ZKROWNN: Zero Knowledge Right of Ownership for Neural Networks
Nojan Sheybani, Zahra Ghodsi, Ritvik Kapila, Farinaz Koushanfar
Abstract
Training contemporary AI models requires investment in procuring learning data and computing resources, making the models intellectual property of the owners. Popular model watermarking solutions rely on key input triggers for detection; the keys have to be kept private to prevent discovery, forging, and removal of the hidden signatures. We present ZKROWNN, the first automated end-to-end framework utilizing Zero-Knowledge Proofs (ZKP) that enable an entity to validate their ownership of a model, while preserving the privacy of the watermarks. ZKROWNN permits a third party client to verify model ownership in less than a second, requiring as little as a few KBs of communication.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext cce0353e-d20f-4333-a4db-bfff061c6097Cited by top-tier papers1
Ask how each one uses itBuilds on5
- Turning Your Weakness Into a Strength: Watermarking Deep Neural Networks by BackdooringYossi Adi, Carsten Baum, Moustapha Cissé, Benny Pinkas et al.USENIX Security 2018 · 832 citations
- Sonic: Zero-Knowledge SNARKs from Linear-Size Universal and Updatable Structured Reference StringsMary Maller, Sean Bowe, Markulf Kohlweiss, Sarah MeiklejohnCCS 2019 · 412 citations
- Mystique: Efficient Conversions for Zero-Knowledge Proofs with Applications to Machine LearningChenkai Weng, Kang Yang, Xiang Xie, Jonathan Katz et al.USENIX Security 2021 · 161 citations
- Model Watermarking for Image Processing NetworksJie Zhang, Dongdong Chen, Jing Liao, Han Fang et al.AAAI 2020 · 160 citations
- Succinct Zero Knowledge for Floating Point ComputationsSanjam Garg, Abhishek Jain, Zhengzhong Jin, Yinuo ZhangCCS 2022 · 11 citations
Related papers
- PVMark: Enabling Public Verifiability for LLM Watermarking SchemesHaohua Duan, Liyao Xiang, Xin Zhang, Baochun Li et al.USENIX Security 2026 · 2 citations
- Identification for Deep Neural Network: Simply Adjusting Few Weights!Yingjie Lao, Peng Yang, Weijie Zhao, Ping LiICDE 2022 · 19 citations
- Experimenting with Zero-Knowledge Proofs of TrainingSanjam Garg, Aarushi Goel, Somesh Jha, Saeed Mahloujifar et al.CCS 2023 · 31 citations
- NoisePrints: Distortion-Free Watermarks for Authorship in Private Diffusion ModelsNir Goren, Oren Katzir, Abhinav Nakarmi, Eyal Ronen et al.ICLR 2026 · 5 citations
- EmMark: Robust Watermarks for IP Protection of Embedded Quantized Large Language ModelsRuisi Zhang, Farinaz KoushanfarDAC 2024 · 11 citations
