Ai governance in the public sector: Three tales from the frontiers of automated decision-making in demo- cratic settings,”T elecommunications Policy, vol. 44, no. 6, p. 101976, 2020, artificial intelligence, economy and society . [Online]. Availa...

  4. [4]

    Trustworthy artificial intelligence: a review,

    D. Kaur, S. Uslu, K. J. Rittichier, and A. Durresi, “Trustworthy artificial intelligence: a review,”ACM computing surveys (CSUR), vol. 55, no. 2, pp. 1–38, 2022

  5. [5]

    Software verification and validation: an overview,

    D. R. Wallace and R. U. Fujii, “Software verification and validation: an overview,”Ieee Software, vol. 6, no. 3, pp. 10–17, 1989

  6. [6]

    Systematic literature review of validation methods for ai systems,

    L. Myllyaho, M. Raatikainen, T. M ¨annist¨o, T. Mikkonen, and J. Nurminen, “Systematic literature review of validation methods for ai systems,”ArXiv, vol. abs/2107.12190, 2021

  7. [7]

    Availability and reporting quality of external validations of machine-learning prediction models with orthopedic surgical outcomes: a systematic review,

    O. Groot, B. Bindels, P . Ogink, N. D. Kapoor, P . K. Twining, A. Collins, M. Bongers, A. Lans, J. Oosterhoff, A. Karhade, J. V erlaan, and J. Schwab, “Availability and reporting quality of external validations of machine-learning prediction models with orthopedic surgical out...

  8. [8]

    Auditing black-box models for indirect influence,

    P . Adler, C. Falk, S. A. Friedler, T. Nix, G. Rybeck, C. Scheidegger, B. Smith, and S. V enkatasubramanian, “Auditing black-box models for indirect influence,”Knowledge and Information Systems, vol. 54, pp. 95 – 122, 2016

  9. [9]

    EU AI Act: First regulation on artificial intelligence,

    “EU AI Act: First regulation on artificial intelligence,” https://tinyurl.com/EU-AI-Act-PDF, Aug. 2023. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING TO APPEAR, 2026 14

  10. [10]

    The knowledge complexity of interactive proof-systems,

    S. Goldwasser, S. Micali, and C. Rackoff, “The knowledge complexity of interactive proof-systems,” inProviding sound foundations for cryptog- raphy: On the work of shafi goldwasser and silvio micali, 2019, pp. 203–225

  11. [11]

    Zero-knowledge proof meets machine learning in verifiability: A survey ,

    Z. Xing, Z. Zhang, J. Liu, Z. Zhang, M. Li, L. Zhu, and G. Russello, “Zero-knowledge proof meets machine learning in verifiability: A survey ,”arXiv preprint arXiv:2310.14848, 2023

  12. [12]

    Software engineering for machine learning: A case study ,

    S. Amershi, A. Begel, C. Bird, R. DeLine, H. Gall, E. Kamar, N. Nagappan, B. Nushi, and T. Zimmermann, “Software engineering for machine learning: A case study ,” in 2019 IEEE/ACM 41st International Conference on Software Engineering: Software Engineering in Practice (ICSE-SEI...

  13. [13]

    Trustworthy artificial intelligence,

    S. Thiebes, S. Lins, and A. Sunyaev , “Trustworthy artificial intelligence,” Electronic Markets, vol. 31, no. 2, pp. 447–464, Jun. 2021

  14. [14]

    Trustworthy AI: A Computational Perspective,

    H. Liu, Y . Wang, W. Fan, X. Liu, Y . Li, S. Jain, Y . Liu, A. Jain, and J. Tang, “Trustworthy AI: A Computational Perspective,”ACM T rans. Intell. Syst. T echnol., vol. 14, no. 1, pp. 4:1–4:59, Nov . 2022

  15. [15]

    Trustworthy AI: From Principles to Practices,

    B. Li, P . Qi, B. Liu, S. Di, J. Liu, J. Pei, J. Yi, and B. Zhou, “Trustworthy AI: From Principles to Practices,”ACM Computing Surveys, vol. 55, no. 9, pp. 1–46, Sep. 2023

  16. [16]

    Connecting the dots in trustworthy Artificial Intelligence: From AI principles, ethics, and key requirements to responsible AI systems and regulation,

    N. D ´ıaz-Rodr´ıguez, J. Del Ser, M. Coeckelbergh, M. L ´opez de Prado, E. Herrera-Viedma, and F. Herrera, “Connecting the dots in trustworthy Artificial Intelligence: From AI principles, ethics, and key requirements to responsible AI systems and regulation,”Information Fusion...

  17. [17]

    Black-box access is insufficient for rigorous ai audits,

    S. Casper, C. Ezell, C. Siegmann, N. Kolt, T. L. Curtis, B. Bucknall, A. Haupt, K. Wei, J. Scheurer, M. Hobbhahnet al., “Black-box access is insufficient for rigorous ai audits,” inProceedings of the 2024 ACM Con- ference on Fairness, Accountability, and T ransparency, 2024, p...

  18. [18]

    Goldreich,Foundations of cryptography: volume 2, basic applications

    O. Goldreich,Foundations of cryptography: volume 2, basic applications. Cambridge university press, 2001, vol. 2

  19. [19]

    How to prove yourself: Practical solutions to identification and signature problems,

    A. Fiat and A. Shamir, “How to prove yourself: Practical solutions to identification and signature problems,” inConference on the theory and application of cryptographic techniques. Springer, 1986, pp. 186–194

  20. [20]

    Random oracles are practical: A paradigm for designing efficient protocols,

    M. Bellare and P . Rogaway , “Random oracles are practical: A paradigm for designing efficient protocols,” in Proceedings of the 1st ACM Conference on Computer and Communications Security, 1993, pp. 62–73

  21. [21]

    Non-interactive zero-knowledge and its applications,

    M. Blum, P . Feldman, and S. Micali, “Non-interactive zero-knowledge and its applications,” inProviding Sound Foundations for Cryptography: On the Work of Shafi Goldwasser and Silvio Micali, 2019, pp. 329–349

  22. [22]

    Constant-size commitments to polynomials and their applications,

    A. Kate, G. M. Zaverucha, and I. Goldberg, “Constant-size commitments to polynomials and their applications,” inInternational conference on the theory and application of cryptology and information security. Springer, 2010, pp. 177–194

  23. [23]

    Understanding deep neural networks with rectified linear units,

    R. Arora, A. Basu, P . Mianjy , and A. Mukherjee, “Understanding deep neural networks with rectified linear units,” 2018. [Online]. Available: https://arxiv .org/abs/1611.01491

  24. [24]

    Scaling up trustless dnn inference with zero-knowledge proofs,

    D. Kang, T. Hashimoto, I. Stoica, and Y . Sun, “Scaling up trustless dnn inference with zero-knowledge proofs,” 2022. [Online]. Available: https://arxiv .org/abs/2210.08674

  25. [25]

    A Survey on the Applications of Zero-Knowledge Proofs,

    R. Lavin, X. Liu, H. Mohanty , L. Norman, G. Zaarour, and B. Krishnamachari, “A Survey on the Applications of Zero-Knowledge Proofs,” Aug. 2024, arXiv:2408.00243 [cs]. [Online]. Available: http://arxiv .org/abs/2408.00243

  26. [26]

    A Survey of Zero-Knowledge Proof Based V erifiable Machine Learning,

    Z. Peng, T. Wang, C. Zhao, G. Liao, Z. Lin, Y . Liu, B. Cao, L. Shi, Q. Yang, and S. Zhang, “A Survey of Zero-Knowledge Proof Based V erifiable Machine Learning,” Feb. 2025, arXiv:2502.18535 [cs]. [Online]. Available: http://arxiv .org/abs/2502.18535

  27. [27]

    A framework for cryptographic verifiability of end-to-end ai pipelines,

    K. Balan, R. Learney , and T. Wood, “A framework for cryptographic verifiability of end-to-end ai pipelines,”arXiv preprint arXiv:2503.22573, 2025

  28. [28]

    Systematic literature reviews in software engineering–a systematic literature review,

    B. Kitchenham, O. P . Brereton, D. Budgen, M. Turner, J. Bailey , and S. Linkman, “Systematic literature reviews in software engineering–a systematic literature review,” Information and software technology, vol. 51, no. 1, pp. 7–15, 2009

  29. [29]

    Control- theoretical software adaptation: A systematic literature review,

    S. Shevtsov , M. Berekmeri, D. Weyns, and M. Maggio, “Control- theoretical software adaptation: A systematic literature review,”IEEE T ransactions on Software Engineering, vol. 44, no. 8, pp. 784–810, 2018

  30. [30]

    Crisp-dm: Towards a standard process model for data mining,

    R. Wirth and J. Hipp, “Crisp-dm: Towards a standard process model for data mining,” inProceedings of the 4th international conference on the practical applications of knowledge discovery and data mining, vol. 1. Manchester, 2000, pp. 29–39

  31. [31]

    The kdd process for extracting useful knowledge from volumes of data,

    U. Fayyad, G. Piatetsky-Shapiro, and P . Smyth, “The kdd process for extracting useful knowledge from volumes of data,”Communications of the ACM, vol. 39, no. 11, pp. 27–34, 1996

  32. [32]

    Recursive Proof Composition without a Trusted Setup,

    S. Bowe, J. Grigg, and D. Hopwood, “Recursive Proof Composition without a Trusted Setup,” 2019

  33. [33]

    PLONK: Permutations over Lagrange-bases for Oecumenical Noninteractive arguments of Knowledge,

    A. Gabizon, Z. J. Williamson, and O. Ciobotaru, “PLONK: Permutations over Lagrange-bases for Oecumenical Noninteractive arguments of Knowledge,” 2019

  34. [34]

    Scalable, transparent, and post-quantum secure computational integrity ,

    E. Ben-Sasson, I. Bentov , Y . Horesh, and M. Riabzev , “Scalable, transparent, and post-quantum secure computational integrity ,” 2018

  35. [35]

    Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS,

    A. Chiesa, Y . Hu, M. Maller, P . Mishra, N. V esely , and N. W ard, “Marlin: Preprocessing zkSNARKs with Universal and Updatable SRS,” in Advances in Cryptology – EUROCRYPT 2020, A. Canteaut and Y . Ishai, Eds. Cham: Springer International Publishing, 2020, pp. 738–768

  36. [36]

    Sonic: Zero-Knowledge SNARKs from Linear-Size Universal and Updatable Structured Reference Strings,

    M. Maller, S. Bowe, M. Kohlweiss, and S. Meiklejohn, “Sonic: Zero-Knowledge SNARKs from Linear-Size Universal and Updatable Structured Reference Strings,” inProceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’19. New York, NY , USA:...

  37. [37]

    Spartan: Efficient and General-Purpose zkSNARKs Without Trusted Setup,

    S. Setty , “Spartan: Efficient and General-Purpose zkSNARKs Without Trusted Setup,” inAdvances in Cryptology – CRYPTO 2020, D. Micciancio and T. Ristenpart, Eds. Cham: Springer International Publishing, 2020, pp. 704–737

  38. [38]

    Transparent SNARKs from DARK Compilers,

    B. B ¨unz, B. Fisch, and A. Szepieniec, “Transparent SNARKs from DARK Compilers,” inAdvances in Cryptology – EUROCRYPT 2020, A. Canteaut and Y . Ishai, Eds. Cham: Springer International Publishing, 2020, pp. 677–706

  39. [39]

    Aurora: Transparent Succinct Arguments for R1CS,

    E. Ben-Sasson, A. Chiesa, M. Riabzev , N. Spooner, M. Virza, and N. P . Ward, “Aurora: Transparent Succinct Arguments for R1CS,” in Advances in Cryptology – EUROCRYPT 2019, Y . Ishai and V . Rijmen, Eds. Cham: Springer International Publishing, 2019, pp. 103–128

  40. [40]

    Fractal: Post-quantum and Transparent Recursive Proofs from Holography ,

    A. Chiesa, D. Ojha, and N. Spooner, “Fractal: Post-quantum and Transparent Recursive Proofs from Holography ,” inAdvances in Cryptology – EUROCRYPT 2020, A. Canteaut and Y . Ishai, Eds. Cham: Springer International Publishing, 2020, pp. 769–793

  41. [41]

    On the Size of Pairing-Based Non-interactive Arguments,

    J. Groth, “On the Size of Pairing-Based Non-interactive Arguments,” in Advances in Cryptology – EUROCRYPT 2016, M. Fischlin and J.-S. Coron, Eds. Berlin, Heidelberg: Springer, 2016, pp. 305–326

  42. [42]

    Bulletproofs: Short Proofs for Confidential Transactions and More,

    B. B¨unz, J. Bootle, D. Boneh, A. Poelstra, P . Wuille, and G. Maxwell, “Bulletproofs: Short Proofs for Confidential Transactions and More,” in 2018 IEEE Symposium on Security and Privacy (SP), May 2018, pp. 315–334

  43. [43]

    Ligero: Lightweight Sublinear Arguments Without a Trusted Setup,

    S. Ames, C. Hazay , Y . Ishai, and M. V enkitasubramaniam, “Ligero: Lightweight Sublinear Arguments Without a Trusted Setup,” in Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’17. New York, NY , USA: Association for Computing M...

  44. [44]

    Delegating Computation: Interactive Proofs for Muggles,

    S. Goldwasser, Y . T. Kalai, and G. N. Rothblum, “Delegating Computation: Interactive Proofs for Muggles,”J. ACM, vol. 62, no. 4, pp. 27:1–27:64, Sep. 2015

  45. [45]

    Wolverine: Fast, Scalable, and Communication-Efficient Zero-Knowledge Proofs for Boolean and Arithmetic Circuits,

    C. Weng, K. Yang, J. Katz, and X. Wang, “Wolverine: Fast, Scalable, and Communication-Efficient Zero-Knowledge Proofs for Boolean and Arithmetic Circuits,” in2021 IEEE Symposium on Security and Privacy (SP), May 2021, pp. 1074–1091

  46. [46]

    Pinocchio: Nearly practical verifiable computation,

    B. Parno, J. Howell, C. Gentry , and M. Raykova, “Pinocchio: Nearly practical verifiable computation,”Commun. ACM, vol. 59, no. 2, pp. 103–112, Jan. 2016

  47. [47]

    Non-interactive zero- knowledge proof systems,

    A. De Santis, S. Micali, and G. Persiano, “Non-interactive zero- knowledge proof systems,” inAdvances in Cryptology—CRYPTO’87: Proceedings 7. Springer, 1988, pp. 52–72

  48. [48]

    Zero-knowledge using garbled circuits: how to prove non-algebraic statements efficiently ,

    M. Jawurek, F. Kerschbaum, and C. Orlandi, “Zero-knowledge using garbled circuits: how to prove non-algebraic statements efficiently ,” in Proceedings of the 2013 ACM SIGSAC conference on Computer & communications security, 2013, pp. 955–966

  49. [49]

    Fiat-shamir: from practice to theory ,

    R. Canetti, Y . Chen, J. Holmgren, A. Lombardi, G. N. Rothblum, R. D. Rothblum, and D. Wichs, “Fiat-shamir: from practice to theory ,” in Proceedings of the 51st Annual ACM SIGACT Symposium on Theory of Computing, 2019, pp. 1082–1090

  50. [50]

    Definitions and properties of zero- knowledge proof systems,

    O. Goldreich and Y . Oren, “Definitions and properties of zero- knowledge proof systems,”Journal of Cryptology, vol. 7, no. 1, pp. 1–32, 1994

  51. [51]

    Do you need a zero knowledge proof?

    J. Ernstberger, S. Chaliasos, L. Zhou, P . Jovanovic, and A. Gervais, “Do you need a zero knowledge proof?”Cryptology ePrint Archive, 2024

  52. [52]

    Zero- knowledge proof frameworks: A systematic survey ,

    N. Sheybani, A. Ahmed, M. Kinsy , and F. Koushanfar, “Zero- knowledge proof frameworks: A systematic survey ,”arXiv e-prints, pp. arXiv–2502, 2025

  53. [53]

    Announcing the perpetual powers of tau ceremony to benefit all zk-snark projects,

    K. W. Jie, “Announcing the perpetual powers of tau ceremony to benefit all zk-snark projects,” 2019

  54. [54]

    Arithmetic circuits: A survey of recent results and open questions,

    A. Shpilka, A. Yehudayoff et al., “Arithmetic circuits: A survey of recent results and open questions,” Foundations and T rends® in Theoretical Computer Science, vol. 5, no. 3–4, pp. 207–388, 2010. IEEE TRANSACTIONS ON SOFTWARE ENGINEERING TO APPEAR, 2026 15

  55. [55]

    Approximate arithmetic circuits: A survey , characterization, and recent applications,

    H. Jiang, F. J. H. Santiago, H. Mo, L. Liu, and J. Han, “Approximate arithmetic circuits: A survey , characterization, and recent applications,” Proceedings of the IEEE, vol. 108, no. 12, pp. 2108–2135, 2020

  56. [56]

    Study of arithmetization methods for starks,

    T. Martins and J. Farinha, “Study of arithmetization methods for starks,”Cryptology ePrint Archive, 2023

  57. [57]

    Post-quantum zero-knowledge and signatures from symmetric-key primitives,

    M. Chase, D. Derler, S. Goldfeder, C. Orlandi, S. Ramacher, C. Rechberger, D. Slamanig, and G. Zaverucha, “Post-quantum zero-knowledge and signatures from symmetric-key primitives,” in Proceedings of the 2017 acm sigsac conference on computer and communications security, 2017,...

  58. [58]

    Multi- collision resistant hash functions and their applications,

    I. Berman, A. Degwekar, R. D. Rothblum, and P . N. V asudevan, “Multi- collision resistant hash functions and their applications,” inAdvances in Cryptology–EUROCRYPT 2018: 37th Annual International Conference on the Theory and Applications of Cryptographic T echniques, T el Av...

  59. [59]

    Post-quantum zero-knowledge proofs and applications,

    R. Steinfeld, “Post-quantum zero-knowledge proofs and applications,” Proceedings of the 10th ACM Asia Public-Key Cryptography Workshop, 2023

  60. [60]

    A review of zk-snarks,

    T. Chen, H. Lu, T. Kunpittaya, and A. Luo, “A review of zk-snarks,” arXiv preprint arXiv:2202.06877, 2022

  61. [61]

    A benchmark for different implementations of zero-knowledge proof systems,

    M. Kobelt, M. Sober, and S. Schulte, “A benchmark for different implementations of zero-knowledge proof systems,” in2023 IEEE In- ternational Conference on Blockchain (Blockchain). IEEE, 2023, pp. 33–40

  62. [62]

    Non-interactive zero-knowledge proof of knowledge and chosen ciphertext attack,

    C. Rackoff and D. R. Simon, “Non-interactive zero-knowledge proof of knowledge and chosen ciphertext attack,” inAnnual international cryptology conference. Springer, 1991, pp. 433–444

  63. [64]

    LegoSNARK: Modular Design and Composition of Succinct Zero-Knowledge Proofs,

    M. Campanelli, D. Fiore, and A. Querol, “LegoSNARK: Modular Design and Composition of Succinct Zero-Knowledge Proofs,” in Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’19. New York, NY , USA: Association for Computing Machiner...

  64. [65]

    A blockchain-based protocol of trusted setup ceremony for zero-knowledge proof,

    C. Park, M. Chung, and D. Ryu, “A blockchain-based protocol of trusted setup ceremony for zero-knowledge proof,”Proceedings of the 2023 5th Blockchain and Internet of Things Conference, 2023

  65. [66]

    Efficiency of zero-knowledge proofs: A through review and analysis,

    C. P . Sah, M. Kaur, and G. Singh, “Efficiency of zero-knowledge proofs: A through review and analysis,”2024 IEEE International Conference on Public Key Infrastructure and its Applications (PKIA), pp. 1–7, 2024

  66. [67]

    izkp-aka: A secure and improved zkp-aka protocol for sustainable healthcare,

    S. Kumar, K. Kumar, A. Anand, A. K. Y adav , M. Misra, and A. Braeken, “izkp-aka: A secure and improved zkp-aka protocol for sustainable healthcare,”Computers and Electrical Engineering, 2025

  67. [68]

    Linear-time and post-quantum zero-knowledge snarks for r1cs,

    J. Lee, S. Setty , J. Thaler, and R. W ahby , “Linear-time and post-quantum zero-knowledge snarks for r1cs,”Cryptology ePrint Archive, 2021

  68. [69]

    On-demand device authentication using zero-knowledge proofs for smart systems,

    Y . Zhong, J. Hovanes, and U. Guin, “On-demand device authentication using zero-knowledge proofs for smart systems,” inProceedings of the Great Lakes Symposium on VLSI 2023, 2023, pp. 569–574

  69. [70]

    Performance analysis of zero-knowledge proofs,

    S. Samudrala, J. Wu, C. Chen, H. Shan, J. Ku, Y . Chen, and J. Rajendran, “Performance analysis of zero-knowledge proofs,” 2024 IEEE International Symposium on Workload Characterization (IISWC), pp. 144–155, 2024

  70. [71]

    Gzkp: A gpu accelerated zero-knowledge proof system,

    W. Ma, Q. Xiong, X. Shi, X. Ma, H. Jin, H. Kuang, M. Gao, Y . Zhang, H. Shen, and W. Hu, “Gzkp: A gpu accelerated zero-knowledge proof system,”Proceedings of the 28th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume 2, 2023

  71. [72]

    Practical secure aggregation for privacy-preserving machine learning,

    K. Bonawitz, V . Ivanov , B. Kreuter, A. Marcedone, H. B. McMahan, S. Patel, D. Ramage, A. Segal, and K. Seth, “Practical secure aggregation for privacy-preserving machine learning,” inproceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, 2017,...

  72. [73]

    Privacy- preserving machine learning in cloud,

    E. Hesamifard, H. Takabi, M. Ghasemi, and C. Jones, “Privacy- preserving machine learning in cloud,” inProceedings of the 2017 on cloud computing security workshop, 2017, pp. 39–43

  73. [74]

    V eriFL: Communication-Efficient and Fast V erifiable Aggregation for Federated Learning,

    X. Guo, Z. Liu, J. Li, J. Gao, B. Hou, C. Dong, and T. Baker, “V eriFL: Communication-Efficient and Fast V erifiable Aggregation for Federated Learning,”IEEE T ransactions on Information Forensics and Security, vol. 16, pp. 1736–1751, 2021

  74. [75]

    A Secure Federated Learning framework using Homomorphic Encryption and V erifiable Computing,

    A. Madi, O. Stan, A. Mayoue, A. Grivet-S ´ebert, C. Gouy-Pailler, and R. Sirdey , “A Secure Federated Learning framework using Homomorphic Encryption and V erifiable Computing,” in 2021 Reconciling Data Analytics, Automation, Privacy, and Security: A Big Data Challenge (RDAAPS...

  75. [76]

    Universal Interactive V erification Framework for Federated Learning Protocol,

    Z. Cheng, Y . Jiang, X. Huang, and Y . Xia, “Universal Interactive V erification Framework for Federated Learning Protocol,” in Proceedings of the 2021 10th International Conference on Networks, Communication and Computing, ser. ICNCC ’21. New York, NY , USA: Association for C...

  76. [77]

    VFChain: Enabling V erifiable and Auditable Federated Learning via Blockchain Systems,

    Z. Peng, J. Xu, X. Chu, S. Gao, Y . Yao, R. Gu, and Y . Tang, “VFChain: Enabling V erifiable and Auditable Federated Learning via Blockchain Systems,”IEEE T ransactions on Network Science and Engineering, vol. 9, no. 1, pp. 173–186, Jan. 2022

  77. [78]

    Drynx: Decentralized, Secure, V erifiable System for Statistical Queries and Machine Learning on Distributed Datasets,

    D. Froelicher, J. R. Troncoso-Pastoriza, J. S. Sousa, and J.-P . Hubaux, “Drynx: Decentralized, Secure, V erifiable System for Statistical Queries and Machine Learning on Distributed Datasets,”IEEE T ransactions on Information Forensics and Security, vol. 15, pp. 3035–3050, 2020

  78. [79]

    A V erifiable Privacy-Preserving Machine Learning Prediction Scheme for Edge- Enhanced HCPSs,

    X. Li, J. He, P . Vijayakumar, X. Zhang, and V . Chang, “A V erifiable Privacy-Preserving Machine Learning Prediction Scheme for Edge- Enhanced HCPSs,”IEEE T ransactions on Industrial Informatics, vol. 18, no. 8, pp. 5494–5503, Aug. 2022

  79. [80]

    Secure and V erifiable Inference in Deep Neural Networks,

    G. Xu, H. Li, H. Ren, J. Sun, S. Xu, J. Ning, H. Y ang, K. Yang, and R. H. Deng, “Secure and V erifiable Inference in Deep Neural Networks,” in Proceedings of the 36th Annual Computer Security Applications Conference, ser. ACSAC ’20. New York, NY , USA: Association for Computi...

  80. [81]

    zkMLaaS: A V erifiable Scheme for Machine Learning as a Service,

    C. Huang, J. W ang, H. Chen, S. Si, Z. Huang, and J. Xiao, “zkMLaaS: A V erifiable Scheme for Machine Learning as a Service,” inGLOBECOM 2022 - 2022 IEEE Global Communications Conference, Dec. 2022, pp. 5475–5480

  81. [82]

    Privacy-Preserving and V erifiable Cloud-Aided Disease Diagnosis and Prediction With Hyperplane Decision-Based Classifier,

    Y . Shao, C. Tian, L. Han, H. Xian, and J. Yu, “Privacy-Preserving and V erifiable Cloud-Aided Disease Diagnosis and Prediction With Hyperplane Decision-Based Classifier,”IEEE Internet of Things Journal, vol. 9, no. 21, pp. 21 648–21 661, Nov . 2022

  82. [83]

    Hydra: Pipelineable Interactive Arguments of Knowledge for V erifiable Neural Networks,

    W. Zhang and Y . Xia, “Hydra: Pipelineable Interactive Arguments of Knowledge for V erifiable Neural Networks,” in2021 Third IEEE International Conference on T rust, Privacy and Security in Intelligent Systems and Applications (TPS-ISA), Dec. 2021, pp. 1–10

  83. [84]

    TAIRA-BSC - Trusting AI in Recruitment Applications through Blockchain Smart Contracts,

    M. Aleisa, M. Alshahrani, N. Beloff, and M. White, “TAIRA-BSC - Trusting AI in Recruitment Applications through Blockchain Smart Contracts,” in2022 IEEE International Conference on Blockchain (Blockchain), Aug. 2022, pp. 376–383

  84. [85]

    A Scalable Blockchain Approach for Trusted Computation and V erifiable Simu- lation in Multi-Party Collaborations,

    R. K. Raman, R. Vaculin, M. Hind, S. L. Remy , E. K. Pissadaki, N. K. Bore, R. Daneshvar, B. Srivastava, and K. R. Varshney , “A Scalable Blockchain Approach for Trusted Computation and V erifiable Simu- lation in Multi-Party Collaborations,” in2019 IEEE International Con- fer...

  85. [86]

    Machine Learning on Cloud With Blockchain: A Secure, V erifiable and Fair Approach to Outsource the Linear Regression,

    H. Zhang, P . Gao, J. Yu, J. Lin, and N. N. Xiong, “Machine Learning on Cloud With Blockchain: A Secure, V erifiable and Fair Approach to Outsource the Linear Regression,”IEEE T ransactions on Network Science and Engineering, vol. 9, no. 6, pp. 3956–3967, Nov . 2022

  86. [88]

    ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs,

    B.-J. Chen, S. Waiwitlikhit, I. Stoica, and D. Kang, “ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs,” in Proceedings of the Nineteenth European Conference on Computer Systems, ser. EuroSys ’24. New York, NY , USA: Association for Computing Machinery , Ap...

  87. [90]

    ZENO: A Type-based Optimization Framework for Zero Knowledge Neural Network Inference,

    B. Feng, Z. Wang, Y . Wang, S. Yang, and Y . Ding, “ZENO: A Type-based Optimization Framework for Zero Knowledge Neural Network Inference,” in Proceedings of the 29th ACM International Conference on Architectural Support for Programming Languages and Operating Systems, Volume ...

  88. [91]

    Mutually Private V erifiable Machine Learning As-a-service: A Distributed Approach,

    S. Ghaffaripour and A. Miri, “Mutually Private V erifiable Machine Learning As-a-service: A Distributed Approach,” in2021 IEEE World AI IoT Congress (AIIoT), May 2021, pp. 0232–0239

  89. [92]

    Efficient Sum-Check Protocol for Convolution,

    C. Ju, H. Lee, H. Chung, J. H. Seo, and S. Kim, “Efficient Sum-Check Protocol for Convolution,”IEEE Access, vol. 9, pp. 164 047–164 059, 2021

  90. [93]

    vCNN: V erifiable Convolutional Neural Network Based on zk-SNARKs,

    S. Lee, H. Ko, J. Kim, and H. Oh, “vCNN: V erifiable Convolutional Neural Network Based on zk-SNARKs,” IEEE T ransactions on Dependable and Secure Computing, vol. 21, no. 4, pp. 4254–4270, Jul. 2024

  91. [96]

    zkDL: Efficient Zero-Knowledge Proofs of Deep Learning Training,

    H. Sun, T. Bai, J. Li, and H. Zhang, “zkDL: Efficient Zero-Knowledge Proofs of Deep Learning Training,”IEEE T ransactions on Information Forensics and Security, vol. 20, pp. 914–927, 2025

  92. [97]

    zkLLM: Zero Knowledge Proofs for Large Language Models,

    H. Sun, J. Li, and H. Zhang, “zkLLM: Zero Knowledge Proofs for Large Language Models,” inProceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’24. New York, NY , USA: Association for Computing Machinery , Dec. 2024, pp. 4405–4419

  93. [98]

    Fairness as a Service (FaaS): V erifiable and privacy-preserving fairness auditing of machine learning systems,

    E. T oreini, M. Mehrnezhad, and A. van Moorsel, “Fairness as a Service (FaaS): V erifiable and privacy-preserving fairness auditing of machine learning systems,”International Journal of Information Security, vol. 23, no. 2, pp. 981–997, Apr. 2024

  94. [99]

    Trustless Audits without Revealing Data or Models,

    S. W aiwitlikhit, I. Stoica, Y . Sun, T. Hashimoto, and D. Kang, “Trustless Audits without Revealing Data or Models,” Apr. 2024

  95. [100]

    An Efficient and Zero-Knowledge Classical Machine Learning Inference Pipeline,

    H. Wang, R. Bie, and T. Hoang, “An Efficient and Zero-Knowledge Classical Machine Learning Inference Pipeline,”IEEE T ransactions on Dependable and Secure Computing, vol. 22, no. 2, pp. 1347–1364, Mar. 2025

  96. [101]

    Confidential and V erifiable Machine Learning Delegations on the Cloud,

    W . Wu, S. Homsi, and Y . Zhang, “Confidential and V erifiable Machine Learning Delegations on the Cloud,” inComputer Security – ESORICS 2024, J. Garcia-Alfaro, R. Kozik, M. Chora´s, and S. Katsikas, Eds. Cham: Springer Nature Switzerland, 2024, pp. 182–201

  97. [102]

    Zero Knowledge Proofs for Decision Tree Predictions and Accuracy ,

    J. Zhang, Z. Fang, Y . Zhang, and D. Song, “Zero Knowledge Proofs for Decision Tree Predictions and Accuracy ,” inProceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security, ser. CCS ’20. New York, NY , USA: Association for Computing Machinery , Nov ...

  98. [104]

    Aurora: Transparent succinct arguments for r1cs,

    E. Ben-Sasson, A. Chiesa, M. Riabzev , N. Spooner, M. Virza, and N. P . Ward, “Aurora: Transparent succinct arguments for r1cs,” inAdvances in Cryptology–EUROCRYPT 2019: 38th Annual International Conference on the Theory and Applications of Cryptographic T echniques, Darmstadt...

  99. [106]

    Algebraic methods for interactive proof systems,

    C. Lund, L. Fortnow, H. Karloff, and N. Nisan, “Algebraic methods for interactive proof systems,”Journal of the ACM (JACM), vol. 39, no. 4, pp. 859–868, 1992

  100. [108]

    Fairness through awareness,

    C. Dwork, M. Hardt, T. Pitassi, O. Reingold, and R. Zemel, “Fairness through awareness,” inProceedings of the 3rd innovations in theoretical computer science conference, 2012, pp. 214–226

  101. [109]

    A survey on bias and fairness in machine learning,

    N. Mehrabi, F. Morstatter, N. Saxena, K. Lerman, and A. Galstyan, “A survey on bias and fairness in machine learning,”ACM computing surveys (CSUR), vol. 54, no. 6, pp. 1–35, 2021

  102. [110]

    Proofs of partial knowledge and simplified design of witness hiding protocols,

    R. Cramer, I. Damg ˚ard, and B. Schoenmakers, “Proofs of partial knowledge and simplified design of witness hiding protocols,” in Annual International Cryptology Conference. Springer, 1994, pp. 174–187

  103. [111]

    A secure and optimally efficient multi-authority election scheme,

    R. Cramer, R. Gennaro, and B. Schoenmakers, “A secure and optimally efficient multi-authority election scheme,”European transactions on T elecommunications, vol. 8, no. 5, pp. 481–490, 1997

  104. [112]

    Arkworks-rs/snark,

    “Arkworks-rs/snark,” arkworks, May 2025

  105. [113]

    Zkcrypto/bellman,

    “Zkcrypto/bellman,” Zero-knowledge Cryptography in Rust, May 2025

  106. [114]

    HorizenOfficial/ginger-lib,

    “HorizenOfficial/ginger-lib,” Horizen - The Horizen Foundation, Dec. 2024

  107. [115]

    Zcash/halo2,

    “Zcash/halo2,” Zcash, May 2025

  108. [116]

    From airs to raps-how plonk-style arithmetization works,

    A. Gabizon, “From airs to raps-how plonk-style arithmetization works,” 2021

  109. [117]

    Sumcheck arguments and their applications,

    J. Bootle, A. Chiesa, and K. Sotiraki, “Sumcheck arguments and their applications,” inAdvances in Cryptology–CRYPTO 2021: 41st Annual International Cryptology Conference, CRYPTO 2021, Virtual Event, August 16–20, 2021, Proceedings, Part I 41. Springer, 2021, pp. 742–773

  110. [118]

    Doubly- efficient zksnarks without trusted setup,

    R. S. Wahby , I. Tzialla, A. Shelat, J. Thaler, and M. Walfish, “Doubly- efficient zksnarks without trusted setup,” in2018 IEEE Symposium on Security and Privacy (SP). IEEE, 2018, pp. 926–943

  111. [119]

    An efficient and zero-knowledge classical machine learning inference pipeline,

    H. Wang, R. Bie, and T. Hoang, “An efficient and zero-knowledge classical machine learning inference pipeline,”IEEE T ransactions on Dependable and Secure Computing, 2024

  112. [120]

    Trustworthy Artificial Intelligence: A Review,

    D. Kaur, S. Uslu, K. J. Rittichier, and A. Durresi, “Trustworthy Artificial Intelligence: A Review,”ACM Comput. Surv., vol. 55, no. 2, pp. 39:1–39:38, Jan. 2022

Pith tools

Reviewed August 7, 2026 · model on record in the stance chip above.