RzkFL: a Verifiable, Fast and Privacy-Preserving Framework for Federated Learning Inference Using Recursive Zero-Knowledge Proofs and on-Chain Verification
Bibliographic record
Abstract
RzkFL is an end-to-end, privacy-preserving machine-learning framework that fuses Federated Learning (FL) with recursive zero-knowledge proofs (ZKPs) to protect data, models, and users while unlocking verifiable inference. Models are trained entirely on local devices, so sensitive data never leave the premises. The resulting model can be monetized by offering verifiable predictions on a pay-per-use basis. During inference, each customer independently computes predictions using private data, making it essential to verify that these inference results are computed correctly and honestly. Unlike existing approaches that rely on heavy communication or centralized trust assumptions, RzkFL allows each customer to generate a cryptographic proof of correct local inference, which can be succinctly verified without revealing input data or model parameters either by the customer or a third party. The core innovation lies in the use of recursive ZKPs, enabling each customer to generate small, composable proofs for intermediate layers of neural network inference. These proofs are then recursively aggregated into a single succinct proof using the Nova proof folding scheme. Nova’s design eliminates the traditional sequential dependency of recursive proofs by enabling incrementally verifiable computation through a folding scheme. RzkFL supports on-chain verification via Ethereum smart contracts, allowing AI results to flow directly into financial workflows. A decentralized file storage system maintains the integrity and availability of the global model. We introduce specialized circuits for input, hidden, and output layers to optimize proof generation time and gas costs. The customer can generate proof for the entire inference computation or delegate the proof generation for the intermediate layers and the output layer to another party. The design suits privacy-preserving machine learning scenarios where customer devices are resource-constrained. Our results show that RzkFL can significantly reduce proof size and verification costs while maintaining privacy, integrity, and scalability in federated inference. This makes it a compelling approach for real-world decentralized AI systems requiring strong verifiability guarantees.
Fetched live from OpenAlex and de-inverted. Abstracts are not stored in this database: the inverted indexes are 8.6 GB of the frame’s 9.3 GB of text, and the host has 13 GB free.
How this classification was reachedexpand
Full frame distilled prediction
Teacher imitationNot calibrated prevalence, not ground truth. Human validation pending. Learned from the 10,348 direct Codex labels and 10,348 direct Gemma labels. Candidate is the union of thresholded teacher heads; consensus is their intersection. These outputs are machine_predicted_unvalidated and are not human labels or direct frontier model labels.
Codex and Gemma teacher scores by category
| Category | Codex | Gemma |
|---|---|---|
| Metaresearch | 0.001 | 0.003 |
| Meta-epidemiology (narrow) | 0.001 | 0.001 |
| Meta-epidemiology (broad) | 0.001 | 0.000 |
| Bibliometrics | 0.000 | 0.002 |
| Science and technology studies | 0.002 | 0.000 |
| Scholarly communication | 0.002 | 0.001 |
| Open science | 0.001 | 0.002 |
| Research integrity | 0.000 | 0.001 |
| Insufficient payload (model declined to judge) | 0.000 | 0.000 |
Machine scores (provisional)
The two teacher heads of the student model, read on this work. A score orders the frame for review; it never asserts a category, and the validation status ships verbatim with every row.
Baseline scores from an immature model (maturity gate not passed, 7 training rounds). Scores rank; they never assert a category.
score_only:v0-immature-baseline · verbatim from the scoring run: score_only means the number may rank works, and no category label ships from itClassification
machine, unvalidatedMachine predicted; a candidate call from one teacher head, not a consensus.
How this classification was reached, model by model and score by score, is at the end of the page under "How this classification was reached".