K-0024

Cryptographic commitment

A way to fix a value now without revealing it, so that it can later be opened and shown not to have changed.

Source reviewed 2026-09-25

01 / The mechanism and its boundary

What is being described

A cryptographic commitment lets a party fix a value now while keeping it hidden, and later reveal it with assurance that it has not changed S-1606.

A commitment must keep the value hidden until it is opened S-1606, and it must be binding: hard to open in more than one way S-1607. A Merkle hash tree commits to many items with one root hash, and any single item can later be opened with a proof whose size grows only logarithmically with the number of items S-1607. Its binding property reduces to the collision resistance of the hash function, meaning that finding two inputs with the same output is computationally infeasible S-1607 S-1600. In AI verification, commitments fix evidence before anyone checks it:

  • Traffic. The Oxford Martin report describes networking hardware and enclosures that make commitments about all traffic S-0004, and in one design taps send out hashes of captured traffic while the prover keeps the plaintext S-0018, as in network taps and certifiers.
  • Weights. In zero-knowledge proofs of inference the prover commits to its weights once and proves each output against that commitment S-0023.
  • Training. A proposed zero-knowledge scheme combines a pre-committed training specification with Merkle commitments to intermediate computation S-0025, as in zero-knowledge proofs of training constraints.
  • Audits. In one scheme the prover commits to sampled weights at each training step before it learns whether that step will be audited, so that it cannot fabricate consistent records afterwards S-0017.

Connections in the research map

Related research

Sources and provenance

  1. S-1606 / Tier B

    ZKProof Community Reference ↗

    D. Benarroch, L. Brandão, M. Maller, E. Tromer · 2022 · ZKProof

    Supports: ideal commitment: value kept hidden, later retrieved with assurance it did not change

    Locator: §2.1.1, p. 19

    Version and catalogue details
  2. S-1607 / Tier A

    Proofs of Space ↗

    S. Dziembowski, S. Faust, V. Kolmogorov, K. Pietrzak · 2015 · CRYPTO 2015 (IACR Cryptology ePrint Archive 2013/796)

    Supports: hash-tree commitment to N items with N−1 hash invocations; opening one item with L log N bits; binding property reduces to collision resistance

    Locator: §5 (hash trees)

    Version and catalogue details
  3. S-1600 / Tier A

    NIST Computer Security Resource Center (CSRC) Glossary ↗

    National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center

    Supports: collision resistance of approved hash functions

    Locator: term: hash_function (FIPS 203/204/205)

    Version and catalogue details
  4. S-0004 / Tier B

    Verification for International AI Governance ↗

    B. Harack, R. F. Trager, A. Reuel, D. Manheim, M. Brundage, O. Aarne, A. Scher, Y. Pan, J. Xiao, K. Loke, S. N. Adan, G. Bas, N. A. Caputo, J. C. Morse, J. Ahuja, I. Duan, J. Egan, B. Bucknall, B. Rosen, R. Araujo, V. Boulanin, R. Lall, F. Barez, S. Alvira, C. Katzke, A. Atamli, A. Awad · 2025 · Oxford Martin AI Governance Initiative

    Supports: networking hardware and enclosures making cryptographic commitments about all traffic

    Locator: p. 13

    Version and catalogue details
  5. S-0018 / Tier B

    A System Overview for Near-Term, Low-Trust AI Compute Verification ↗

    N. Cankaya · 2026 · Machine Intelligence Research Institute

    Supports: taps send out hashes of captured traffic while the prover keeps the plaintext

    Locator: §3.2.1

    Version and catalogue details
  6. S-0023 / Tier A

    zkLLM: Zero Knowledge Proofs for Large Language Models ↗

    H. Sun, J. Li, H. Zhang · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024)

    Supports: one-time commitment to model weights, then per-query proofs against it

    Locator: §3; §8, Table 1

    Version and catalogue details
  7. S-0025 / Tier B

    Zero knowledge verification for frontier AI training is possible ↗

    P. Peigné, K. Nguyen, P. Wang · 2026 · arXiv

    Supports: pre-committed training specification and Merkle commitments of intermediate computation

    Locator: abstract

    Version and catalogue details
  8. S-0017 / Tier C

    Example Schemes for Verifying High-Stakes AI Agreements ↗

    Amodo Design · 2026 · Amodo Design

    Supports: prover commits a hash of sampled weights before it learns whether a step will be audited

    Locator: pre-training scheme

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review