Pith. sign in

REVIEW 5 cited by

Scaling up Trustless DNN Inference with Zero-Knowledge Proofs

Not yet reviewed by Pith; the record is open.

This paper has not been read by Pith yet. Machine review is queued; the pith claim, tier, and objections will appear here once it completes.

SPECIMEN: schema-true, not a live event

T0 review · schema-true

One-sentence machine reading of the paper's core claim.

pith:XXXXXXXX · record.json · timestamp

arxiv 2210.08674 v1 pith:U2MKMRIR submitted 2022-10-17 cs.CR cs.LG

classification cs.CRcs.LG
keywords modelinferencemlaasverifyzk-snarksaccuracymodelszero-knowledge
verification ladder T0 review T1 audit T2 compute T3 formal
0 comments
read the original abstract

As ML models have increased in capabilities and accuracy, so has the complexity of their deployments. Increasingly, ML model consumers are turning to service providers to serve the ML models in the ML-as-a-service (MLaaS) paradigm. As MLaaS proliferates, a critical requirement emerges: how can model consumers verify that the correct predictions were served, in the face of malicious, lazy, or buggy service providers? In this work, we present the first practical ImageNet-scale method to verify ML model inference non-interactively, i.e., after the inference has been done. To do so, we leverage recent developments in ZK-SNARKs (zero-knowledge succinct non-interactive argument of knowledge), a form of zero-knowledge proofs. ZK-SNARKs allows us to verify ML model execution non-interactively and with only standard cryptographic hardness assumptions. In particular, we provide the first ZK-SNARK proof of valid inference for a full resolution ImageNet model, achieving 79\% top-5 accuracy. We further use these ZK-SNARKs to design protocols to verify ML model execution in a variety of scenarios, including for verifying MLaaS predictions, verifying MLaaS model accuracy, and using ML models for trustless retrieval. Together, our results show that ZK-SNARKs have the promise to make verified ML model inference practical.

Discussion (0). Continue with ORCID to comment.

Forward citations

Cited by 5 Pith papers

Reviewed papers in the Pith corpus that reference this work. Sorted by Pith novelty score. Full citation record

  1. Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification

    cs.CR 2026-07 accept novelty 6.0 of 10

    Certifying a model only on a fixed audit dataset is vulnerable to data-forging; committing before sampling fresh audit data restores distributional security.

  2. ZKTorch: Compiling ML Inference to Zero-Knowledge Proofs via Parallel Proof Accumulation

    cs.CR 2025-07 conditional novelty 6.0 of 10

    ZKTorch compiles machine learning models into basic cryptographic blocks and uses a parallelized accumulation scheme to generate compact zero-knowledge proofs of inference for all MLPerf edge models.

  3. Integrity of peer-to-peer distributed LLM inference under malicious nodes

    cs.CR 2026-07 conditional novelty 5.0 of 10

    Under a simulated isotropic noise model, a canary-trap activation-drift detector achieves perfect AUROC separation of one malicious shard in multi-hop LLM inference.

  4. Private, Verifiable, and Auditable AI Systems

    cs.CR 2025-08 conditional novelty 4.0 of 10

    A thesis demonstrating partial prototypes for zk-verifiable model evaluation and privacy-preserving retrieval, and arguing these pieces can compose into end-to-end auditable AI systems.

  5. Engineering Trustworthy Machine-Learning Operations with Zero-Knowledge Proofs

    cs.SE 2025-05 conditional novelty 4.0 of 10

    A systematic review of 57 ZKP-for-ML papers concludes that inference verification dominates the field and that research is converging toward a unified ZKMLOps framework for trustworthy, auditable AI.

Pith tools