01 / The mechanism and its boundary
What the technique establishes
Zero-knowledge proofs of training would let an AI developer prove that a model was trained as declared, on a committed dataset and within agreed rules such as a compute limit, without showing the weights or the data. Peer-reviewed systems have done this for small models. Kaizen proves training iterations of a 10-million-parameter image model. ZkAudit proves single training steps of small image and recommender models, and estimates the cost of full runs. A peer-reviewed 2026 paper proves single fine-tuning steps of 13-billion-parameter language models. A 2026 preprint argues that frontier-scale verification is feasible by proving only randomly challenged training steps, anchored by network observations. It is unbuilt, and its overheads are estimates. The biggest obstacle is cost: each proven training step takes minutes. The biggest known weakness of the frontier design is that sparse challenges give probabilistic detection, and its network anchor cannot see traffic inside a server.
- Threat model
- Adversarial prover
- Adversarial evaluation
- Published analysis
- Hardware needed
- None
- Prover cooperation
- Required
- Confidentiality
- Partial
- Category
- Cryptography & computation
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
A training run stayed within declared limits
Proves training followed a committed specification and data; the frontier design adds compute-threshold attestations.
Readiness for a stated use
Assessed use: proving a training run followed a committed specification and data
medium confidence · current · assessed 2026-09-25 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
Peer-reviewed end-to-end results exist for small models against a stated adversary, and public code proves single fine-tuning steps of 13-billion-parameter language models. The frontier-scale design is unbuilt.
- R1 met: Kaizen S-1110 and ZkAudit S-0022 define proofs of correct training on committed data. Peigné et al. describe a frontier design with stated claims, trust anchors and open problems S-0025.
- R2 met through reproducible published end-to-end results and a public working implementation. Kaizen and ZkAudit are peer-reviewed, specify the protocol, setup and parameters, and state a cheating prover as the adversary. Kaizen measures proving per training iteration of a 10-million-parameter VGG-11, with recursive aggregation implemented S-1110. ZkAudit proves single SGD steps of MobileNet v2 and recommender models on AWS g4dn.8xlarge instances, and estimates the cost of proving full training runs S-0022. Kaizen links no code S-1110, and ZkAudit links only an anonymised review repository S-0022; the rubric does not require code on this route. VeriLoRA, peer-reviewed and with public code, proves one LoRA fine-tuning step on a single sample for LLaMA and OPT models of 3 to 13 billion parameters S-3080. All of these results are far below frontier training.
- R3 not met: as of September 2026 no deployment or reliance by a third party has been published. The frontier design is unimplemented, and its authors present its costs as estimates, with target values "not yet measured" S-0025.
- R4 not met: no independent evaluation has been published.
Evidence needed for the next level
Any use by a party other than the developer, or a production-grade, available implementation.
An independent public security evaluation of a proof-of-training system.
For the frontier use: an implementation of challenge-based step proofs at realistic model and cluster scale.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
significant / open / theoretical argument
Sparse challenge-based auditing gives probabilistic detection only
In the frontier design, proofs are generated only for training steps the auditor challenges after the hash chain is frozen. The authors describe this as "detection-grade, not universal": the verifier "cannot make universal claims about every step", but can detect deviations with high probability when sampling occurs S-0025.
significant / open / theoretical argument
The network anchor misses traffic inside a server
The frontier design observes traffic between nodes only, so "intra-node NVLink is invisible". Its attested-SmartNIC tier is weaker than a physical tap against firmware or supply-chain adversaries S-0025.
significant / open / open question
Proven training uses fixed-point arithmetic
Kaizen and ZkAudit prove training in fixed point S-1110 S-0022. ZkAudit reports accuracy 0.5 to 0.7 points below fp32 on three image datasets S-0022. The frontier design proposes native floating-point precompiles, and lists the algebraic reductions needed to verify floating-point matrix multiplication as an open problem S-0025.
minor / open / open question
A proof binds committed data but does not vet it
ZkAudit notes that it does not protect against data poisoning, and that it reveals the model architecture S-0022. Whether committed data obeys a rule needs a separate proven audit function S-0022.
What still blocks use or stronger assurance
- S-1110S-0022
Proving costs minutes per training step even for small models: 15 minutes per VGG-11 iteration S-1110 and 47.5 to 328.3 seconds per single-image MobileNet v2 SGD step S-0022.
- S-0025
The frontier design is unbuilt and lists 13 open problems, including zero-knowledge proofs of backpropagation and deterministic attention backward passes with low overhead S-0025.
- S-0025
The frontier design needs deterministic training; current deterministic tensor-parallel all-reduce is reported to lose 64 to 89% of bandwidth S-0025.
The frontier design needs an open-hardware network tap at line rate, listed as an open problem S-0025.
Dependency: Network taps and certifiers
S-0025- S-0025
Mixture-of-experts, reinforcement-learning post-training and multi-site training are not yet covered S-0025.
Connections in the research map
Complementary techniques
Alternative approaches
The Consortium’s case files
Related editorial reviews use the Consortium’s own descriptive scores and review dates. Their scores are separate from the atlas readiness rubric.
PT-07 / AttestationProof that training happened properlyRead case file ↗Sources and provenance
- S-1110 / Tier A
Zero-Knowledge Proofs of Training for Deep Neural Networks ↗
K. Abbaszadeh, C. Pappas, J. Katz, D. Papadopoulos · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024), pp. 4316-4330
Supports: Kaizen zkPoT definition, techniques, threat model and costs
Locator: abstract; §1.2; evaluation
Version and catalogue details - S-0022 / Tier A
Trustless Audits without Revealing Data or Models ↗
S. Waiwitlikhit, I. Stoica, Y. Sun, T. Hashimoto, D. Kang · 2024 · 41st International Conference on Machine Learning (ICML 2024)
Supports: ZkAudit training proofs, costs, accuracy, limitations, code link
Locator: abstract; §3; §4–6; evaluation tables; §8
Version and catalogue details - S-3080 / Tier A
VeriLoRA: Fine-Tuning Large Language Models with Verifiable Security via Zero-Knowledge Proofs ↗
G. Liao, T. Wang, S. Zhang, J. Zhang, L. Shi, D. Tao · 2026 · NDSS Symposium 2026
Supports: VeriLoRA zero-knowledge proofs of single LoRA fine-tuning steps for 3B–13B language models; hardware; costs; public code
Locator: abstract; evaluation
Version and catalogue details - S-0025 / Tier B
Zero knowledge verification for frontier AI training is possible ↗
P. Peigné, K. Nguyen, P. Wang · 2026 · arXiv
Supports: frontier-scale design, trust anchors, overhead estimates, open problems
Locator: abstract; §3.2; MOD. 1–4; Tables 1–2; App. A; App. G.5
Version and catalogue details - S-1100 / Tier A
A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning ↗
Z. Peng, C. Zhao, T. Wang, G. Liao, Z. Lin, Y. Liu, B. Cao, L. Shi, Q. Yang, S. Zhang · 2026 · Artificial Intelligence Review, vol. 59, no. 7, article 157
Supports: categorisation of verifiable training; survey-reported costs of other systems
Locator: §III-A1; Table IV
Version and catalogue details - S-0023 / Tier A
zkLLM: Zero Knowledge Proofs for Large Language Models ↗
H. Sun, J. Li, H. Zhang · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024)
Supports: zkLLM authors' view of extending ZKPs to LLM training
Locator: §9
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review