M-0005 / Cryptography & computation

Zero-knowledge proofs of training constraints

Cryptographic proofs that a training run followed a committed dataset, procedure and rules, checkable without revealing the model or the data.

R2 DemonstratedSource reviewed 2026-09-25

01 / The mechanism and its boundary

What the technique establishes

Zero-knowledge proofs of training would let an AI developer prove that a model was trained as declared, on a committed dataset and within agreed rules such as a compute limit, without showing the weights or the data. Peer-reviewed systems have done this for small models. Kaizen proves training iterations of a 10-million-parameter image model. ZkAudit proves single training steps of small image and recommender models, and estimates the cost of full runs. A peer-reviewed 2026 paper proves single fine-tuning steps of 13-billion-parameter language models. A 2026 preprint argues that frontier-scale verification is feasible by proving only randomly challenged training steps, anchored by network observations. It is unbuilt, and its overheads are estimates. The biggest obstacle is cost: each proven training step takes minutes. The biggest known weakness of the frontier design is that sparse challenges give probabilistic detection, and its network anchor cannot see traffic inside a server.

Threat model
Adversarial prover
Adversarial evaluation
Published analysis
Hardware needed
None
Prover cooperation
Required
Confidentiality
Partial
Category
Cryptography & computation

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R2 Demonstrated

Assessed use: proving a training run followed a committed specification and data

medium confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

Peer-reviewed end-to-end results exist for small models against a stated adversary, and public code proves single fine-tuning steps of 13-billion-parameter language models. The frontier-scale design is unbuilt.

  • R1 met: Kaizen S-1110 and ZkAudit S-0022 define proofs of correct training on committed data. Peigné et al. describe a frontier design with stated claims, trust anchors and open problems S-0025.
  • R2 met through reproducible published end-to-end results and a public working implementation. Kaizen and ZkAudit are peer-reviewed, specify the protocol, setup and parameters, and state a cheating prover as the adversary. Kaizen measures proving per training iteration of a 10-million-parameter VGG-11, with recursive aggregation implemented S-1110. ZkAudit proves single SGD steps of MobileNet v2 and recommender models on AWS g4dn.8xlarge instances, and estimates the cost of proving full training runs S-0022. Kaizen links no code S-1110, and ZkAudit links only an anonymised review repository S-0022; the rubric does not require code on this route. VeriLoRA, peer-reviewed and with public code, proves one LoRA fine-tuning step on a single sample for LLaMA and OPT models of 3 to 13 billion parameters S-3080. All of these results are far below frontier training.
  • R3 not met: as of September 2026 no deployment or reliance by a third party has been published. The frontier design is unimplemented, and its authors present its costs as estimates, with target values "not yet measured" S-0025.
  • R4 not met: no independent evaluation has been published.

Evidence needed for the next level

  • Any use by a party other than the developer, or a production-grade, available implementation.

  • An independent public security evaluation of a proof-of-training system.

  • For the frontier use: an implementation of challenge-based step proofs at realistic model and cluster scale.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / open / theoretical argument

Sparse challenge-based auditing gives probabilistic detection only

In the frontier design, proofs are generated only for training steps the auditor challenges after the hash chain is frozen. The authors describe this as "detection-grade, not universal": the verifier "cannot make universal claims about every step", but can detect deviations with high probability when sampling occurs S-0025.

S-0025

significant / open / theoretical argument

The network anchor misses traffic inside a server

The frontier design observes traffic between nodes only, so "intra-node NVLink is invisible". Its attested-SmartNIC tier is weaker than a physical tap against firmware or supply-chain adversaries S-0025.

S-0025

significant / open / open question

Proven training uses fixed-point arithmetic

Kaizen and ZkAudit prove training in fixed point S-1110 S-0022. ZkAudit reports accuracy 0.5 to 0.7 points below fp32 on three image datasets S-0022. The frontier design proposes native floating-point precompiles, and lists the algebraic reductions needed to verify floating-point matrix multiplication as an open problem S-0025.

S-1110S-0022S-0025

minor / open / open question

A proof binds committed data but does not vet it

ZkAudit notes that it does not protect against data poisoning, and that it reveals the model architecture S-0022. Whether committed data obeys a rule needs a separate proven audit function S-0022.

S-0022

What still blocks use or stronger assurance

  1. Proving costs minutes per training step even for small models: 15 minutes per VGG-11 iteration S-1110 and 47.5 to 328.3 seconds per single-image MobileNet v2 SGD step S-0022.

    S-1110S-0022
  2. The frontier design is unbuilt and lists 13 open problems, including zero-knowledge proofs of backpropagation and deterministic attention backward passes with low overhead S-0025.

    S-0025
  3. The frontier design needs deterministic training; current deterministic tensor-parallel all-reduce is reported to lose 64 to 89% of bandwidth S-0025.

    S-0025
  4. The frontier design needs an open-hardware network tap at line rate, listed as an open problem S-0025.

    Dependency: Network taps and certifiers

    S-0025
  5. Mixture-of-experts, reinforcement-learning post-training and multi-site training are not yet covered S-0025.

    S-0025

Connections in the research map

Complementary techniques

Alternative approaches

Concepts used

The Consortium’s case files

Related editorial reviews use the Consortium’s own descriptive scores and review dates. Their scores are separate from the atlas readiness rubric.

PT-07 / AttestationProof that training happened properlyRead case file ↗

Sources and provenance

  1. S-1110 / Tier A

    Zero-Knowledge Proofs of Training for Deep Neural Networks ↗

    K. Abbaszadeh, C. Pappas, J. Katz, D. Papadopoulos · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024), pp. 4316-4330

    Supports: Kaizen zkPoT definition, techniques, threat model and costs

    Locator: abstract; §1.2; evaluation

    Version and catalogue details
  2. S-0022 / Tier A

    Trustless Audits without Revealing Data or Models ↗

    S. Waiwitlikhit, I. Stoica, Y. Sun, T. Hashimoto, D. Kang · 2024 · 41st International Conference on Machine Learning (ICML 2024)

    Supports: ZkAudit training proofs, costs, accuracy, limitations, code link

    Locator: abstract; §3; §4–6; evaluation tables; §8

    Version and catalogue details
  3. S-3080 / Tier A

    VeriLoRA: Fine-Tuning Large Language Models with Verifiable Security via Zero-Knowledge Proofs ↗

    G. Liao, T. Wang, S. Zhang, J. Zhang, L. Shi, D. Tao · 2026 · NDSS Symposium 2026

    Supports: VeriLoRA zero-knowledge proofs of single LoRA fine-tuning steps for 3B–13B language models; hardware; costs; public code

    Locator: abstract; evaluation

    Version and catalogue details
  4. S-0025 / Tier B

    Zero knowledge verification for frontier AI training is possible ↗

    P. Peigné, K. Nguyen, P. Wang · 2026 · arXiv

    Supports: frontier-scale design, trust anchors, overhead estimates, open problems

    Locator: abstract; §3.2; MOD. 1–4; Tables 1–2; App. A; App. G.5

    Version and catalogue details
  5. S-1100 / Tier A

    A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning ↗

    Z. Peng, C. Zhao, T. Wang, G. Liao, Z. Lin, Y. Liu, B. Cao, L. Shi, Q. Yang, S. Zhang · 2026 · Artificial Intelligence Review, vol. 59, no. 7, article 157

    Supports: categorisation of verifiable training; survey-reported costs of other systems

    Locator: §III-A1; Table IV

    Version and catalogue details
  6. S-0023 / Tier A

    zkLLM: Zero Knowledge Proofs for Large Language Models ↗

    H. Sun, J. Li, H. Zhang · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024)

    Supports: zkLLM authors' view of extending ZKPs to LLM training

    Locator: §9

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review