Verifiable evaluations of machine learning models using zkSNARKs

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: South, Tobin, Camuto, Alexander, Jain, Shrey, Nguyen, Shayla, Mahari, Robert, Paquin, Christian, Morton, Jason, Pentland, Alex 'Sandy'
Natura: Preprint
Pubblicazione: 2024
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866914806226747392
author South, Tobin
Camuto, Alexander
Jain, Shrey
Nguyen, Shayla
Mahari, Robert
Paquin, Christian
Morton, Jason
Pentland, Alex 'Sandy'
author_facet South, Tobin
Camuto, Alexander
Jain, Shrey
Nguyen, Shayla
Mahari, Robert
Paquin, Christian
Morton, Jason
Pentland, Alex 'Sandy'
contents In a world of increasing closed-source commercial machine learning models, model evaluations from developers must be taken at face value. These benchmark results-whether over task accuracy, bias evaluations, or safety checks-are traditionally impossible to verify by a model end-user without the costly or impossible process of re-performing the benchmark on black-box model outputs. This work presents a method of verifiable model evaluation using model inference through zkSNARKs. The resulting zero-knowledge computational proofs of model outputs over datasets can be packaged into verifiable evaluation attestations showing that models with fixed private weights achieve stated performance or fairness metrics over public inputs. We present a flexible proving system that enables verifiable attestations to be performed on any standard neural network model with varying compute requirements. For the first time, we demonstrate this across a sample of real-world models and highlight key challenges and design solutions. This presents a new transparency paradigm in the verifiable evaluation of private models.
format Preprint
id arxiv_https___arxiv_org_abs_2402_02675
institution arXiv
publishDate 2024
record_format arxiv
spellingShingle Verifiable evaluations of machine learning models using zkSNARKs
South, Tobin
Camuto, Alexander
Jain, Shrey
Nguyen, Shayla
Mahari, Robert
Paquin, Christian
Morton, Jason
Pentland, Alex 'Sandy'
Machine Learning
Artificial Intelligence
Cryptography and Security
68T01
In a world of increasing closed-source commercial machine learning models, model evaluations from developers must be taken at face value. These benchmark results-whether over task accuracy, bias evaluations, or safety checks-are traditionally impossible to verify by a model end-user without the costly or impossible process of re-performing the benchmark on black-box model outputs. This work presents a method of verifiable model evaluation using model inference through zkSNARKs. The resulting zero-knowledge computational proofs of model outputs over datasets can be packaged into verifiable evaluation attestations showing that models with fixed private weights achieve stated performance or fairness metrics over public inputs. We present a flexible proving system that enables verifiable attestations to be performed on any standard neural network model with varying compute requirements. For the first time, we demonstrate this across a sample of real-world models and highlight key challenges and design solutions. This presents a new transparency paradigm in the verifiable evaluation of private models.
title Verifiable evaluations of machine learning models using zkSNARKs
topic Machine Learning
Artificial Intelligence
Cryptography and Security
68T01
url https://arxiv.org/abs/2402.02675