01 / The mechanism and its boundary
What is being described
A cryptographic commitment lets a party fix a value now while keeping it hidden, and later reveal it with assurance that it has not changed S-1606.
A commitment must keep the value hidden until it is opened S-1606, and it must be binding: hard to open in more than one way S-1607. A Merkle hash tree commits to many items with one root hash, and any single item can later be opened with a proof whose size grows only logarithmically with the number of items S-1607. Its binding property reduces to the collision resistance of the hash function, meaning that finding two inputs with the same output is computationally infeasible S-1607 S-1600. In AI verification, commitments fix evidence before anyone checks it:
- Traffic. The Oxford Martin report describes networking hardware and enclosures that make commitments about all traffic S-0004, and in one design taps send out hashes of captured traffic while the prover keeps the plaintext S-0018, as in network taps and certifiers.
- Weights. In zero-knowledge proofs of inference the prover commits to its weights once and proves each output against that commitment S-0023.
- Training. A proposed zero-knowledge scheme combines a pre-committed training specification with Merkle commitments to intermediate computation S-0025, as in zero-knowledge proofs of training constraints.
- Audits. In one scheme the prover commits to sampled weights at each training step before it learns whether that step will be audited, so that it cannot fabricate consistent records afterwards S-0017.
Connections in the research map
Related research
Sources and provenance
- S-1606 / Tier B
ZKProof Community Reference ↗
D. Benarroch, L. Brandão, M. Maller, E. Tromer · 2022 · ZKProof
Supports: ideal commitment: value kept hidden, later retrieved with assurance it did not change
Locator: §2.1.1, p. 19
Version and catalogue details - S-1607 / Tier A
Proofs of Space ↗
S. Dziembowski, S. Faust, V. Kolmogorov, K. Pietrzak · 2015 · CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796)
Supports: hash-tree commitment to N items with N−1 hash invocations; opening one item with L log N bits; binding property reduces to collision resistance
Locator: §5 (hash trees)
Version and catalogue details - S-1600 / Tier A
NIST Computer Security Resource Center (CSRC) Glossary ↗
National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center
Supports: collision resistance of approved hash functions
Locator: term: hash_function (FIPS 203/204/205)
Version and catalogue details - S-0004 / Tier B
Verification for International AI Governance ↗
B. Harack, R. F. Trager, A. Reuel, D. Manheim, M. Brundage, O. Aarne, A. Scher, Y. Pan, J. Xiao, K. Loke, S. N. Adan, G. Bas, N. A. Caputo, J. C. Morse, J. Ahuja, I. Duan, J. Egan, B. Bucknall, B. Rosen, R. Araujo, V. Boulanin, R. Lall, F. Barez, S. Alvira, C. Katzke, A. Atamli, A. Awad · 2025 · Oxford Martin AI Governance Initiative
Supports: networking hardware and enclosures making cryptographic commitments about all traffic
Locator: p. 13
Version and catalogue details - S-0018 / Tier B
A System Overview for Near-Term, Low-Trust AI Compute Verification ↗
N. Cankaya · 2026 · Machine Intelligence Research Institute
Supports: taps send out hashes of captured traffic while the prover keeps the plaintext
Locator: §3.2.1
Version and catalogue details - S-0023 / Tier A
zkLLM: Zero Knowledge Proofs for Large Language Models ↗
H. Sun, J. Li, H. Zhang · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024)
Supports: one-time commitment to model weights, then per-query proofs against it
Locator: §3; §8, Table 1
Version and catalogue details - S-0025 / Tier B
Zero knowledge verification for frontier AI training is possible ↗
P. Peigné, K. Nguyen, P. Wang · 2026 · arXiv
Supports: pre-committed training specification and Merkle commitments of intermediate computation
Locator: abstract
Version and catalogue details - S-0017 / Tier C
Example Schemes for Verifying High-Stakes AI Agreements ↗
Amodo Design · 2026 · Amodo Design
Supports: prover commits a hash of sampled weights before it learns whether a step will be audited
Locator: pre-training scheme
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review