{
  "schema_version": "1.2.0",
  "rubric_version": "1.1",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "M-0005",
    "slug": "zk-proofs-of-training-constraints",
    "title": "Zero-knowledge proofs of training constraints",
    "aliases": [
      "zero-knowledge proofs of training",
      "zkPoT",
      "verifiable training"
    ],
    "status": "published",
    "last_reviewed": "2026-09-25",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": [
        "codex-review"
      ]
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "Cryptographic proofs that a training run followed a committed dataset, procedure and rules, checkable without revealing the model or the data.",
    "summary": "Zero-knowledge proofs of training would let an AI developer prove that a model was trained as declared, on a committed dataset and within agreed rules such as a compute limit, without showing the weights or the data. Peer-reviewed systems have done this for small models. Kaizen proves training iterations of a 10-million-parameter image model. ZkAudit proves single training steps of small image and recommender models, and estimates the cost of full runs. A 2025 preprint proves single fine-tuning steps of 13-billion-parameter language models. A 2026 preprint argues that frontier-scale verification is feasible by proving only randomly challenged training steps, anchored by network observations. It is unbuilt, and its overheads are estimates. The biggest obstacle is cost: each proven training step takes minutes. The biggest known weakness of the frontier design is that sparse challenges give probabilistic detection, and its network anchor cannot see traffic inside a server.",
    "category": "cryptographic-computational",
    "secondary_categories": [],
    "verifies": [
      {
        "claim": "C-0007",
        "role": "primary",
        "note": "Proves training followed a committed specification and data; the frontier design adds compute-threshold attestations."
      }
    ],
    "threat_model": "adversarial",
    "adversarial_evaluation": "analysis",
    "hardware_requirement": "none",
    "prover_cooperation": "required",
    "confidentiality": "partial",
    "depends_on": [
      {
        "target": "M-0013",
        "note": "The frontier-scale design by Peigné et al. anchors its commitments with an auditor-controlled network tap or an attested SmartNIC."
      }
    ],
    "readiness": {
      "assessment": true,
      "level": "R2",
      "scope": "proving a training run followed a committed specification and data",
      "rubric_version": "1.1",
      "rationale": "Peer-reviewed end-to-end results exist for small models against a stated adversary, and public code proves single fine-tuning steps of 13-billion-parameter language models. The frontier-scale design is unbuilt.\n\n- **R1** met: Kaizen [[S-1110]] and ZkAudit [[S-0022]] define proofs of correct training on committed data. Peigné et al. describe a frontier design with stated claims, trust anchors and open problems [[S-0025]].\n- **R2** met through reproducible published end-to-end results and a public working implementation. Kaizen and ZkAudit are peer-reviewed, specify the protocol, setup and parameters, and state a cheating prover as the adversary. Kaizen measures proving per training iteration of a 10-million-parameter VGG-11, with recursive aggregation implemented [[S-1110]]. ZkAudit proves single SGD steps of MobileNet v2 and recommender models on AWS g4dn.8xlarge instances, and estimates the cost of proving full training runs [[S-0022]]. Kaizen links no code [[S-1110]], and ZkAudit links only an anonymised review repository [[S-0022]]; the rubric does not require code on this route. VeriLoRA, a preprint with public code, proves one LoRA fine-tuning step on a single sample for LLaMA and OPT models of 3 to 13 billion parameters [[S-3080]]. All of these results are far below frontier training.\n- **R3** not met: as of September 2026 no deployment or reliance by a third party has been published. The frontier design is unimplemented, and its authors present its costs as estimates, with target values \"not yet measured\" [[S-0025]].\n- **R4** not met: no independent evaluation has been published.",
      "evidence": [
        "S-1110",
        "S-0022",
        "S-3080",
        "S-0025"
      ],
      "next_level_gaps": [
        "Any use by a party other than the developer, or a production-grade, available implementation.",
        "An independent public security evaluation of a proof-of-training system.",
        "For the frontier use: an implementation of challenge-based step proofs at realistic model and cluster scale."
      ],
      "confidence": "medium",
      "assessed_by": [
        "claude-review",
        "codex-review"
      ],
      "assessed_on": "2026-09-25",
      "status": "current",
      "dispute": null
    },
    "flaws": [
      {
        "assessment": true,
        "title": "Sparse challenge-based auditing gives probabilistic detection only",
        "kind": "theoretical-argument",
        "severity": "significant",
        "status": "open",
        "description": "In the frontier design, proofs are generated only for training steps the auditor challenges after the hash chain is frozen. The authors describe this as \"detection-grade, not universal\": the verifier \"cannot make universal claims about every step\", but can detect deviations with high probability when sampling occurs [[S-0025]].",
        "sources": [
          "S-0025"
        ],
        "response": null
      },
      {
        "assessment": true,
        "title": "The network anchor misses traffic inside a server",
        "kind": "theoretical-argument",
        "severity": "significant",
        "status": "open",
        "description": "The frontier design observes traffic between nodes only, so \"intra-node NVLink is invisible\". Its attested-SmartNIC tier is weaker than a physical tap against firmware or supply-chain adversaries [[S-0025]].",
        "sources": [
          "S-0025"
        ],
        "response": null
      },
      {
        "assessment": true,
        "title": "Proven training uses fixed-point arithmetic",
        "kind": "open-question",
        "severity": "significant",
        "status": "open",
        "description": "Kaizen and ZkAudit prove training in fixed point [[S-1110]] [[S-0022]]. ZkAudit reports accuracy 0.5 to 0.7 points below fp32 on three image datasets [[S-0022]]. The frontier design proposes native floating-point precompiles, and lists the algebraic reductions needed to verify floating-point matrix multiplication as an open problem [[S-0025]].",
        "sources": [
          "S-1110",
          "S-0022",
          "S-0025"
        ],
        "response": null
      },
      {
        "assessment": true,
        "title": "A proof binds committed data but does not vet it",
        "kind": "open-question",
        "severity": "minor",
        "status": "open",
        "description": "ZkAudit notes that it does not protect against data poisoning, and that it reveals the model architecture [[S-0022]]. Whether committed data obeys a rule needs a separate proven audit function [[S-0022]].",
        "sources": [
          "S-0022"
        ],
        "response": null
      }
    ],
    "blockers": [
      {
        "text": "Proving costs minutes per training step even for small models: 15 minutes per VGG-11 iteration [[S-1110]] and 47.5 to 328.3 seconds per single-image MobileNet v2 SGD step [[S-0022]].",
        "theme": "performance-compatibility",
        "blocked_by": null,
        "sources": [
          "S-1110",
          "S-0022"
        ]
      },
      {
        "text": "The frontier design is unbuilt and lists 13 open problems, including zero-knowledge proofs of backpropagation and deterministic attention backward passes with low overhead [[S-0025]].",
        "theme": "protocol-soundness",
        "blocked_by": null,
        "sources": [
          "S-0025"
        ]
      },
      {
        "text": "The frontier design needs deterministic training; current deterministic tensor-parallel all-reduce is reported to lose 64 to 89% of bandwidth [[S-0025]].",
        "theme": "performance-compatibility",
        "blocked_by": null,
        "sources": [
          "S-0025"
        ]
      },
      {
        "text": "The frontier design needs an open-hardware network tap at line rate, listed as an open problem [[S-0025]].",
        "theme": "hardware-trust",
        "blocked_by": "M-0013",
        "sources": [
          "S-0025"
        ]
      },
      {
        "text": "Mixture-of-experts, reinforcement-learning post-training and multi-site training are not yet covered [[S-0025]].",
        "theme": "coverage-hidden-compute",
        "blocked_by": null,
        "sources": [
          "S-0025"
        ]
      }
    ],
    "challenge_themes": [
      "performance-compatibility",
      "protocol-soundness",
      "hardware-trust",
      "coverage-hidden-compute",
      "evidence-binding"
    ],
    "organizations": [],
    "people": [],
    "sources": [
      {
        "source": "S-1110",
        "supports": "Kaizen zkPoT definition, techniques, threat model and costs",
        "locator": "abstract; §1.2; evaluation"
      },
      {
        "source": "S-0022",
        "supports": "ZkAudit training proofs, costs, accuracy, limitations, code link",
        "locator": "abstract; §3; §4–6; evaluation tables; §8"
      },
      {
        "source": "S-3080",
        "supports": "VeriLoRA zero-knowledge proofs of single LoRA fine-tuning steps for 3B–13B language models; hardware; costs; public code",
        "locator": "abstract; evaluation"
      },
      {
        "source": "S-0025",
        "supports": "frontier-scale design, trust anchors, overhead estimates, open problems",
        "locator": "abstract; §3.2; MOD. 1–4; Tables 1–2; App. A; App. G.5"
      },
      {
        "source": "S-1100",
        "supports": "categorisation of verifiable training; survey-reported costs of other systems",
        "locator": "§III-A1; Table IV"
      },
      {
        "source": "S-0023",
        "supports": "zkLLM authors' view of extending ZKPs to LLM training",
        "locator": "§9"
      }
    ],
    "concepts": [
      "K-0010",
      "K-0024",
      "K-0014",
      "K-0020",
      "K-0008",
      "K-0023"
    ],
    "complements": [],
    "alternatives": [
      "M-0006"
    ],
    "type": "mechanism",
    "implementations": [],
    "url": "https://trustbutveri.fyi/mechanisms/zk-proofs-of-training-constraints/",
    "source_file": "content/mechanisms/zk-proofs-of-training-constraints.md",
    "flags_all": [],
    "body_markdown": "## How it works\n\nA zero-knowledge proof of training (zkPoT) lets a party prove \"that they have correctly trained a committed model based on a committed dataset\", revealing nothing further about the model or the data [[S-1110]]. A survey calls this verifiable training: certifying that updated parameters result from the declared procedure [[S-1100]].\n\n**Small-scale protocols.** Published systems follow three steps:\n1. The prover commits to the dataset [[S-1110]] [[S-0022]].\n2. It fixes the data order using verified randomness [[S-0022]].\n3. It proves each gradient-descent step: the forward pass, the backward pass and the weight update [[S-0022]].\n\nKaizen adds three techniques [[S-1110]]:\n- sumcheck-based proofs specialised for gradient descent;\n- recursive composition, so that proof size and verifier time do not grow with the number of iterations;\n- aggregatable polynomial commitments.\n\nZkAudit adds proofs of arbitrary audit functions over the committed data and weights [[S-0022]].\n\n**A frontier-scale design.** Peigné et al. propose a design for frontier training with four parts [[S-0025]]:\n- **Commitment.** Before training, the trainer publishes a hashed commitment that combines the architecture specification, a Merkle root of the dataset and the root of the initial weights [[S-0025]].\n- **Hash chain.** During training, the GPUs compute Merkle roots of per-layer tensors at every step and publish them in a hash chain [[S-0025]].\n- **Network anchor.** An auditor-controlled network tap, or an attested SmartNIC, records hashes of traffic between nodes as an independent anchor [[S-0025]] (see [[M-0013]]).\n- **Challenges.** After the chain is frozen, the auditor challenges sampled steps. The trainer re-executes those steps, and a zero-knowledge virtual machine, with native precompiles mostly for floating-point operations, checks them against the committed roots [[S-0025]].\n\nThe design also includes genesis proofs and \"ex-ante\" attestations that enforce policy invariants, such as compute thresholds [[S-0025]].\n\n## What it establishes\n**What it can establish.**\n- A zkPoT shows that the committed weights resulted from the declared training procedure on the committed dataset [[S-1110]] [[S-0022]]. This bears on [[C-0007]].\n- Peigné et al. aim to verify further claims: that training faithfully executed a pre-committed specification, how much compute it consumed, its training regime and data-content filters [[S-0025]].\n\n**What it cannot establish.**\n- **That the data is acceptable.** A proof binds data to a commitment but does not vet it. ZkAudit does not protect against data poisoning [[S-0022]].\n- **Every step, in the frontier design.** Sparse auditing is \"detection-grade, not universal\" [[S-0025]].\n- **Full confidentiality.** ZkAudit reveals the model architecture [[S-0022]].\n\n## Threat model\nThe small-scale systems assume a cheating prover bounded by cryptographic assumptions, and a public training algorithm and architecture [[S-1110]] [[S-0022]]. The frontier design adds trust anchors [[S-0025]]:\n- deterministic GPU execution;\n- a physical network tap, or secure boot and device identity for the SmartNIC tier;\n- the soundness of the zkVM;\n- a public proof-checker binary.\n\nIt does not cover traffic inside a server, and its SmartNIC tier is weaker against supply-chain adversaries [[S-0025]].\n\n## Evidence\n- **Kaizen (CCS 2024).** It proves training of a 10-million-parameter VGG-11 on CIFAR-10 at batch size 16. The prover takes 15 minutes per iteration; the proof is 1.63 MB and verifies in 130 milliseconds, independent of the number of iterations [[S-1110]]. Its authors report \"24× faster prover time\" than generic recursive proof systems [[S-1110]].\n- **ZkAudit (ICML 2024).** It proved single SGD steps for MobileNet v2 image classifiers and a recommender model on AWS g4dn.8xlarge instances. Proving one step on a single image took 47.5 to 328.3 seconds for MobileNet v2 (1.0, 224), depending on the fixed-point scale factor. The authors estimated, rather than generated, proofs of full training runs, at costs of hundreds to thousands of dollars [[S-0022]].\n- **VeriLoRA (2025 preprint).** It proves one LoRA fine-tuning step, covering the forward pass, backward pass and parameter update, on a single sample, for LLaMA and OPT models of 3 to 13 billion parameters on one A100 GPU. Proving a step takes minutes and verifying it takes seconds, and the code is public [[S-3080]].\n- **Other systems.** The survey lists further verifiable-training systems in its Table IV [[S-1100]].\n- **The frontier design.** Peigné et al. estimate 2 to 10% training-side overhead for a Llama 3.1 405B-scale run, and deployment \"within approximately 36 months\" [[S-0025]]. The paper reports no prototype or measurements of its own, and marks its target values as \"not yet measured\" [[S-0025]].\n\nThe zkLLM authors wrote in 2024 that zero-knowledge proofs of LLM training \"may pose insurmountable challenges\" [[S-0023]].\n\n## Limitations\n**Cost.** A 10-million-parameter model needs minutes of proving per step [[S-1110]]. ZkAudit's authors leave scaling to larger models, such as language models, to future work [[S-0022]]. VeriLoRA reaches 13-billion-parameter language models, but for single-sample steps that update only low-rank adapters [[S-3080]].\n\n**Open problems in the frontier design.** Peigné et al. list 13, including [[S-0025]]:\n- zero-knowledge proofs of backpropagation;\n- deterministic attention backward passes with under 5% overhead;\n- an open-hardware network tap at line rate;\n- a way to tell silent data corruption apart from adversarial deviation;\n- coverage of mixture-of-experts, reinforcement-learning post-training and multi-site training.\n\nThey also report that current deterministic tensor-parallel all-reduce configurations lose 64 to 89% of bandwidth [[S-0025]].\n\n**Attacks.** As of September 2026 no attack on these proof systems has been published.",
    "body_text": "How it works A zero-knowledge proof of training (zkPoT) lets a party prove \"that they have correctly trained a committed model based on a committed dataset\", revealing nothing further about the model or the data [S-1110]. A survey calls this verifiable training: certifying that updated parameters result from the declared procedure [S-1100]. Small-scale protocols. Published systems follow three steps: 1. The prover commits to the dataset [S-1110] [S-0022]. 2. It fixes the data order using verified randomness [S-0022]. 3. It proves each gradient-descent step: the forward pass, the backward pass and the weight update [S-0022]. Kaizen adds three techniques [S-1110]: - sumcheck-based proofs specialised for gradient descent; - recursive composition, so that proof size and verifier time do not grow with the number of iterations; - aggregatable polynomial commitments. ZkAudit adds proofs of arbitrary audit functions over the committed data and weights [S-0022]. A frontier-scale design. Peigné et al. propose a design for frontier training with four parts [S-0025]: - Commitment. Before training, the trainer publishes a hashed commitment that combines the architecture specification, a Merkle root of the dataset and the root of the initial weights [S-0025]. - Hash chain. During training, the GPUs compute Merkle roots of per-layer tensors at every step and publish them in a hash chain [S-0025]. - Network anchor. An auditor-controlled network tap, or an attested SmartNIC, records hashes of traffic between nodes as an independent anchor [S-0025] (see Network taps and certifiers). - Challenges. After the chain is frozen, the auditor challenges sampled steps. The trainer re-executes those steps, and a zero-knowledge virtual machine, with native precompiles mostly for floating-point operations, checks them against the committed roots [S-0025]. The design also includes genesis proofs and \"ex-ante\" attestations that enforce policy invariants, such as compute thresholds [S-0025]. What it establishes What it can establish. - A zkPoT shows that the committed weights resulted from the declared training procedure on the committed dataset [S-1110] [S-0022]. This bears on A training run stayed within declared limits. - Peigné et al. aim to verify further claims: that training faithfully executed a pre-committed specification, how much compute it consumed, its training regime and data-content filters [S-0025]. What it cannot establish. - That the data is acceptable. A proof binds data to a commitment but does not vet it. ZkAudit does not protect against data poisoning [S-0022]. - Every step, in the frontier design. Sparse auditing is \"detection-grade, not universal\" [S-0025]. - Full confidentiality. ZkAudit reveals the model architecture [S-0022]. Threat model The small-scale systems assume a cheating prover bounded by cryptographic assumptions, and a public training algorithm and architecture [S-1110] [S-0022]. The frontier design adds trust anchors [S-0025]: - deterministic GPU execution; - a physical network tap, or secure boot and device identity for the SmartNIC tier; - the soundness of the zkVM; - a public proof-checker binary. It does not cover traffic inside a server, and its SmartNIC tier is weaker against supply-chain adversaries [S-0025]. Evidence - Kaizen (CCS 2024). It proves training of a 10-million-parameter VGG-11 on CIFAR-10 at batch size 16. The prover takes 15 minutes per iteration; the proof is 1.63 MB and verifies in 130 milliseconds, independent of the number of iterations [S-1110]. Its authors report \"24× faster prover time\" than generic recursive proof systems [S-1110]. - ZkAudit (ICML 2024). It proved single SGD steps for MobileNet v2 image classifiers and a recommender model on AWS g4dn.8xlarge instances. Proving one step on a single image took 47.5 to 328.3 seconds for MobileNet v2 (1.0, 224), depending on the fixed-point scale factor. The authors estimated, rather than generated, proofs of full training runs, at costs of hundreds to thousands of dollars [S-0022]. - VeriLoRA (2025 preprint). It proves one LoRA fine-tuning step, covering the forward pass, backward pass and parameter update, on a single sample, for LLaMA and OPT models of 3 to 13 billion parameters on one A100 GPU. Proving a step takes minutes and verifying it takes seconds, and the code is public [S-3080]. - Other systems. The survey lists further verifiable-training systems in its Table IV [S-1100]. - The frontier design. Peigné et al. estimate 2 to 10% training-side overhead for a Llama 3.1 405B-scale run, and deployment \"within approximately 36 months\" [S-0025]. The paper reports no prototype or measurements of its own, and marks its target values as \"not yet measured\" [S-0025]. The zkLLM authors wrote in 2024 that zero-knowledge proofs of LLM training \"may pose insurmountable challenges\" [S-0023]. Limitations Cost. A 10-million-parameter model needs minutes of proving per step [S-1110]. ZkAudit's authors leave scaling to larger models, such as language models, to future work [S-0022]. VeriLoRA reaches 13-billion-parameter language models, but for single-sample steps that update only low-rank adapters [S-3080]. Open problems in the frontier design. Peigné et al. list 13, including [S-0025]: - zero-knowledge proofs of backpropagation; - deterministic attention backward passes with under 5% overhead; - an open-hardware network tap at line rate; - a way to tell silent data corruption apart from adversarial deviation; - coverage of mixture-of-experts, reinforcement-learning post-training and multi-site training. They also report that current deterministic tensor-parallel all-reduce configurations lose 64 to 89% of bandwidth [S-0025]. Attacks. As of September 2026 no attack on these proof systems has been published.",
    "referenced_by": [
      {
        "id": "M-0014",
        "title": "Bandwidth limits and compartmentalization",
        "url": "https://trustbutveri.fyi/mechanisms/bandwidth-limits-and-compartmentalization/"
      },
      {
        "id": "M-0006",
        "title": "Training-transcript verification (proof-of-learning)",
        "url": "https://trustbutveri.fyi/mechanisms/proof-of-learning/"
      },
      {
        "id": "C-0007",
        "title": "A training run stayed within declared limits",
        "url": "https://trustbutveri.fyi/claims/training-within-declared-limits/"
      },
      {
        "id": "K-0024",
        "title": "Cryptographic commitment",
        "url": "https://trustbutveri.fyi/concepts/cryptographic-commitment/"
      },
      {
        "id": "K-0010",
        "title": "Zero-knowledge proof",
        "url": "https://trustbutveri.fyi/concepts/zero-knowledge-proof/"
      },
      {
        "id": "O-0122",
        "title": "University of Waterloo",
        "url": "https://trustbutveri.fyi/organizations/university-of-waterloo/"
      }
    ]
  }
}