Papers · Proving properties · zkAudit
zkAudit
Trustless Audits without Revealing Data or Models
Reported benchmarks
| models | note |
|---|---|
| recommender systems, ImageNet-scale image classifiers | Specific per-model timings not extracted. |
Notes
Two phases. ZKAudit-T proves the model was trained by SGD on a committed dataset -- that is a zkPoT, and cross-lists into the training: section. ZKAudit-I then audits arbitrary properties over the hidden data and weights. Supports copyright, censorship-detection and counterfactual audits with little to no accuracy loss. Weights stay secret but the ARCHITECTURE is public -- relevant to the Fiat-Shamir open question above, since pinning the architecture is exactly the mitigation.
Our reading
Citation neighbourhood
Builds on
- none recorded
Cited by, in this corpus
- none recorded
Edges are a proxy: paper A's text mentions B anywhere (body or bibliography). See the full graph.
Discussed in
Threat models -- who learns whatA claim about a model, not about a computationThe prior surveys, and where we disagree with themEvery relaxation, and what an adversary can still doThe systems, grouped by what they gave up
Other recorded fields
property_proven: Arbitrary user-defined properties of hidden weights and hidden training data objectives: - training - properties