Pith. sign in

REVIEW 5 major objections 5 minor 64 references

ZORRO: Zero-Knowledge Robustness and Privacy for Split Learning (Full Version)

T0 review · 5 major / 5 minor · reviewed 2026-08-15 · deepseek-v4-flash

Pith's one-line read ZORRO claims zero-knowledge proofs can enforce a client-side frequency-domain defense that reduces split-learning backdoor attack success below 6%.

desk verdict Genuinely novel client-side split-learning defense with solid experiments, but the ZKP enforcement of the pruning step is not actually encoded in Algorithm 2, and the abstract overstates the attack-success claim. read the letter →

arxiv 2509.09787 v1 pith:3YWUI6LV submitted 2025-09-11 cs.CR cs.AI

classification cs.CRcs.AI
keywords splitlearningbackdoordefensepoisoningzero-knowledgeproofsinteractivediscretecosinetransformclient-sidefrequency-domainanalysis
verification ladder T0 review T1 audit T2 compute T3 formal

The pith

A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.

The reading

ZORRO sets out to establish a way to defend split learning against backdoor attacks launched by malicious clients, without making the server the security bottleneck. In the U-shaped split setting, each client owns the head and tail layers, so ZORRO makes the client itself score its freshly trained update by the magnitude of the low-frequency discrete cosine transform coefficients, remove the worst checkpoint from a sliding window, and then generate an interactive zero-knowledge proof that these steps were performed correctly on the exact models the server has committed to. The proof does not reveal model parameters. If it works as claimed, the scheme turns backdoor defense into a cryptographic enforcement problem: a malicious client must either let its poisoned update be pruned or fail verification and be exposed. The paper's evaluation supports this position with backdoor accuracy below 6% in most settings, minimal utility loss, and client-side overhead of under 10 seconds for models with $10^6$ client-side parameters.

What carries the argument

The argument rides on three interlocking pieces. First, a frequency-domain scorer: each head/tail update $U_t$ is viewed as a matrix, transformed by the 2D discrete cosine transform, and the magnitude of the low-frequency coefficients satisfying $u+v<N/2$ is summed with the taxicab ($\ell^1$) norm to give a poison risk score $s_t$; the oldest score is divided by $\beta$ and the newest score is multiplied by $\beta$ to keep training moving when no poison is present. Second, a sliding queue: each client holds $k$ checkpoints plus its new model, removes the highest-scoring checkpoint, and advances a best-model pointer to the lowest-scoring remaining checkpoint. Third, an interactive zero-knowledge proof built on vector oblivious linear evaluation (VOLE) commitments, whose circuit asserts that each model hashes to the server-published commitment, that the claimed DCT is consistent with the committed model through a verifier-chosen randomized matrix-vector check rather than a full in-circuit transform, and that the reported maximum and minimum scores are the true ones. The proof, verified by the next client and the server, is what converts the heuristic scoring rule into an enforceable protocol.

What would settle it

An adaptive attacker who adds a frequency-shaping term to the backdoor objective, minimizing the $\ell^1$ norm of the low-frequency DCT coefficients of the poisoned update, could be tested against ZORRO; if the poisoned checkpoint survives pruning and the defended model still misclassifies triggered inputs, the core detection assumption fails.

Watch

Extended reading notes

Core claim

The central claim is that backdoor poisoning of split learning can be stopped at the client by requiring each client to prove, through an interactive zero-knowledge proof, that it ran a specified frequency-domain hygiene step on its own head and tail update. Concretely, ZORRO appends the freshly trained model $M_i$ to a queue of $k$ checkpoints, computes each update's two-dimensional discrete cosine transform, sums the magnitude of the low-frequency coefficients in the triangle $u+v<N/2$ with the taxicab norm, prunes the highest-scoring checkpoint, and points the next client to the lowest-scoring one; a bias parameter $\beta\in(0,1]$ nudges selection toward recent benign checkpoints. The interactive ZKP attests, without revealing model parameters, that the hash of each model matches the server-committed hash, that the claimed DCT is consistent with the committed model (checked probabilistically with verifier randomness), and that the reported worst and best scores are the true maximum and minimum. The paper claims this forces a malicious client into a dilemma: follow the protocol and let the poison be pruned, or deviate and fail verification, exposing the client. This is the first client-side, ZKP-enforced backdoor defense for split learning, and the reported experiments put backdoor accuracy below 6%, main-task accuracy close to the undefended model, and client-side runtime for $10^6$ parameters under 10 seconds.

Load-bearing premise

The load-bearing premise is that a poisoned client-side head or tail update reliably produces larger low-frequency DCT magnitudes than a benign update trained on non-IID data, so always pruning the highest-scoring checkpoint leaves a benign model in the queue and removes the poison.

Editorial extensions

If this is right

  • A malicious client can no longer keep a poisoned checkpoint in the training chain without detection: either the enforced pruning removes it or the failed proof identifies the client.
  • The defense scales with client count, with the paper reporting low backdoor accuracy even at 1000 clients and with poisoning rates up to 80%.
  • The per-client cost fits edge-device constraints: under 10 seconds of proof overhead for a $10^6$-parameter local model and roughly 0.9 GB peak memory for the largest tested client-side partition.
  • Privacy survives the defense: neither the server nor the next client ever sees raw head or tail parameters, only commitments of those models and proofs of correct processing.
  • Because the ZK circuit is modular, the same enforcement mechanism can attest to other client-side scoring rules, such as an $\ell^2$-norm or clustering-based score, without a new cryptographic design.

Reading between the lines

Editorial extensions of the paper, not claims the author makes directly.

  • The ZKP can prove only that the scoring and pruning were executed faithfully; it cannot prove that low-frequency DCT magnitude separates poison from benign non-IID drift, so the defense's real security bound lives in that empirical separation rather than in the cryptography.
  • A natural attack not explicitly covered would shape the poisoned update to minimize low-frequency DCT energy while preserving trigger effectiveness; if such an attack succeeds, the frequency heuristic itself would be the point of failure, not the proof system.
  • The same enforcement pattern could plausibly be extended to server-side defenses or to other distributed training paradigms, since the circuit verifies generic scoring, argmax, argmin, and pointer updates, although the paper only claims the scheme for its own split-learning setting.
  • The MNIST distraction result suggests that a defended model can still classify triggered inputs into the attacker's target class when no poison survives, so reported backdoor accuracy may overstate residual poisoning in datasets with strong positional or structural bias.
Share X Bluesky LinkedIn Reddit HN

Signed reviews

No signed human review yet.

Editorial analysis

A structured set of objections, weighed in public.

Desk editor's note, referee report, and a circularity audit.

Referee Report

5 major / 5 minor

Summary. The paper presents ZORRO, a client-side backdoor defense for U-shaped split learning. In ZORRO, each client computes discrete-cosine-transform (DCT) based poison risk scores for a queue of recent head/tail checkpoints, prunes the highest-scoring model, updates a best-model pointer, and uses an interactive VOLE-based zero-knowledge proof (built on Wolverine/emp-zk) to attest that this computation was performed honestly. The paper evaluates ZORRO on six datasets, several architectures, different IID degrees, client counts, and adaptive attacks, and reports low backdoor accuracy and modest ZKP overhead for models with up to roughly one million client-side parameters.

Significance. If the cryptographic enforcement claim were correct, ZORRO would be the first client-side, ZKP-enforced backdoor defense for split learning, and the empirical study is genuinely broad: it covers multiple datasets, architectures, poisoning rates, and adaptive attack strategies, and it includes runtime and memory measurements on realistic hardware. The use of Freivald's algorithm to probabilistically verify the DCT inside the ZK circuit is a sensible and potentially useful optimization. However, the central claim that the ZKP forces correct execution of the defense is not supported by the protocol as written: Algorithm 2 does not constrain the pruning/forwarding decision, and the abstract's headline attack-success bound is contradicted by the paper's own MNIST result. These are load-bearing issues, not presentation concerns.

major comments (5)
  1. [§4.5, Algorithm 2] The circuit in Algorithm 2 does not attest to the pruning and forwarding decisions, which are the core of the claimed enforcement. The only aggregate assertions are on the numeric values S_WM and S_BM (max and min of the score list); there is no assertion that the model attaining S_WM is the one excluded from the forwarded top-k list, no assertion that BM corresponds to the argmin model, and no public input committing to the actual subset of hashes that is forwarded. A malicious prover can compute all hashes and scores honestly, then forward the high-scoring poisoned model and drop a benign one; every assertion in the circuit still holds, and the verifier's hash check in Step 2 only confirms that the received models belong to the committed hash set. This invalidates the claims in §4.1 and §6.1 that a deviating client cannot produce a valid proof, and it invalidates the formal soundness statement in Eq. (2) as applied to "correct execution of Alg. 2." The circuit must take the forwarded hashes as public inputs and enforce the subset/exclusion and argmax/argmin relations. Separately, Step 7's statement that the proof verifies the update is the difference M_i - M_{i-1} is not reflected in Algorithm 2, which has no update inputs at all.
  2. [§4.3, Algorithm 1, Algorithm 2] The beta-adjustment encoded in Algorithm 2 is inconsistent with Algorithm 1. Algorithm 1 adjusts the entire score vector before computing argmax and argmin: S[0] <- S[0]/beta and S[k] <- S[k]*beta, and both extrema are taken over this adjusted vector. Algorithm 2, however, asserts S_WM = max(S_{i-k}/beta, ..., S_i) and S_BM = min(S_{i-k}, ..., S_i*beta), using the unadjusted oldest score in the minimum. For beta < 1 these differ whenever the oldest score is the minimum after adjustment, so the ZKP can attest to a different BM than the defense procedure would compute. The circuit should use S_{i-k}/beta in the minimum as well, or the prose should explicitly define BM over the unadjusted scores; as written, the circuit does not match the described defense.
  3. [Abstract, Table 2] The abstract's headline claim that ZORRO "reduces the attack success rate to less than 6%" is contradicted by Table 2, which reports ZORRO achieving BA = 36.99% on MNIST. The Appendix F explanation (benign-model distraction) may be plausible, and PRR = 100% shows that poisoned models were removed, but the metric BA is exactly the attack success rate, and 36.99% is not less than 6%. This is not a minor wording issue: a reader relying on the abstract would wrongly conclude that the defense bounds the backdoor accuracy on every reported configuration. The claim should be qualified, for example by stating the bound holds on all datasets except MNIST, or by reporting a different metric that supports the advertised bound.
  4. [§5.2.1, App. D, Tables 2 and 7] The default configuration used for the headline results was selected using ablations on the same CIFAR-10/ResNet-18 setup that later serves as the principal evidence of effectiveness. Specifically, beta = 0.7, k = 3, and the Taxicab norm are chosen based on Tables 9-11 in Appendix D, which are CIFAR-10 results, while Table 2 and Table 7 report the CIFAR-10 configuration as the main demonstration of low BA and high MA. This creates a selection-circularity: the reported numbers for the default setting are not an out-of-sample evaluation of the defense. The authors should either fix all hyperparameters before running any experiments and treat every dataset as held out, or report the parameter selection procedure separately with a clear statement of the degrees of freedom used and their effect on the headline metrics.
  5. [§6.2, §4.1] The security analysis in Section 6.2 assumes without proof that the DCT/Taxicab scoring separates poisoned from benign updates. The ZKP only enforces that the scoring and pruning computations were performed; it does not prove that the highest-scoring model is actually poisoned, nor that the forwarded model is benign. The paper's empirical evidence supports the heuristic for the tested attacks, but the invariant argument in §6.2 that "one benign model remains in the queue" depends on this detection heuristic rather than on the cryptographic protocol. This should be stated explicitly as an assumption, and the abstract's phrases claiming the proof attests to the "benign nature" of local model portions should be softened accordingly.
minor comments (5)
  1. [References] Reference [17] contains a formatting error: the author name should be "Rūsiņš Freivalds," not "R¯usin, š Freivalds."
  2. [§5.3] The sentence "As the table shows ZORRO effectively mitigates the attack.ZORRO effectively mitigates the attack for all datasets" is duplicated and should be merged.
  3. [§5.2.2, App. C] Section 5.2.2 states that all experiments were repeated 3 times with different seeds, while Appendix C says the experiment was conducted on each server 5 times; these statements should be reconciled.
  4. [Fig. 6] The legend entry "ResNet-18. 34 (CIFAR10)" appears to be a formatting artifact and should read "ResNet-18, ResNet-34 (CIFAR-10)."
  5. [Algorithm 2] The expressions max(S_{i-k}/beta, ..., S_i) and min(S_{i-k}, ..., S_i*beta) are ambiguous because the ellipsis does not make explicit which scores are adjusted. The pseudocode should list the adjusted score vector explicitly, especially given the inconsistency with Algorithm 1 noted above.

Circularity Check

2 steps flagged · score 4.0 of 10

Partial circularity: the default β and k are selected by ablations on the same CIFAR-10 benchmark whose BA/MA are then reported as headline evidence, and the §6.2 security invariant assumes the poisoning-detection separation it is meant to establish; separately, Algorithm 2 does not actually constrain the pruning step, a soundness gap rather than a circular reduction.

  1. fitted input called prediction [Section 4.6, Appendix D (Tables 9-10), Section 5.3 (Table 2) and Section 5.6 (Table 7)]
    "In contrast, β=0.7 strikes a practical balance between utility and robustness, reducing BA to the level of the Gold Standard while preserving high MA. ... As the table shows, a moderate value of k=3 achieves the best balance, minimizing BA (3.16%), maintaining high MA (73.51%), and ensuring robust PRR and low BBR."

    The paper's default security parameters β=0.7 and k=3, plus the Taxicab scoring norm, are chosen by ablating BA, MA, PRR, and BBR on the same CIFAR-10/ResNet-18 configuration used for the headline evaluation. Section 5.3 then reports that configuration's CIFAR-10 numbers (BA 4.45%, MA 73.02%) and Section 5.6 reports BA 3.16% / MA 73.51% as evidence of ZORRO's effectiveness. The abstract's 'reduces the attack success rate to less than 6%' is therefore partly in-sample: the CIFAR-10 result is the outcome of selecting parameters on that dataset, not an independent prediction. The remaining datasets and architectures still provide out-of-sample evidence, so the circularity is partial.

  2. self definitional [Section 6.2, Security of Poisoning Detection]
    "If the added model shows detectable poisoning artifacts, the scoring function will prioritize its removal. Thus, if there was one benign model in the queue before the current round (as given by the security invariant) and the new model, which, if poisoned, is removed, it follows that after the defense round, again one benign model is in the queue, thus fulfilling the security invariant also for the following round."

    The invariant proof's only mechanism for eliminating a poisoned model is the conditional premise 'if the added model shows detectable poisoning artifacts, the scoring function will prioritize its removal.' But 'detectable' is operationalized by the scoring function itself: the defense removes the model with the largest low-frequency DCT ℓ1 score. The proof does not derive that poisoned updates reliably receive larger scores than benign non-IID updates; it assumes that separation, which is exactly the effectiveness claim under examination. The conclusion 'again one benign model is in the queue' is thus equivalent to assuming the poison-scoring property rather than establishing it.

full rationale

The paper does not contain a hidden equation whose conclusion equals its input: Algorithm 1 computes scores by DCT/ℓ1, Algorithm 2 checks hashes and min/max equalities, and the empirical BA/MA numbers are measurements rather than formal consequences of the scoring definition. The two genuine circularities are (i) the in-sample selection of β and k on the same CIFAR-10 benchmark later quoted as the headline result, and (ii) the Section 6.2 invariant proof, which assumes the poison/benign score separation that the detection mechanism is supposed to guarantee. Neither is a total collapse: the paper evaluates across many datasets, architectures, and attack settings, and the ZKP overhead measurements are independent of the detection heuristic. However, the strongest advertised claim — that the ZKP enforces the client-side defense and reduces BA below 6% — is weakened by these two in-sample/assumed premises. Separately, and not counted as circularity, Algorithm 2's aggregate assertions S_WM = max(S_{i-k}/β, ..., S_i) and S_BM = min(S_{i-k}, ..., S_i·β) never constrain which model is actually excluded from the forwarded top-k list or which index BM points to; the Section 4.5 prose that the proof 'proves that it is not included in the top-k models' is therefore unsupported by the circuit as written. That is a soundness gap in the enforcement claim rather than a derivation that reduces to its inputs. Self-citations to [39] and [42] are present but not load-bearing here: the frequency-domain rationale also cites independent works [38, 57], and the VOLE-based ZKP implementation rests on external tools [52, 53].

Assumptions & free parameters 4 free parameters · 6 assumptions · 0 invented entities

The ledger captures what the paper assumes beyond the ZKP layer: empirical detectability of backdoors by low-frequency DCT scoring, the queue invariant, inherited VOLE and Freivalds security, the no-server-collusion threat model, and the interpretation of backdoor accuracy. Four hand-tuned choices, beta, k, the low-frequency region, and the L1 norm, directly control the headline BA and MA and were selected from ablations on the same benchmark. No new physical or mathematical entities are introduced.

free parameters (4)
  • Security parameter beta = 0.7
    Scales the oldest and newest poison scores in Algorithm 1 lines 14-15. Chosen from the ablation in Appendix D, Table 10; at beta=0.5 the backdoor accuracy rises to 34.94 percent and at beta=1.0 the main accuracy collapses to 23.58 percent, so the headline result depends on this tuned value.
  • Queue length k = 3
    Number of checkpoints retained and scored at each client. Chosen from the ablation in Appendix D, Table 9; k=1 gives backdoor accuracy 35.43 percent, so the reported robustness relies on this choice.
  • Low-frequency DCT selection region = u+v < N/2 triangular region
    Defines which DCT coefficients are treated as low frequency in Appendix A, Eq. 4. This hand-chosen region directly determines every poison score and is not derived or swept in the paper.
  • Poison score norm = Taxicab (L1)
    The L1 norm on low-frequency DCT coefficients is selected after comparing cosine, L2, and Taxicab in Appendix D, Table 11. Cosine distance gives no defense at all, so the detection mechanism itself is chosen based on the same benchmark used for the headline evaluation.
assumptions (6)
  • domain assumption Backdoor training creates larger low-frequency DCT artifacts in model updates than benign non-IID updates.
    Introduced in Sect. 4.3 and used by the scoring function. Sect. 6.2 assumes 'detectable poisoning artifacts' rather than proving that the score separates poisoned from benign models. If this assumption fails, pruning removes the wrong models.
  • domain assumption At least one benign model always remains in the queue, and the initialization phase provides this benign reference.
    Stated as the security invariant in Sect. 6.2 and supported by the initialization phase in Sect. 4.4. If all initial clients are malicious or a benign model receives a high poison score, the invariant can fail.
  • standard math Wolverine VOLE-based ZKP has computational soundness, zero-knowledge, and completeness.
    The security analysis in Sect. 6.1 relies entirely on the external protocol guarantees claimed for Wolverine and emp-zk; these are not re-derived or machine-checked in this paper.
  • standard math Freivalds randomized matrix check with a random binary vector has soundness error at most 1/2 per repetition.
    Used in Sect. 4.7 to verify the DCT inside the ZK circuit. The check assumes a field encoding of real-valued model parameters, which the paper does not specify.
  • domain assumption The server is semi-honest and does not collude with malicious clients.
    Stated in Sect. 3.2. The server acts as a second verifier to prevent malicious clients from falsely rejecting proofs, so a colluding server would break that property.
  • domain assumption A benign model's accuracy on triggered inputs remains low, so a high backdoor accuracy implies a surviving backdoor.
    Appendix F shows this assumption is false for MNIST, where benign models consistently predict one label for triggered inputs. The paper treats this as an artifact rather than a security failure, but the metric interpretation depends on the assumption.

how reviews work

0 comments
Cite this review

Pith. "Pith review of ZORRO: Zero-Knowledge Robustness and Privacy for Split Learning (Full Version)." pith.science (2026). https://pith.science/paper/3YWUI6LV

@misc{pith2026250909787,
  author       = {Pith},
  title        = {Pith review of: ZORRO: Zero-Knowledge Robustness and Privacy for Split Learning (Full Version)},
  year         = {2026},
  howpublished = {\url{https://pith.science/paper/3YWUI6LV}},
  note         = {Machine review of arXiv:2509.09787}
}
read the original abstract

Split Learning (SL) is a distributed learning approach that enables resource-constrained clients to collaboratively train deep neural networks (DNNs) by offloading most layers to a central server while keeping in- and output layers on the client-side. This setup enables SL to leverage server computation capacities without sharing data, making it highly effective in resource-constrained environments dealing with sensitive data. However, the distributed nature enables malicious clients to manipulate the training process. By sending poisoned intermediate gradients, they can inject backdoors into the shared DNN. Existing defenses are limited by often focusing on server-side protection and introducing additional overhead for the server. A significant challenge for client-side defenses is enforcing malicious clients to correctly execute the defense algorithm. We present ZORRO, a private, verifiable, and robust SL defense scheme. Through our novel design and application of interactive zero-knowledge proofs (ZKPs), clients prove their correct execution of a client-located defense algorithm, resulting in proofs of computational integrity attesting to the benign nature of locally trained DNN portions. Leveraging the frequency representation of model partitions enables ZORRO to conduct an in-depth inspection of the locally trained models in an untrusted environment, ensuring that each client forwards a benign checkpoint to its succeeding client. In our extensive evaluation, covering different model architectures as well as various attack strategies and data scenarios, we show ZORRO's effectiveness, as it reduces the attack success rate to less than 6\% while causing even for models storing \numprint{1000000} parameters on the client-side an overhead of less than 10 seconds.

Figures

Figures reproduced from arXiv: 2509.09787 by the authors.

Figure 1
Figure 1. Overview of a Split Learning (SL) System. [PITH_FULL_IMAGE:figures/full_fig_p003_1.png] view at source ↗
Figure 2
Figure 2. End-to-End Workflow of ZORRO at Each Client in Split Learning. a pointer BM identifying the recommended model for continuation, and a zero-knowledge proof 𝜋𝑖−1 attesting to the correct execution of the defense mechanism. Simultaneously, client 𝐶𝑖 obtains from the server the corresponding model hashes Hash𝑖−𝑘, . . . , Hash𝑖−1 allow client 𝐶𝑖 verifying the integrity of the received models and updates. Step 2 – Validat… view at source ↗
Figure 4
Figure 4. BA for different client counts and initializations, [PITH_FULL_IMAGE:figures/full_fig_p010_4.png] view at source ↗
Figures from the paper (5 more)
Figure 3
Figure 3. Figure 3: ZORRO’s effectiveness for different client numbers. 5.3 High-Level Results Tab. 2 shows ZORRO’s effectiveness for different datasets2 . As the table shows ZORRO effectively mitigates the attack. ZORRO effec￾tively mitigates the attack for all datasets. For CIFAR-10 and…
Figure 5
Figure 5. Figure 5: Effectiveness of ZORRO for different ratios of poi￾soned models (PMR). mitigation or significant drops in MA. While k-means achieves high PRR and low BA, its MA is considerably reduced to 52.06%, and it suffers from a high BBR of 87.93%, indicating that it frequently d…
Figure 6
Figure 6. Figure 6: Scalability of runtime and communication overhead [PITH_FULL_IMAGE:figures/full_fig_p012_6.png]
Figure 7
Figure 7. Figure 7: Variance in the BA and MA for ZORRO. D Ablation Study [PITH_FULL_IMAGE:figures/full_fig_p016_7.png]
Figure 8
Figure 8. Figure 8: Poison risk-scores for benign and poisoned model [PITH_FULL_IMAGE:figures/full_fig_p017_8.png]

Discussion (0). Continue with ORCID to comment.

Reference graph

Works this paper leans on

64 extracted references · 51 canonical work pages

  1. [1]

    Wendy Kan Addison Howard, Eunbyung Park. 2018. ImageNet Object Localiza- tion Challenge. https://kaggle.com/competitions/imagenet-object-localization- challenge

  2. [2]

    Meta AI. 2025. The Llama 4 Herd: The Beginning of a New Era of Natively Multi- modal AI Innovation. https://ai.meta.com/blog/llama-4-multimodal-intelligence/. https://ai.meta.com/blog/llama-4-multimodal-intelligence/ Accessed: 2025-04- 09

  3. [3]

    Eugene Bagdasaryan, Andreas Veit, Yiqing Hua, Deborah Estrin, and Vitaly Shmatikov. 2020. How to backdoor federated learning. InInternational conference on artificial intelligence and statistics. PMLR, Online, 2938–2948. CCS ’25, October 13–17, 2025, Taipei, Taiwan Nojan Sheybani et al

  4. [4]

    2023.{VILLAIN}: Backdoor attacks against vertical split learning

    Yijie Bai, Yanjiao Chen, Hanlei Zhang, Wenyuan Xu, Haiqin Weng, and Dou Goodman. 2023.{VILLAIN}: Backdoor attacks against vertical split learning. In 32nd USENIX Security Symposium (USENIX Security 23). USENIX, Anaheim, CA, 2743–2760

  5. [5]

    Moran Baruch, Gilad Baruch, and Yoav Goldberg. 2019. A Little Is Enough: Circumventing Defenses For Distributed Learning. InNIPS. IEEE, Vancouver, Canada, 11 pages

  6. [6]

    Carsten Baum, Samuel Dittmer, Peter Scholl, and Xiao Wang. 2023. SoK: Vector OLE-based zero-knowledge protocols.Designs, Codes and Cryptography91, 11 (2023), 3527–3561

  7. [7]

    Eli Ben-Sasson, Iddo Bentov, Yinon Horesh, and Michael Riabzev. 2018. Scalable, transparent, and post-quantum secure computational integrity

  8. [8]

    Eli Ben-Sasson, Alessandro Chiesa, Eran Tromer, and Madars Virza. 2014. Succinct Non-Interactive zero knowledge for a von neumann architecture. InUSENIX Security. 781–796

Show all 64 references
  1. [9]

    Jock Blackard. 1998. Covertype. UCI Machine Learning Repository. DOI: https://doi.org/10.24432/C50K5N

  2. [10]

    Peva Blanchard, El Mahdi El Mhamdi, Rachid Guerraoui, and Julien Stainer. 2017. Machine Learning with Adversaries: Byzantine Tolerant Gradient Descent. In NIPS

  3. [11]

    Elette Boyle, Geoffroy Couteau, Niv Gilboa, and Yuval Ishai. 2018. Compressing vector OLE. InCCS. ACM, Toronto, Canada, 896–912

  4. [12]

    California State Legislature. 2018. California Consumer Privacy Act. https:// leginfo.legislature.ca.gov/faces/billTextClient.xhtml?bill_id=201720180SB1121

  5. [13]

    Xiaoyu Cao, Minghong Fang, Jia Liu, and Neil Zhenqiang Gong. 2021. FLTrust: Byzantine-robust Federated Learning via Trust Bootstrapping. InNDSS. NDSS, San Diego, CA

  6. [14]

    Bing-Jyue Chen, Suppakit Waiwitlikhit, Ion Stoica, and Daniel Kang. 2024. Zkml: An optimizing system for ml inference in zero-knowledge proofs. InConference on Computer Systems

  7. [15]

    Li Deng. 2012. The mnist database of handwritten digit images for machine learning research. InIEEE Signal Processing Magazine, Vol. 29. IEEE, Online, 141–142

  8. [16]

    Arne Dür. 1998. On the optimality of the discrete Karhunen–Loève expansion. SIAM Journal on Control and Optimization36, 6 (1998), 1937–1939

  9. [17]

    R¯usin, š Freivalds. 1979. Fast probabilistic algorithms. InInternational Symposium on Mathematical Foundations of Computer Science. Springer, 57–69

  10. [18]

    Clement Fung, Chris JM Yoon, and Ivan Beschastnikh. 2020. The limitations of federated learning in sybil settings. InRAID

  11. [19]

    Sanjam Garg, Aarushi Goel, Somesh Jha, Saeed Mahloujifar, Mohammad Mah- moody, Guru-Vamsi Policharla, and Mingyuan Wang. 2023. Experimenting with zero-knowledge proofs of training. InCCS

  12. [20]

    Zahra Ghodsi, Mojan Javaheripi, Nojan Sheybani, Xinqiao Zhang, Ke Huang, and Farinaz Koushanfar. 2023. zprobe: Zero peek robustness checks for federated learning. InComputer Vision and Pattern Recognition (CVPR)

  13. [21]

    Otkrist Gupta and Ramesh Raskar. 2018. Distributed learning of deep neural network over multiple agents.Journal of Network and Computer Applications116 (2018), 1–8

  14. [22]

    Kaiming He, Xiangyu Zhang, Shaoqing Ren, and Jian Sun. 2016. Deep resid- ual learning for image recognition. InComputer Vision and Pattern Recognition (CVPR)

  15. [23]

    Ying He, Zhili Shen, Jingyu Hua, Qixuan Dong, Jiacheng Niu, Wei Tong, Xu Huang, Chen Li, and Sheng Zhong. 2023. Backdoor Attack Against Split Neural Network-Based Vertical Federated Learning.IEEE Transactions on Information Forensics and Security(2023)

  16. [24]

    Zecheng He, Tianwei Zhang, and Ruby B Lee. 2019. Model inversion attacks against collaborative inference. InACSAC

  17. [25]

    Torsten Krauß and Alexandra Dmitrienko. 2023. MESAS: Poisoning Defense for Federated Learning Resilient against Adaptive Attackers. InCCS

  18. [26]

    Alex Krizhevsky, Geoffrey Hinton, et al. 2009. Learning multiple layers of features from tiny images. Citeseer

  19. [27]

    Na Li, Yongfei Zhang, Yun Zhang, and C-C Jay Kuo. 2019. On energy compaction of 2D Saab image transforms. InAsia-Pacific Signal and Information Processing Association Annual Summit and Conference (APSIPA ASC). IEEE, Lanzhou, China

  20. [28]

    Tianyi Liu, Xiang Xie, and Yupeng Zhang. 2021. zkCNN: Zero knowledge proofs for convolutional neural network predictions and accuracy. InCCS. ACM SIGSAC, Virtual Event Republic of Korea

  21. [29]

    Hidde Lycklama, Lukas Burkhalter, Alexander Viand, Nicolas Küchler, and Anwar Hithnawi. 2023. Rofl: Robustness of secure federated learning. InIEEE S&P. IEEE, SAN FRANCISCO, CA

  22. [30]

    Song Lyu, Zheng Lin, Guanqiao Qu, Xianhao Chen, Xiaoxia Huang, and Pan Li

  23. [31]

    Brendan McMahan, Eider Moore, Daniel Ramage, Seth Hampson, and Blaise Aguera y Arcas. 2017. Communication-efficient learning of deep net- works from decentralized data. InArtificial intelligence and statistics. PMLR, Fort Lauderdale, Florida, 1273–1282

  24. [32]

    mnmoustafa and Mohammed Ali. 2017. Tiny ImageNet. https://kaggle.com/ competitions/tiny-imagenet. Kaggle

  25. [33]

    Mohammad Naseri, Jamie Hayes, and Emiliano De Cristofaro. 2020. Local and central differential privacy for robustness and privacy in federated learning. arXiv preprint arXiv:2009.03561(2020)

  26. [34]

    Milad Nasr, Reza Shokri, and Amir Houmansadr. 2019. Comprehensive privacy analysis of deep learning: Passive and active white-box inference attacks against centralized and federated learning. InIEEE S&P. IEEE, San Francisco, CA, 739– 753

  27. [35]

    OpenCV Team. 2018. OpenCV 4.x Documentation: Core Functionality: Array Operations: DCT function. Online Documentation

  28. [36]

    Adam Paszke, Sam Gross, Francisco Massa, Adam Lerer, James Bradbury, Gregory Chanan, Trevor Killeen, Zeming Lin, Natalia Gimelshein, Luca Antiga, et al. 2019. Pytorch: An imperative style, high-performance deep learning library.Advances in neural information processing systems...

  29. [37]

    Yuwen Pu, Zhuoyuan Ding, Jiahao Chen, Chunyi Zhou, Qingming Li, Chunqiang Hu, and Shouling Ji. 2024. Dullahan: Stealthy Backdoor Attack against Without- Label-Sharing Split Learning.arXiv preprint arXiv:2405.12751(2024)

  30. [38]

    Hamprecht, Yoshua Bengio, and Aaron Courville

    Nasim Rahaman, Aristide Baratin, Devansh Arpit, Felix Draxler, Min Lin, Fred A. Hamprecht, Yoshua Bengio, and Aaron Courville. 2019. On the Spectral Bias of Neural Networks. InInternational Conference on Machine Learning

  31. [39]

    Phillip Rieger, Alessandro Pegoraro, Kavita Kumari, Tigist Abera, Jonathan Knauer, and Ahmad-Reza Sadeghi. 2025. SafeSplit: A Novel Defense Against Client-Side Backdoor Attacks in Split Learning. InNDSS

  32. [40]

    Amrita Roy Chowdhury, Chuan Guo, Somesh Jha, and Laurens van der Maaten

  33. [41]

    Shiqi Shen, Shruti Tople, and Prateek Saxena. 2016. Auror: Defending Against Poisoning Attacks in Collaborative Deep Learning Systems. InACSAC

  34. [42]

    Nojan Sheybani, Anees Ahmed, Michel Kinsy, and Farinaz Koushanfar. 2025. Zero-Knowledge Proof Frameworks: A Survey.arXiv preprint arXiv:2502.07063 (2025)

  35. [43]

    K Simonyan and A Zisserman. 2015. Very deep convolutional networks for large-scale image recognition. InICLR. Computational and Biological Learning Society

  36. [44]

    Haochen Sun, Jason Li, and Hongyang Zhang. 2024. zkllm: Zero knowledge proofs for large language models. InCCS

  37. [45]

    Christian Szegedy, Wei Liu, Yangqing Jia, Pierre Sermanet, Scott Reed, Dragomir Anguelov, Dumitru Erhan, Vincent Vanhoucke, and Andrew Rabinovich. 2015. Going deeper with convolutions. InComputer Vision and Pattern Recognition (CVPR)

  38. [46]

    Behrad Tajalli, Oğuzhan Ersoy, and Stjepan Picek. 2023. On Feasibility of Server- side Backdoor Attacks on Split Learning. InIEEE Security and Privacy Workshops (SPW). IEEE

  39. [47]

    European Union. 2018. General Data Protection Regulation. https://eur-lex. europa.eu/eli/reg/2016/679/oj

  40. [48]

    United States Congress. 1996. Health Insurance Portability and Accountabil- ity Act. https://www.govinfo.gov/content/pkg/PLAW-104publ191/pdf/PLAW- 104publ191.pdf

  41. [49]

    Praneeth Vepakomma, Otkrist Gupta, Tristan Swedish, and Ramesh Raskar. 2018. Split learning for health: Distributed deep learning without sharing raw patient data.arXiv preprint arXiv:1812.00564(2018), 7 pages

  42. [50]

    Hongyi Wang, Kartik Sreenivasan, Shashank Rajput, Harit Vishwakarma, Saurabh Agarwal, Jy-yong Sohn, Kangwook Lee, and Dimitris Papailiopoulos. 2020. Attack of the tails: Yes, you really can backdoor federated learning. InNIPS, Vol. 33. IEEE, Vancouver, Canada, 15 pages

  43. [51]

    2025.EMP-Toolkit

    Xiao Wang. 2025.EMP-Toolkit. https://github.com/emp-toolkit

  44. [52]

    2025.EMP-zk

    Xiao Wang. 2025.EMP-zk. wizkit team. https://github.com/emp-toolkit/emp-zk

  45. [53]

    Chenkai Weng, Kang Yang, Jonathan Katz, and Xiao Wang. 2021. Wolverine: fast, scalable, and communication-efficient zero-knowledge proofs for boolean and arithmetic circuits. InIEEE S&P. IEEE, 1074–1091

  46. [54]

    Chenkai Weng, Kang Yang, Xiang Xie, Jonathan Katz, and Xiao Wang. 2021. Mystique: Efficient conversions for Zero-Knowledge proofs with applications to machine learning. InUSENIX Security. USENIX, 501–518

  47. [55]

    Alexander Wong, Mohammad Javad Shafiee, and Michael St Jules. 2018. Mi- cronNet: A highly compact deep convolutional neural network architecture for real-time embedded traffic sign classification.IEEE Access6 (2018), 59803–59810

  48. [56]

    Han Xiao, Kashif Rasul, and Roland Vollgraf. 2017. Fashion-MNIST: a Novel Image Dataset for Benchmarking Machine Learning Algorithms. arXiv:cs.LG/1708.07747 [cs.LG]

  49. [57]

    Zhi-Qin John Xu, Yaoyu Zhang, and Yanyang Xiao. 2019. Training behavior of deep neural network in frequency domain. InInternational Conference on Neural Information Processing. Springer, 264—-274

  50. [58]

    Ziyuan Yang, Yingyu Chen, Huijie Huangfu, Maosong Ran, Hui Wang, Xiaoxiao Li, and Yi Zhang. 2022. Robust split federated learning for u-shaped medical image networks.arXiv preprint arXiv:2212.06378(2022)

  51. [59]

    Dong Yin, Yudong Chen, Ramchandran Kannan, and Peter Bartlett. 2018. Byzantine-robust distributed learning: Towards optimal statistical rates. InInter- national Conference on Machine Learning. PMLR, Stockholm, Sweden, 5650–5659

  52. [60]

    Fangchao Yu, Lina Wang, Bo Zeng, Kai Zhao, Zhi Pang, and Tian Wu. 2023. How ZORRO: Zero-Knowledge Robustness and Privacy for Split Learning (Full Version) CCS ’25, October 13–17, 2025, Taipei, Taiwan to backdoor split learning.Neural Networks168 (2023), 326–336

  53. [61]

    Fangchao Yu, Bo Zeng, Kai Zhao, Zhi Pang, and Lina Wang. 2024. Chronic Poisoning: Backdoor Attack against Split Learning. InAAAI conference on artificial intelligence. AAAI, Vancouver, Canada

  54. [62]

    Sergey Zagoruyko. 2016. Wide residual networks.arXiv preprint arXiv:1605.07146 (2016). A Frequency Selection For the frequency transformation, we employ theDiscrete Cosine Transform(DCT). The DCT has been proven to closely approximate theKarhunen-Loève Transform(KLT) [ 27], wh...

  55. [2022]

    Eiffel: Ensuring integrity for federated learning. InCCS

  56. [2023]

    In2023 IEEE Globecom Workshops (GC Wkshps)

    Optimal resource allocation for U-shaped parallel split learning. In2023 IEEE Globecom Workshops (GC Wkshps). IEEE, Kuala Lumpur, Malaysia, 197–202

Pith tools

Reviewed August 15, 2026 · model on record in the stance chip above.