Jolt-FL: A General-Purpose Verifiable Federated Learning Framework Powered by zkVM
Abstract
Federated Learning (FL) enables multiple participants to collaboratively train a shared model without sharing their private data. However, FL remains vulnerable to malicious clients submitting incorrect updates to disrupt training. To address this, we formalize each client’s local training step as a Nondeterministic Polynomial-time (NP) statement, verifiable via zero-knowledge proofs (ZKPs) at every round. We propose Jolt-FL, the first general-purpose verifiable FL framework that immediately detects and excludes malicious clients upon their first dishonest action – without relying on heuristics, statistical assumptions, or multi-round analysis. Built on Jolt’s zkVM, a state-of-the-art zero-knowledge virtual machine (zkVM) developed by a16zcrypto, Jolt-FL guarantees training integrity and data privacy without trusted hardware or third-party intermediaries. By witnessing every computation step, it defends against a wide range of attack vectors, securely filtering dishonest updates even if up to 50% of clients are malicious, while preserving convergence and final model performance. To demonstrate feasibility, we implement a prototype featuring a complete end-to-end Convolutional Neural Network (CNN) for image classification using the MNIST dataset. To our knowledge, this is the first fully verifiable end-to-end CNN training under ZKPs without any custom circuit design. Our solution achieves competitive proof generation times, compact proof sizes, and low verification costs–all while preserving model accuracy on par with standard FL.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.