arXiv AI

Zero knowledge verification for frontier AI training is possible

arXiv:2606. 05433v1 Announce Type: new Abstract: Frontier AI governance frameworks increasingly use cumulative training compute as the primary criterion for designating high-impact models, but enforcement rests on self-reporting because no technical verification primitive for training exists.

arXiv Machine Learning
Sep 16

OPEN-1B: A Fully Auditable Training Run

The paper introduces Open-1B, a language model trained under a new fully auditable regime that ensures every training operation is reproducible on heterogeneous commodity hardware with bitwise certainty. By enforcing a fixed order on sources of nondeterminism—GPU reductions, data batch ordering, and inter/intra-node communication—the authors enable auditors to replay and verify individual training steps on a single machine. The release includes the full pretraining dataset, all intermediate checkpoints, the training codebase, and an audit harness for step-by-step verification.

By John Donaghy, Brian Wilcox, O\u{g}uzhan Ersoy, Shikhar Rastogi, Adam St Arnaud, Alexey Titov, Jordan Greenberg, Ben Fielding, Harry Grieve
arXiv AI
Sep 11

Beyond Training: A Feasibility Taxonomy for Inference-Time AI Governance

The paper "Beyond Training: A Feasibility Taxonomy for Inference-Time AI Governance" presents a taxonomy of twenty inference‑time mechanisms for monitoring, verification, and enforcement, each evaluated on a four‑point readiness scale using evidence from four vendors. It applies this taxonomy to a two‑dimensional adversary model and maps the mechanisms to four governance scenarios, finding that most mechanisms are commercially available but only adequate against cooperative or low‑to‑medium‑capability users, not high‑capability state‑level deployers. The study also links inference‑stage controls to hardware‑stage mechanisms through a substitution principle and reports a second‑rater reliability of 0.74. whyItMatters":"The work identifies the current gaps and readiness of inference‑time governance tools, highlighting that existing mechanisms are insufficient against powerful adversaries and thus informing future regulatory and technical development."

By Samar Ansari
arXiv Machine Learning
Sep 11

Numbat: Building and Verifying a Self-Contained Machine-Learning Stack

The paper introduces Numbat, a self‑contained machine‑learning stack implemented entirely in Zig with no external runtime dependencies. It covers tensor computation, automatic differentiation, neural‑network modules, mixed precision, multi‑GPU training, data loading, and monitoring, and exposes a stable C ABI with over 1,400 entry points and bindings for six languages. The authors verify the stack against a reference implementation at multiple levels, uncovering ten silent recipe divergences, and demonstrate its practical capability by training a 25.9M‑parameter YOLOv8m detector on COCO 2017, achieving a competitive mAP score and matching single‑GPU performance.

By Thang Tran (CloudKites AI Lab, New South Wales, Australia), Lan Dang (Monash Business School, Monash University, Victoria, Australia)
arXiv Machine Learning
4d ago

OVIG: Optimistic Verification of AI Training Integrity via Gradient Signals

OVIG is an optimistic verification framework that audits AI training by replaying the process and comparing gradient differences against an empirically calibrated boundary. It treats any gradient difference exceeding this boundary as a malicious deviation. By partitioning training into stride‑s intervals and storing evidence only at interval endpoints, OVIG dramatically reduces off‑chain storage and transmission costs while maintaining zero attack success rate across language, vision, and diffusion workloads.

By Hongxu Su, Jianzhu Yao, Huan Zhang, Xuechao Wang, Pramod Viswanath
arXiv Machine Learning
Aug 19

Certified but Private: Scalable Zero-Knowledge Proofs for Neural Network Guarantees

PANDA is a scalable system that uses zero‑knowledge proofs to certify the robustness and fairness of neural networks without revealing their private parameters. Built on the CROWN robustness framework, PANDA introduces a novel algorithm for proving linear relaxation bounds on non‑linear activation layers, producing lightweight proofs. The system can generate proofs for networks with over 2.9 million parameters in just five minutes and verify them in ten seconds, scaling polynomially with network size and enabling verification of models four orders of magnitude larger than prior ZKP‑based approaches.

By Youwei Zhong, Ben Merbaum, Timos Antonopoulos, Ning Luo, Charalampos Papamanthou, Katerina Sotiraki, Ruzica Piskac
arXiv AI
2d ago

Can AI Oversight Be Zero Knowledge?

The paper investigates whether interactive arguments for oracle‑aided AI computations can be zero‑knowledge, meaning the verifier learns nothing beyond the correctness of the output. It proves that, in general, zero‑knowledge proofs for all oracle‑aided computations are impossible, even in the random oracle model, and this impossibility extends to debate protocols. However, if the oracle signs each answer with a cryptographic signature, then every oracle‑aided computation can be verified in zero‑knowledge with efficient provers and verifiers, assuming only collision‑resistant hash functions.

By Alessandro Chiesa, Ziyi Guan, Burcu Yildiz
arXiv AI
6d ago

Werracle: Sub-Cent Intra-Block AI Reflex Oracles and Flash-Loan Circuit Breakers for EVM Smart Contracts

Werracle is a zero‑storage on‑chain AI decision oracle that fits into a single 32‑byte EVM storage slot and uses procedural Mandelbrot dynamics to generate continuous non‑linear decision hyperplanes from a 24‑byte coordinate triplet. Implemented in pure Solidity bytecode with fixed‑point arithmetic, it evaluates a 16‑point Pareto micro‑grid in only 21,438 gas, achieving sub‑millisecond latency on Layer‑2 rollups. The protocol is formally verified with a 1,000‑test deterministic suite and is deployed live on an EVM devnet, demonstrated through a Uniswap v4 dynamic fee governor that adjusts liquidity provider fees in real time.

By Volkan Da\u{g}l{\i}, Zerrin Da\u{g}l{\i}, Da\u{g}han Da\u{g}l{\i}