zkAudit

Trustless Audits without Revealing Data or Models

Suppakit Waiwitlikhit, Ion Stoica, Yi Sun, Tatsunori Hashimoto, Daniel Kang

Venue
ICML 2024
Date
2024-04-06
Numbers from
primary
Paper
https://arxiv.org/abs/2404.04500

Reported benchmarks

modelsnote
recommender systems, ImageNet-scale image classifiersSpecific per-model timings not extracted.

Notes

Two phases. ZKAudit-T proves the model was trained by SGD on a committed dataset -- that is a zkPoT, and cross-lists into the training: section. ZKAudit-I then audits arbitrary properties over the hidden data and weights. Supports copyright, censorship-detection and counterfactual audits with little to no accuracy loss. Weights stay secret but the ARCHITECTURE is public -- relevant to the Fiat-Shamir open question above, since pinning the architecture is exactly the mitigation.

Our reading

Citation neighbourhood

Builds on
  • none recorded
Cited by, in this corpus
  • none recorded

Edges are a proxy: paper A's text mentions B anywhere (body or bibliography). See the full graph.

Discussed in

Other recorded fields
property_proven: Arbitrary user-defined properties of hidden weights and hidden training
  data
objectives:
- training
- properties