Secure and Confidential Certificates of Online Fairness
Olive Franzese, Ali Shahin Shamsabadi, Carter Luck, Hamed Haddadi
摘要
The "black-box service model" enables ML service providers to serve clients while keeping their intellectual property and client data confidential. Confidentiality is critical for delivering ML services legally and responsibly, but makes it difficult for outside parties to verify important model properties such as fairness. Existing methods that assess model fairness confidentially lack either (i) reliability because they certify fairness with respect to a static set of data, and therefore fail to guarantee fairness in the presence of distribution shift or service provider malfeasance; and/or (ii) scalability due to the computational overhead of confidentiality-preserving cryptographic primitives. We address these problems by introducing online fairness certificates, which verify that a model is fair with respect to data received by the service provider online during deployment. We then present OATH, a deployably efficient and scalable zero-knowledge proof protocol for confidential online group fairness certification. OATH exploits statistical properties of group fairness via a "cut-and-choose" style protocol, enabling scalability improvements over baselines.
• Service Phase. Clients query the service provider's model, and send the auditor cryptographic commitments to their results. They perform no expensive ZKP operations, offloading them to the service provider and auditor in the next phase.
• Audit Phase. The service provider commits to a measurement of the fairness metric across all queries in the evaluation set. Then, they verify validity on a randomly sampled subset of the queries. This "cut-and-choose"-style [53] verification provides a statistical bound on the group fairness that is robust to arbitrary malicious behavior from the service provider, while maintaining excellent scaling for large numbers of client queries.
Contributions. We summarize our contributions as follows.
• Online Group Fairness Certificate. OATH audits group fairness over large sets of data received from clients online, rather than assuming fairness will generalize from a static set of offline data.
• Scalability. We exploit statistical properties of group fairness to audit an arbitrarily large set of queries to large neural networks using a constant-sized probabilistic sample (Theorem 4.1). On neural networks with 42.5 million parameters, OATH achieves 4.4 seconds of amortized runtime per query, of which only 0.23 seconds require the client to be online.
• Confidentiality & Reliability. Our cryptographic protocols guarantee that i) the auditor learns no information about the evaluation data or model parameters; and ii) the service provider cannot tamper with the audit's measurement of fairness, except within a very small probability and effect size that do not impact practical use.
Our code is publicly available at https://github.com/cleverhans-lab/ oath-zk-online-fairness.git.
2 Background, Preliminaries & Related Work ML Preliminaries. In this work we focus on probabilistic binary classifiers. That is, we consider models that can be represented as mappings M : X × 0, 1 k → 0, 1, where X is a feature space, and 0, 1 k for some k ∈ N is the space of random seeds. We assume that one feature of each query point q ∈ X corresponds to a binary demographic attribute 0, 1 ∈ S such as sex, race, or disability.
Fairness. The ML community has proposed various fairness definitions tailored to different philosophical assumptions and contexts. We focus on group fairness [22,12,22] which ensures statistical parity across different subgroups. For simplicity, we demonstrate verification of demographic parity [7] in the main text, and generalize to other metrics in Appendix B. In this work we are interested in verifying whether demographic parity is satisfied within a public threshold, as formalized below.
Definition 2.1. [Thresholded demographic parity] A predictor Ŷ satisfies demographic parity with respect to sensitive attribute S within a public threshold θ if:
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- Audits Under Resource, Data, and Access Constraints: Scaling Laws For Less Discriminatory AlternativesSarah H. Cen, Salil Goyal, Zaynah Javed, Ananya Karthik 等NeurIPS 2025 · 被引用 3 次
- Certification of Machine Learning Models via Directional SharpnessGefei Tan, Adrià Gascón, Sarah Meiklejohn, Mariana RaykovaUSENIX Security 2026
- Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model CertificationCarter Luck, Olive Franzese-McLaughlin, Elisaweta Masserova, Akira Takahashi 等USENIX Security 2026
它引用的顶会 Paper15
- SecureML: A System for Scalable Privacy-Preserving Machine LearningPayman Mohassel, Yupeng ZhangS&P 2017 · 被引用 2,107 次
- Wolverine: Fast, Scalable, and Communication-Efficient Zero-Knowledge Proofs for Boolean and Arithmetic CircuitsChenkai Weng, Kang Yang, Jonathan Katz, Xiao WangS&P 2021 · 被引用 205 次
- Mystique: Efficient Conversions for Zero-Knowledge Proofs with Applications to Machine LearningChenkai Weng, Kang Yang, Xiang Xie, Jonathan Katz 等USENIX Security 2021 · 被引用 161 次
- ZKML: An Optimizing System for ML Inference in Zero-Knowledge ProofsBing-Jyue Chen, Suppakit Waiwitlikhit, Ion Stoica, Daniel KangEuroSys 2024 · 被引用 65 次
- Fairness Transferability Subject to Bounded Distribution ShiftYatong Chen, Reilly Raab, Jialu Wang, Yang LiuNeurIPS 2022 · 被引用 40 次
相关 Paper
- FairProof : Confidential and Certifiable Fairness for Neural NetworksChhavi Yadav, Amrita Roy Chowdhury, Dan Boneh, Kamalika ChaudhuriICML 2024 · 被引用 20 次
- FairZK: A Scalable System to Prove Machine Learning Fairness in Zero-KnowledgeTianyu Zhang, Shen Dong, Oyku Deniz Kose, Yanning Shen 等S&P 2025
- Confidential-PROFITT: Confidential PROof of FaIr Training of TreesAli Shahin Shamsabadi, Sierra Calanda Wyllie, Nicholas Franzese, Natalie Dullerud 等ICLR 2023
- Trustless Audits without Revealing Data or ModelsSuppakit Waiwitlikhit, Ion Stoica, Yi Sun, Tatsunori Hashimoto 等ICML 2024 · 被引用 20 次
- Azkaban: A Zero-Knowledge Abstract Analysis for Neural NetworksSankha Das, Lucien K. L. Ng, Yibin Yang, Vladimir Kolesnikov 等CCS 2026
