01 / The mechanism and its boundary
What the technique establishes
Proof-of-learning asks a model trainer to keep a transcript of training: weight checkpoints, the data used at each step and the settings. A verifier re-runs a few segments and checks that they reproduce the logged checkpoints. It was proposed to show that compute was really spent on training, and later to check that training runs obeyed rules on compute and data. Later data-focused tests were run on language models of up to 1 billion parameters. A 2024 variant makes small training runs exactly reproducible across GPU types, so an auditor can replicate them. The biggest known weakness is that published attacks produced invalid proofs that passed verification, and the original authors later argued that no provably robust version exists without a better theory of deep-learning optimisation. The biggest obstacle for verification use is that the verifier must see the training data and weights and be able to re-run training.
- Threat model
- Adversarial prover
- Adversarial evaluation
- Independent red-team
- Hardware needed
- None
- Prover cooperation
- Required
- Confidentiality
- Revealing
- Category
- Cryptography & computation
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
A training run stayed within declared limits
Transcript checks for rules on training compute, data and hyperparameters (Shavit; Choi et al.).
Readiness for a stated use
Assessed use: checking from its transcript that a training run followed declared rules
medium confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
R2 through later peer-reviewed work by Choi et al. and Srivastava et al. The original verification rule is broken, and no independent attack on the later defences has been published.
- R1 met: Jia et al. define proof-of-learning and its security goal S-0028, and Shavit sets out training-transcript verification for rules on large training runs S-0029.
- R2 met through later work, not through the original scheme. The original authors demonstrated spoofs that pass verification across configurations at a fraction of the cost of earlier spoofing strategies S-0027. An earlier independent attack reported spoofs cheaper than honest training S-1109, which the original authors dispute S-0027. These breaks invalidate the original demonstration, including the public code, which implements that rule S-1111. Choi et al. publish peer-reviewed end-to-end experiments against a stated set of spoofing attacks, training GPT-2 (124M) and testing published Pythia checkpoints up to 1B on GPUs S-0030. The paper links no code; the rubric does not require code for results described in enough detail to repeat. Srivastava et al. replicate ResNet-50 training and GPT-2 fine-tuning bit for bit on three NVIDIA GPU types, against a trainer that may poison data, and release their code S-3081. The open critical flaws concern the original rule, not the evidence the level rests on.
- R3 not met: Verde realises this mechanism for delegated training jobs, but Gensyn states that its public runtime is limited to LLM inference S-1812, so its production use does not count for training verification. As of September 2026 no third party is known to rely on training-transcript checks, and no production-grade implementation has been published.
- R4 not met: no independent attack on the post-2023 defences has been published.
Evidence needed for the next level
Use by a party other than the developer, or a production-grade implementation, at realistic training scale.
Verification rules with formal robustness arguments, as Fang et al. argue are needed, or an independent red-team of the post-2023 defences.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / disputed / demonstrated attack
Adversarial-example spoofs pass verification at lower cost than training
Zhang et al. construct proofs that pass the original verification "with significantly less cost than generating a proof by the prover". Their attack uses adversarial-example-style perturbations, and they demonstrate it on CIFAR-10, CIFAR-100 and an ImageNet subset S-1109. They suggest dynamic thresholds, or proofs built on verifiable computation, as countermeasures S-1109.
Fang et al., who include the original PoL authors, state that the attack assumes the adversary sets the checkpoint interval k, which the verifier should set, and that the verifier can prevent it by using a small k S-0027.
critical / open / demonstrated attack
Structurally correct spoofs exploit tolerance thresholds and sampled checks
Fang et al., including the original proposers, present spoofing strategies that work across PoL configurations at "a fraction of the cost of previous spoofing strategies" S-0027. The strategies exploit the tolerance that verification must allow for hardware noise, and the choice of which updates the verifier re-runs S-0027.
significant / open / theoretical argument
No provably robust verification without better optimisation theory
Fang et al. conclude that "one cannot develop a provably robust PoL verification mechanism without further understanding of optimization in deep learning" S-0027. Shavit notes that the PoL literature "has been heuristic-based" S-0029.
significant / open / theoretical argument
Rule-compliance transcripts face a stronger adversary
Shavit argues that proving a training transcript "appears to be strictly harder than PoL". The adversary knows the true transcript and may spend extra compute to build a compliant-looking one S-0029.
significant / open / open question
Small data changes and masked hyperparameters may go undetected
Choi et al. state that their protocol cannot yet detect modest data additions, such as inserted backdoors. They note that attacks could be hidden with "cleverly chosen hyperparameters", such as a temporarily lower learning rate than reported, and that the protocol does not apply to online or reinforcement learning S-0030.
What still blocks use or stronger assurance
- S-0028S-0030
- S-0029
Transcripts are large: weight checkpoints may each require terabytes S-0029.
- S-0030
The verifier must reproduce training segments, which may be infeasible if the prover uses specialised or proprietary hardware S-0030.
- S-0027
The noise tolerance needed for honest reproduction is what structurally correct spoofs exploit S-0027.
- S-0029
Tying transcripts to real chips needs on-chip weight-snapshot logging, chip inspections and a trusted chip-owner directory S-0029.
Connections in the research map
Alternative approaches
Concepts used
Implementations
The Consortium’s case files
Related editorial reviews use the Consortium’s own descriptive scores and review dates. Their scores are separate from the atlas readiness rubric.
PT-07 / AttestationProof that training happened properlyRead case file ↗Sources and provenance
- S-0028 / Tier A
Proof-of-Learning: Definitions and Practice ↗
H. Jia, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, A. Thudi, V. Chandrasekaran, N. Papernot · 2021 · 2021 IEEE Symposium on Security and Privacy (SP), pp. 1039-1056
Supports: PoL definition, transcript contents, verification, security analysis, limits
Locator: Definition 1; Algorithm 2; §IV–VI; Table I
Version and catalogue details - S-1111 / Tier B
Proof-of-Learning: code for Proof-of-Learning: Definitions and Practice ↗
CleverHans Lab · 2021 · GitHub
Supports: public PoL implementation (train and verify scripts); rationale for the cost of forging
Locator: README
Version and catalogue details - S-1109 / Tier A
"Adversarial Examples" for Proof-of-Learning ↗
R. Zhang, J. Liu, Y. Ding, Z. Wang, Q. Wu, K. Ren · 2022 · 2022 IEEE Symposium on Security and Privacy (SP), pp. 1408-1422
Supports: independent demonstrated spoofing attack; countermeasures
Locator: abstract; §III–V
Version and catalogue details - S-0027 / Tier A
Proof-of-Learning is Currently More Broken Than You Think ↗
C. Fang, H. Jia, A. Thudi, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, V. Chandrasekaran, N. Papernot · 2023 · 8th IEEE European Symposium on Security and Privacy (EuroS&P 2023)
Supports: structurally correct and stochastic spoofing; robustness conclusion; response to Zhang et al.
Locator: abstract; §2.3; attack sections; conclusion
Version and catalogue details - S-0029 / Tier B
What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring ↗
Y. Shavit · 2023 · arXiv
Supports: training-transcript verification for rules; chip logging; open problems; costs
Locator: §4; §5; §5.1; §5.2; §6.1; Table 1
Version and catalogue details - S-0030 / Tier A
Tools for Verifying Neural Models' Training Data ↗
D. Choi, Y. Shavit, D. K. Duvenaud · 2023 · Advances in Neural Information Processing Systems 36 (NeurIPS 2023)
Supports: proof-of-training-data protocol, experiments, defended attacks, costs, limits
Locator: §3; §4.1–4.4; §6; §7; App. A
Version and catalogue details - S-3081 / Tier A
Optimistic Verifiable Training by Controlling Hardware Nondeterminism ↗
M. Srivastava, S. Arora, D. Boneh · 2024 · Advances in Neural Information Processing Systems 37 (NeurIPS 2024)
Supports: exact-replication verifiable training: rounding logs, Merkle-tree dispute search, experiments, overheads, 1-of-n auditor assumption, limitations
Locator: abstract; §3–§5; limitations
Version and catalogue details - S-1809 / Tier B
Verde: Verification via Refereed Delegation for Machine Learning Programs ↗
A. Arun, A. St. Arnaud, A. Titov, B. Wilcox, V. Kolobaric, M. Brinkmann, O. Ersoy, B. Fielding, J. Bonneau · 2025 · arXiv
Supports: Verde dispute narrowing for training jobs; RepOps LoRA fine-tuning overhead
Locator: §3; Table 2
Version and catalogue details - S-1812 / Tier B
gensyn-ai/ree: Gensyn Reproducible Execution Environment (GitHub repository) ↗
Gensyn · 2026 · GitHub
Supports: Gensyn's REE release limited to reproducible LLM inference (provider-reported)
Locator: README
Version and catalogue details - S-0022 / Tier A
Trustless Audits without Revealing Data or Models ↗
S. Waiwitlikhit, I. Stoica, Y. Sun, T. Hashimoto, D. Kang · 2024 · 41st International Conference on Machine Learning (ICML 2024)
Supports: cryptographic alternative (ZK proofs of SGD)
Locator: abstract
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review