SoK: The Role of Zero-Knowledge Proofs in Building Confidential and Trustworthy AI
Bibliographic record
Abstract
The verifiability of machine learning models and the privacy of training data have become critical concerns due to their widespread deployment in sensitive applications. Ensuring that a model performs as claimed, without revealing private data or algorithms, is a significant challenge. Zero-Knowledge Proof systems (ZKPs) have emerged as a promising cryptographic solution, enabling the verification of statements without disclosing underlying information. Their integration with blockchain technology further enhances trust and decentralization, offering robust solutions for secure and transparent AI systems. This paper explores the use of ZKPs in machine learning, focusing on privacy-preservation techniques, model verifiability, and confidential AI. It compares the differences and challenges of employing ZKPs in machine learning versus blockchains, highlighting their unique requirements and overlapping benefits. We review the basic concepts of ZKPs, advances such as zkSNARKs and zk-STARKs, and their applications in blockchainbased AI frameworks to ensure data integrity, immutability, and scalability. Furthermore, the paper delves into the practical implications of using ZKPs in AI, providing case studies and analyzing their scalability, performance, and limitations. We conclude by identifying key challenges and presenting future research directions to extend the applicability of ZKPs in AI, particularly in federated learning, model fairness, and decentralized AI pipelines.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame machine prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. The Gemma side is a direct model label for every work in the frame, read from the title-only record. The Codex side is a classifier learned from the 10,348 direct Codex labels and calibrated to design-weighted sample rates; fields without enough sample support carry no Codex call. Candidate is the union of the two sides; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels.
Distilled classifier scores by category (both heads)
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.019 | 0.065 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.001 | 0.002 |
| Bibliometrics | 0.002 | 0.002 |
| Science and technology studies | 0.003 | 0.012 |
| Scholarly communication | 0.009 | 0.028 |
| Open science | 0.003 | 0.010 |
| Research integrity | 0.003 | 0.007 |
| Insufficient payload (model declined to judge) | 0.007 | 0.002 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one source (direct Gemma or distilled Codex), not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".