Papers

Every paper

All 87 entries in papers.yml, across every cell. PDF means we hold the primary source; Note means someone has actually read it and written down what to distrust.

87 shown
PaperSectionYearVenueHeadlinePDFNote
DeepProve Proving inference2026IACR ePrint 2026/1112174 tok/min✓✓
Jolt Atlas Proving inference2026arXiv:2602.174524.3 tok/min✓✓
NANOZK Proving inference2026arXiv:2603.1804643 s to prove
Range-Arithmetic Proving inference2026arXiv:2505.17623v2—✓✓
zkGPT Proving inference2025USENIX Security 20252.75 tok/min✓✓
zkPyTorch Proving inference2025IACR ePrint 2025/5352.2 s to prove✓✓
Bionetta Proving inference2025arXiv:2510.06784v2 (technical report, not peer-reviewed)3.05 s to prove✓✓
ZKTorch Proving inference2025arXiv:2507.070311397.52 s to prove✓✓
ZIP Proving inference2025ACM CCS 2025—✓✓
zkLLM Proving inference2024ACM CCS 2024900 s to prove✓✓
ZKML Proving inference2024EuroSys 20240.016 tok/min✓✓
SpaGKR Proving inference2024IACR ePrint 2024—
Artemis / Apollo Proving inference2024arXiv:2409.1205512000–14400 s to prove
Lu et al. Proving inference2024—287.1 s to prove
Hao et al. Proving inference2024USENIX Security 20242.107 s to prove✓✓
Remainder Proving inference2024Modulus Labs technical report (not peer-reviewed)54 s to prove✓✓
ezkl Proving inference2023Open-source project (no canonical paper)1310 s to prove
Zator Proving inference2023Open-source project, Hack Lodge (no paper)26966.8 s to prove✓
zkCNN Proving inference2021ACM CCS 202188.3 s to prove
Mystique Proving inference2021USENIX Security 2021262 s to prove✓✓
ZEN Proving inference2021—147–4710 s to prove✓✓
vCNN Proving inference2020IEEE TDSC28800 s to prove
SafetyNets Proving inference2017NeurIPS 2017—✓✓
pvCNN Proving testing2023—1448.83 s to prove
zkDT Proving testing2020ACM CCS 2020250 s to prove
ZKBoost Proving training2026IACR ePrint 2026/202—
Optimum Vicinity Proving training2025ACM CCS 2025—
VeriLoRA / zkLoRA Proving training2025NDSS 2026600 s to prove
SUMMER Proving training2025IACR ePrint 2025/1688—
ZKPROV Proving training2025arXiv:2506.20915—
Kaizen Proving training2024ACM CCS 2024900 s to prove
PoL is More Broken Than You Think Proving training2023IEEE EuroS&P 2023—✓✓
zkDL Proving training2023IEEE TIFS 20240.86 s to prove
zkPoT (Garg et al.) Proving training2023ACM CCS 20234208 s to prove✓✓
PoL Adversarial Examples Proving training2022IEEE S&P 2022—✓✓
zkMLaaS Proving training2022IEEE GLOBECOM 20222.2 s to prove
Proof-of-Learning Proving training2021IEEE S&P 2021—✓✓
VeriML Proving training2021IEEE TPDS12 s to prove
PRoVeFL Federated & aggregation2026arXiv:2607.06612—
ByzSFL Federated & aggregation2025arXiv:2501.06953—
Trusted Model Aggregation (ZKFL) Federated & aggregation2024IEEE TPDS 2024—
RoFL Federated & aggregation2023IEEE S&P 2023—
ACORN Federated & aggregation2023USENIX Security 2023—✓✓
zkFL Federated & aggregation2023arXiv:2310.02554—
RiseFL Federated & aggregation2023——
EIFFeL Federated & aggregation2022ACM CCS 2022—✓✓
Prio / Prio+ Federated & aggregation2017NSDI 2017 (Prio); SCN 2022 (Prio+)—
Probabilistic truncation in PPML Numerics2025AAAI 2025—✓✓
ZKLP Numerics2024arXiv 2404.14983—✓✓
Garg et al. (FP) Numerics2022ACM CCS 2022—✓✓
SecFloat Numerics2022IEEE S&P 2022—✓✓
Archer et al. (IEEE cost) Numerics2021LATINCRYPT 2021—✓✓
SIRNN Numerics2021IEEE S&P 202149.6 s to prove✓✓
Bootstrapping is All You Need Private inference2026IACR ePrint 2026/1255349.5 s to infer✓✓
Sigma Private inference2024PoPETs 2024(4), pp. 61-7937.59 s to prove✓✓
BOLT Private inference2024IEEE S&P 2024—✓✓
Nimbus Private inference2024NeurIPS 2024—✓✓
CipherGPT Private inference2023IACR ePrint 2023/11471180.9 s to infer✓✓
Cheetah Private inference2022USENIX Security 202280.3 s to prove✓✓
Iron Private inference2022NeurIPS 2022—✓✓
Delphi Private inference2020USENIX Security 20203.8 s to prove✓✓
Mosformer Private inference2025ACM CCS 202559.47 s to prove✓✓
PUMA Private inference2023arXiv:2307.12533v3 (preprint, Sep 2023); later published in Security and Safety, 2025200.473 s to prove✓✓
PriFT Private training2026IACR ePrint 2026/1381—
Private LoRA Fine-tuning with HE Private training2025——
CryptPEFT Private training2025——
PrivTuner Private training2024——
Encryption-Friendly LLM Architecture Private training2024——
FairZK Proving properties2025IEEE S&P 2025343 s to prove
Show Me You Comply Proving properties2025——
Cryptographic Verifiability of E2E AI Pipelines Proving properties2025——
FairProof Proving properties2024ICML 2024—
OATH Proving properties2024——
zkAudit Proving properties2024ICML 2024—
zk-OPML Alternatives to ZK2026Journal of King Saud University CIS—
Optimistic TEE-Rollups (OTR) Alternatives to ZK2025——
TEE confidential LLM inference Alternatives to ZK2025arXiv:2509.18886 [cs.PF]—✓✓
opML Alternatives to ZK2024arXiv:2401.17555—
opp/ai Alternatives to ZK2024——
Proof of Sampling Alternatives to ZK2024——
Proof of Quality Alternatives to ZK2024——✓
NVIDIA Confidential Computing (Hopper H100) Alternatives to ZK2023NVIDIA whitepaper WP-11459-001 v1.0 (vendor document, not peer-reviewed)—✓✓
Lightweight Sampling Proofs of Inference Alternatives to ZK2026IACR ePrint 2026/541—✓
ZKP-VML Survey Surveys & reports2025arXiv:2502.18535 / Artificial Intelligence Review—✓✓
The Definitive Guide to ZKML (2025) Surveys & reports2025ICME Labs blog—
Decentralized ZKML Survey Surveys & reports2023——
The Cost of Intelligence Surveys & reports2023Modulus Labs whitepaper v1.2 (eprint 2026/1063)—✓✓
primary — read in the paper survey — secondhand vendor claim, or provenance unrecorded