Trustless Audits without Revealing Data or Models
Suppakit Waiwitlikhit, Ion Stoica, Yi Sun, Tatsunori Hashimoto, Daniel Kang
Abstract
There is an increasing conflict between business incentives to hide models and data as trade secrets, and the societal need for algorithmic transparency. For example, a rightsholder wishing to know whether their copyrighted works have been used during training must convince the model provider to allow a third party to audit the model and data. Finding a mutually agreeable third party is difficult, and the associated costs often make this approach impractical. In this work, we show that it is possible to simultaneously allow model providers to keep their model weights (but not architecture) and data secret while allowing other parties to trustlessly audit model and data properties. We do this by designing a protocol called ZKAUDIT in which model providers publish cryptographic commitments of datasets and model weights, alongside a zero-knowledge proof (ZKP) certifying that published commitments are derived from training the model. Model providers can then respond to audit requests by privately computing any function F of the dataset (or model) and releasing the output of F alongside another ZKP certifying the correct execution of F . To enable ZKAUDIT, we develop new methods of computing ZKPs for SGD on modern neural nets for simple recommender systems and image classification models capable of high accuracies on ImageNet. Empirically, we show it is possible to provide trustless audits of DNNs, including copyright, censorship, and counterfactual audits with little to no loss in accuracy.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 4e1440ca-9f07-4428-bc9c-3475ca55baf6Cited by top-tier papers3
- Audits Under Resource, Data, and Access Constraints: Scaling Laws For Less Discriminatory AlternativesSarah H. Cen, Salil Goyal, Zaynah Javed, Ananya Karthik et al.NeurIPS 2025 · 3 citations
- Robust ML Auditing using Prior KnowledgeJade Garcia Bourrée, Augustin Godinot, Sayan Biswas, Anne-Marie Kermarrec et al.ICML 2025
- zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM InferenceWenjie Qu, Yijun Sun, Xuanming Liu, Tao Lu et al.USENIX Security 2025
Builds on12
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 2,107 citations
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 1,075 citations
- CrypTen: Secure Multi-Party Computation Meets Machine LearningBrian Knott, Shobha Venkataraman, Awni Y. Hannun, Shubho Sengupta et al.NeurIPS 2021 · 573 citations
- CrypTFlow: Secure TensorFlow InferenceNishant Kumar, Mayank Rathee, Nishanth Chandran, Divya Gupta et al.S&P 2020 · 276 citations
- HEMET: A Homomorphic-Encryption-Friendly Privacy-Preserving Mobile Neural Network ArchitectureQian Lou, Lei JiangICML 2021 · 88 citations
Related papers
- FairProof : Confidential and Certifiable Fairness for Neural NetworksChhavi Yadav, Amrita Roy Chowdhury, Dan Boneh, Kamalika ChaudhuriICML 2024 · 20 citations
- Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model CertificationCarter Luck, Olive Franzese-McLaughlin, Elisaweta Masserova, Akira Takahashi et al.USENIX Security 2026
- Confidential-DPproof: Confidential Proof of Differentially Private TrainingAli Shahin Shamsabadi, Gefei Tan, Tudor Cebere, Aurélien Bellet et al.ICLR 2024 · 24 citations
- GZKP: A GPU Accelerated Zero-Knowledge Proof SystemWeiliang Ma, Qian Xiong, Xuanhua Shi, Xiaosong Ma et al.ASPLOS 2023 · 47 citations
- ZKROWNN: Zero Knowledge Right of Ownership for Neural NetworksNojan Sheybani, Zahra Ghodsi, Ritvik Kapila, Farinaz KoushanfarDAC 2023 · 10 citations
