用零知识证明让机器学习结果可验证且隐私安全
A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning
- 用零知识证明验证模型训练、测试和推理过程
- 解决计算完整性与数据隐私的双重难题
- 适合关注可信AI与隐私保护的研究者
机器学习越来越多地通过外包和云平台部署,虽提升了可访问性,却也引发了计算完整性、数据隐私和模型保密性的担忧。零知识证明(ZKPs)为可验证机器学习提供了有力基础,使一方能在不泄露敏感数据或专有模型参数的前提下,证明某次训练、测试或推理结果确实由指定计算生成。尽管零知识机器学习(ZKML)进展迅速,相关文献仍分散在不同密码学设定、机器学习任务和系统目标中。本综述系统回顾了2017年6月至2025年8月间发表的ZKML研究,首先介绍支撑ZKML的基础零知识证明形式,将现有工作归纳为三类核心任务:可验证训练、可验证测试和可验证推理。随后综合代表性系统,比较其设计选择,分析主要实现瓶颈,包括电路表达能力有限、证明开销高、部署复杂等。此外,总结提升通用性与效率的关键技术,回顾新兴商业实践,并探讨未来发展方向。通过整合ZKML的设计空间,本综述旨在为可信且隐私保护的机器学习研究者与从业者提供结构化参考。
原文摘要 · Abstract (English)
Machine learning is increasingly deployed through outsourced and cloud-based pipelines, which improve accessibility but also raise concerns about computational integrity, data privacy, and model confidentiality. Zero-knowledge proofs (ZKPs) provide a compelling foundation for verifiable machine learning because they allow one party to certify that a training, testing, or inference result was produced by the claimed computation without revealing sensitive data or proprietary model parameters. Despite rapid progress in zero-knowledge machine learning (ZKML), the literature remains fragmented across different cryptographic settings, ML tasks, and system objectives. This survey presents a comprehensive review of ZKML research published from June 2017 to August 2025. We first introduce the basic ZKP formulations underlying ZKML and organize existing studies into three core tasks: verifiable training, verifiable testing, and verifiable inference. We then synthesize representative systems, compare their design choices, and analyze the main implementation bottlenecks, including limited circuit expressiveness, high proving cost, and deployment complexity. In addition, we summarize major techniques for improving generality and efficiency, review emerging commercial efforts, and discuss promising future directions. By consolidating the design space of ZKML, this survey aims to provide a structured reference for researchers and practitioners working on trustworthy and privacy-preserving machine learning.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。