Ahmed Anwer Jaafa, Madhu Sahu, M. Jasmin, Mamadjanova Zukhra Bakhromjanovna ¡ 8 authors
Sharing patient data safely and efficiently is still hard in the constantly changing world of digital healthcare because of worries about privacy, giving consent, and how different systems work together. This paper suggests using ChainMedX, which relies on blockchain technology to let patients, doctors, and other healthcare professionals exchange data in real time with dynamic consent consent management. ChainMedX uses permissions, smart contracts, and zero-knowledge proofs to let patients pick who can have access to their medical records, manage exactly what is shared, and specify the time period the sharing is needed, making sure those permissions cannot be altered. Being distributed across both cloud and edge servers, the patient-managed encrypted data vaults make active updates of medical records possible, complying with FHIR standards. Thanks to an AI-based consent suggestion module, patients receive useful advice that suits their needs and the current emergency situation. In addition, ChainMedX deals with urgent issues, such as fast access with easy âbreak-glassâ rules and complete tracking of every transaction, and makes it easier for healthcare services to interact with the wider health organization and verify insurance policies. According to the results, latency, security, and managing consent are all better in the new system than in systems that operate centrally or rely on blockchain. The research mentions that connecting blockchain, edge computing, and privacy-based cryptography can form a healthcare system that respects patient data privacy and makes healthcare cooperation speedy and secure. The goal of this framework is to help provide for data exchange between countries, while including new forms of digital health technology, all this aims to strengthen patient trust and the integrity of their medical data, along with providing better healthcare outcomes.
Provable security is a cornerstone of modern cryptography: Due to ubiquitous and diverse applications of cryptography, a proof of security gives us the necessary confidence to deploy a cryptographic protocol. In most cases, such a security proof comes in the form of a black-box reduction, which bases the security of a potentially complex protocol on a small set of simple and abstract assumptions that are much easier to analyse. However, proving a black-box reduction can be quite complicated, and we do not have proofs for every protocol used in practice. Here, analysing the protocols relative to oracles, a technique from computational complexity theory, can provide insights: Oracles provide the ability to compute functionalities in one computational step that otherwise might not be efficiently computable, e.g., provide access to a truly random function or solve any NP-complete problem. These oracles now allow us to replace some parts in the protocol with abstract, idealized primitives that are easier to analyse, e.g., to replace a one-way function with a truly random function. In this thesis, we utilize oracles in two different ways. In the first part, we use oracles to prove lower bounds for cryptographic primitives, i.e., showing that certain assumptions are not sufficient to build this primitive securely. The essential idea here, going back to Impagliazzo and Rudich, is to replace the assumption with an oracle, i.e., replacing a one-way function with a truly random function, and then showing that relative to this oracle, it is impossible to build the primitive. From this impossibility result relative to the oracle, we can now conclude that the primitive cannot be built from the assumption in a black-box way. We use this technique to prove a lower bound on the efficiency of constructing strong from weak one-way functions, to show that we cannot construct collision-resistant hash functions from distributional collision-resistant hash functions in a fully black-box way, and to prove that extremely lossy functions cannot be built from a large class of symmetric primitives in a black-box way. In the second part of this thesis, we use oracles as idealized models that can be used to provide heuristic security arguments for protocols.These idealized models, starting with the random oracle model (short ROM) introduced and defined by Fiat and Shamir as well as Bellare and Rogaway, were motivated by the existence of very efficient cryptographic protocols used in practice, but for which no proof of security existed. Using idealized models, it was now possible to give at least a heuristic security argument for them. In this thesis, we first focus on the common random string model, an idealized model introduced to circumvent impossibility results for non-interactive zero-knowledge proofs. We show how to reuse a single common random string for polynomially many non-interactive statistical zero-knowledge arguments, as well as analyze the relation between different soundness definitions used in literature. In a second result, we introduce an alternative notion for the ROM, the universal random oracle model, which brings this idealized model closer to reality.
M Dhinesh, A. Karthik, Abdur Rahim M, S. AARYA ¡ 6 authors
The rapid expansion of India's e-commerce ecosystem has led to a corresponding rise in consumer grievances, data privacy violations, and non-compliance with statutory norms. Although the Consumer Protection Act, 2019 and the Consumer Protection (E-Commerce) Rules, 2020 mandate transparent disclosures, grievance redressal mechanisms, and seller accountability, enforcement remains inconsistent due to the centralized nature of compliance systems. This paper outlines a proposal of a Blockchain-Driven Compliance Model (BDCM) based on permissioned blockchain infrastructure, smart contracts, and zero-knowledge proofs to guarantee automated, auditable, and enforceable legal compliance. The architecture has the main legal points in smart contracts, including Rule$4(4)$on product disclosure, Rule 5(3) on record retention, and Rule 6(3) on seller liability, and a compliance scoring/alerts system to dynamically monitor the trust is provided. The outputs of simulations on Hyperledger Fabric show that the compliance will be substantially enforced. Most legal clauses had a success rate of$\geqslant 97.5$and grievance redressal time was also lowered by 75 and consumer satisfaction increased to 94.7. The over-95% privacy index trust index guaranteed privacy of the model through the use of the zero-knowledge consent verification algorithm to guarantee privacy of the model among the users who had tested the model. Moreover, the compliance scores successfully ranked sellers according to their legal conduct allowing a proactive suspension and warning of the potential high risk entities. To sum up, the BDCM framework provides a legal-tech interface between legal requirements and technical implementation, which can be transparent, auditable, and trusted.
Mohhammed H. Al-Farouni, Jyotsna Dwivedi, T. Saravanan, Ismatullaeva Yodgora Abduvahobkizi ¡ 8 authors
Online elections (e-voting) are fast and convenient. Still, there is growing concern that the democratic integrity of the election process is under threat due to problems such as cyberattacks, illegal intrusion, vote manipulation, and unclear verification of the results. Actual cases have demonstrated voter fraud, insecure data storage, and unreliable results, undermining the public's confidence in digital voting systems, particularly in primary national elections. Moreover, the traditional auditing system, which relies on paper ballots, manual logistics, and resource-intensive verification, results insignificant operational costs and a negative environmental impact. This paper proposes a solution to these capital challenges by introducing SECURE-VOTE_CHAIN, an open, secure e-voting platform that integrates a certified blockchain network, biometric verification checks, homomorphic encryption, and zero-knowledge public audit records. The blockchain nodes in this system, run by voting bodies and legitimate observers, consistently registered votes and facilitated decentralised consultation. Biometric authentication can exclude identity duplication and voter fraud, and only homomorphic encryption can ensure fair counting without knowing any votes provided by an individual. Zero-knowledge proofs also make public auditability achievable without reducing the anonymity of voters. The application of realistic election parameters in simulations yields an accuracy of 91.88, along with low confirmation latency and high attack resilience probabilities in the presence of insider attacks, replay attacks, and denial-of-service attempts. In addition to security and reliability, the system will eliminate paperwork and manual auditing, significantly reducing the carbon footprint of traditional elections. Altogether, SECURE-VOTE_CHAIN offers an environmentally friendly, secure, and scalable solution that is suitable for regaining voter confidence, ensuring electoral integrity, and creating a future-proof digital governance model. The model can be considered a reasonably helpful standard by which contemporary voting systems operate, as it combines technological benefits with the adequacy of achievements in terms of prospects, providing policymakers with dependable means of security and transparency in election procedures, applicable to both urban and rural settings.
Revocable ring signatures protect signer anonymity. A trusted authority can revoke signing rights when necessary. This makes them attractive for blockchains and vehicular networks. Existing lattice-based ring signature schemes are only traceable. They can de-anonymize a malicious signer, yet fail to stop the revoked signer from creating a valid signature. This contradicts the very notion of revocation. We introduce a polynomial-based revocation list. It is enforced with non-interactive zero-knowledge proofs of knowledge. Our protocol implicitly verifies the up-to-date revocation list during signature generation. Consequently, revoked signers cannot authenticate and are effectively excluded. Integrating this mechanism into a lattice setting, we obtain a compact revocable ring signature. The scheme is correct, anonymous, unforgeable, and truly revocable under the random oracle model. No costly key updates are required. Compared with prior trace-and-update schemes, our construction offers a practical post-quantum primitive. It guarantees both privacy and accountable revocation. Overhead analysis shows that we have added very little cost while ensuring true revocation.
K. Swathi, Putta Durga, K. Venkata Prasad, A Krishna Chaitanya ¡ 7 authors
An enormous demand for a secure, scalable, intelligent edge computing framework has emerged for the exponentially increasing number of Internet of Things (IoT) devices for any substrate of modern digital infrastructure. These edge nodes distributed across heterogeneous environments serve as primary interfaces for sensing, computation, and actuations. Their physical deployment in unattended scenarios puts them at risk of being targets for resource manipulation. One widely accepted IoT architecture with traditional notions of edge may consider a threat to its centralized knowledge with an unbounded attack surface that includes anything that can remotely connect to the edge from the cloud-like domain. Existing strategies either forget the dynamic risk context of edge nodes or do not achieve a reasonable trade-off between security and resource constraints, essentially degrading the robustness and trustworthiness of solutions intended for real-life scenarios. To address the existing gaps, the work presents a novel Blockchain Integrated Deep Learning Framework for secure IoT edge computing, introducing a hybrid architecture where the transparency of blockchain meets deep learning flexibility. The proposed system incorporates five specialized components: Blockchain-Orchestrated Federated Curriculum Learning (BOFCL), which ensures risk-prioritized training using threat indices derived from blockchain logs; this adaptive sequencing enhances responsiveness to high-risk edge scenarios. Zero-Knowledge Proof Enabled Secure Inference Engine (ZK-SIE) provides verifiable privacy-preserving inference, ensuring model integrity without exposing input data or model internals in process. Blockchain Indexed Adversarial Attack Simulator (BI-AAS) focuses on testing the models in edge environments against attack scenarios drawn from common adversarial profiles and thereby facilitates a model defensive retraining. Energy-Aware Lightweight Consensus with Adaptive Synchronization (ELCAS) avoids overhead by seeking energy-efficient participants for global model synchronization in constrained environments. Trust Indexed Model Provenance and Deployment Ledger (TIMPDL) ensures model lineage tracking and deploy ability in a transparent manner by providing composite trust scores computed from data quality, node reputation, and validation metrics. Altogether, the framework combines the data integrity, adversarial robustness, and trust-aware deployment, shortening training latency, synchronization energy, and privacy leakage. It is a foundational advancement supporting secure decentralized edge intelligence for next-generation IoT ecosystems.
Srinivas P M, Ruthvik M T, Sanjay UG, Shiva Kumar S ¡ 6 authors
Secure digital identity management is every emerging concern. Traditional authentication which includes use of passwords, central databases, and third party recovery present great security and also usability issues. Zero- Knowledge Proofs (ZKPs) and blockchain have put forth as very good for Decentralized identity systems. But also many present solutions have large compute requirements, donât scale well, and have poor user recovery. This review puts forth that in present ZKP based identity systems we see the lack of password less login, human readable identities, and self sovereign recovery. We look at recent systems which we note have a heavy use of complex crypto credentials, central verification which is a point of failure, and extensive infrastructure which in turn do not see wide scale adoption. To present solutions to these issues we have put forth a UID based identity which uses ZKPs for authentication which does not require storage of passwords or private keys. We introduce a novel recovery which uses a human readable phrase from private key, salt, and UID which in turn is a user controlled method. What we did is we put the UID on the blockchain which in turn improves privacy and scale. Our analysis which we present improves on issues of usability, scale and security which in turn we present a very simple and practical solution for todayâs identity management issues. Also this study we present which we put forth to be the base for what we think will be future works in the development of useable ZKP based identity systems.
In an age where knowledge is power and credentials are the currency of trust, securing academic qualifications while preserving individual privacy has become paramount. Traditional verification methods are costly, slow, and prone to fraud, and centralized digital systems risk exposing sensitive personal data. To address these challenges, we propose a novel framework the Blockchain Academic Credential Interoperability Protocol (BACIP) - that leverages blockchain technology and zero-knowledge proofs (ZKPs). BACIP integrates smart contracts and a dual-blockchain architecture with privacy-preserving ZKP circuits (implemented via Circom/SnarkJS) to automate issuance, storage, and cross-border verification of educational credentials. Our methodology combines on-chain integrity (via Ethereum/Polygon smart contracts) with off-chain confidentiality (using AES encryption and IPFS storage) and self-sovereign identities (DIDs). The distinguishing innovation of BACIP is the seamless integration of ZKPs throughout the credential lifecycle, enabling verifiers to validate specific academic attributes-such as degree completion or GPA-without accessing or exposing any underlying personal data. This approach ensures cryptographic trust while upholding strict privacy standards. Initial results demonstrate a considerably well proof success rate, improved compliance with data protection regulations such as GDPR, and a significant reduction in on-chain computational load. By uniting the transparency of blockchain with the confidentiality of zero-knowledge techniques, BACIP offers a scalable and interoperable framework for secure academic credentialing. Institutions and employers benefit from faster, automated verification workflows, while learners maintain full control over their digital identities and credentials. Ultimately, BACIP paves the way for trustworthy, efficient, and privacy-respecting academic mobility across borders and platforms.
Mohammad Madine, Khaled Salah, Raja Jayaraman, Ibrar Yaqoob
In recent years, the healthcare sector has been increasingly challenged in securing patient identities and medical records on blockchain due to rising privacy demands and strict regulatory requirements. Although advanced techniques like self-sovereign identity and zero-knowledge proofs (ZKPs) show promise, these solutions fail to limit unwarranted patient data disclosure effectively. In this paper, we propose a ZKP-based solution that combines STARKs and anonymous credentials to enable anonymous authentication and enhance privacy across both public and private blockchains. Leveraging transparent ZKP schemes and anonymous credentials, our approach ensures unlinkability by preventing the correlation of multiple patient interactions. We present sequence diagrams of real-world interactions, detailed algorithms for on- and off-chain computations, and implement the system on Ethereum and Starknet blockchains. We present a rigorous evaluation of the proposed solution, encompassing smart contract testing on Starknet networks, transaction cost analysis, performance benchmarking, scalability assessment, and static security auditing. The results demonstrate consistent and economically viable transaction costs, millisecond-level execution times for credential issuance, presentation generation, and verification, linear scalability with increasing claim count and size. We compare our solution with state-of-the-art ZKP-based identity systems to demonstrate its superiority. We further discuss its broader applicability beyond healthcare, including domains such as finance, education, and supply chain management. We make the smart contract codes publicly available on GitHub.
This paper discusses the obstacles to the capitalization of data elements, such as the difficulties in confirming data ownership, trust deficit, privacy breaches, and inefficiency of transactions, through a distributed solution based on blockchain technology. First, a data ownership confirmation mechanism based on a consortium blockchain is established by using the Merkle tree and PBFT (Practical Byzantine Fault Tolerance) consensus algorithm to achieve transparency and traceability of data ownership. Second, a multi-dimensional data value evaluation and RF-BP (Random Forest-Back Propagation) dynamic pricing mechanism are established by using machine learning algorithms to evaluate the value of data assets in a scientific manner. Third, a smart contract is established for pricing and payment, in order to achieve transaction automation and clearing and settlement. Finally, ZKP (Zero-Knowledge Proof) technology is applied to develop a mechanism for verifying compliance and privacy of data under the proposition of public review and "visible, invisible". Experimental results show that the proposed method reduces the average leakage risk and defense success rate under various attacks to 8.57 % and 97.1%, respectively. In terms of transaction efficiency, the proposed method achieves a throughput of 1250 TPS (Transactions Per Second) with a latency of 120 milliseconds at a 50-node scale. Overall performance is demonstrated with a confirmation and transaction success rate of 99.2% and 97.8%, respectively. The suggested framework provides reliable confirmation of data elements, scientific pricing, efficient trading and transaction processes, and privacy protection. It can support the vision of developing a secure, transparent and efficient market for data element circulation with technical feasibility and performance.
Modern cryptographic tools such as multi-party computation (MPC) and zero-knowledge proofs (ZKPs) offer strong, provable security guaranteesâbut these generic protocols remain impractical for production-scale machine learning (ML), especially in the era of large language models (LLMs). This thesis proposal advances the central claim that cryptographic protocols co-designed with the structure of specific ML subtasks can achieve practical efficiency without compromising privacy or verifiability. To validate this vision, this proposal develops three interconnected research thrusts: (1) Confidential Outsourced Training. Customized MPC protocols shift expensive cryptographic steps to local computations, enabling secure training of large models in untrusted clouds by resource-constrained data owners. (2) Scalable MPC Primitives for Large Datasets. Provably secure building blocksâsuch as oblivious shuffles, private joins, and sparse linear algebra routinesâbridge the performance gap in privacy-preserving data pipelines at scale. (3) Verifiable ML without Retraining. Rather than proving each training step, a new proof-of-optimality framework certifies that a trained or fine-tuned model (e.g., LoRA adapters) satisfies desired properties, enabling efficient, auditable deployment without re-executing training. Together, these efforts aim to close the long-standing gap between privacy and efficiency, demonstrating that strong cryptographic guarantees and modern ML workflows can be reconciled through principled, application-aware design.
The increasing use of deep learning (DL) models has given rise to significant privacy concerns regarding training and inference data. To address these concerns, the community has increasingly adopted crypto-based privacy-enhancing technologies (CPET) like homomorphic encryption (HE), secure multi-party computation (MPC), and zero-knowledge proofs (ZKP). The integration of CPET with DL, often referred to as CPET-DL, is commonly facilitated by specialized frameworks like CrypTen, TenSEAL, and EZKL. These frameworks offer configurable parameters to balance model accuracy and computational efficiency during privacy-preserving operations. However, these configurations, while seemingly harmless, can introduce subtle vulnerabilities. The stealthy attacks induced by misconfigurations are hard to detect because 1) the plaintext models remain vulnerability-free, and 2) existing auditing tools are hardly applicable to CPET-hardened models. This creates a paradox: tools intended to protect privacy can be undermined through configuration manipulation.
Open access
Cryptography and Data Security
Physical Unclonable Functions (PUFs) and Hardware Security
Verifiable Random Functions (VRFs) and Oblivious Pseudorandom Functions (OPRFs) are essential cryptographic primitives in privacy-preserving applications such as anonymous authentication, private set intersection (PSI), and decentralized identity. Existing constructions, however, rely on number-theoretic assumptions that are vulnerable to quantum attacks. This PhD research project focuses on constructing efficient and practical VRFs and OPRFs from lattice-based assumptions to ensure post-quantum security. A key obstacle in these constructions is the overhead of zero-knowledge proofs (ZKPs), particularly range proofs, which are costly in terms of size and prover complexity. To address this, we investigate probabilistic techniques that relax exact correctness. In particular, we explore approximate range proofs and algebraic transformations, such as using automorphisms in polynomial rings to simulate inner product arguments via polynomial multiplication. These methods enable more efficient and scalable lattice-based constructions of VRFs, including group and context-bound variants, as well as OPRFs. The goal is to make these primitives practical for deployment in post-quantum privacy-preserving systems.
We introduce the notion of committed vector oblivious linear evaluation (C-VOLE), which allows a party holding a pre-committed vector to generate VOLE correlations with multiple parties on the committed value. It is a unifying tool that can be found useful in zero-knowledge proofs (ZKPs) of committed values, actively secure multi-party computation, private set intersection (PSI), etc.
This preprint introduces Proof-of-Being (PoB) and ontological cryptography â the first cryptographic paradigm explicitly designed for the post-AGI era. As frontier language models, autonomous agents, and embodied robots increasingly generate outputs indistinguishable from human actions, classical authentication mechanisms (public-key cryptography, biometrics, CAPTCHAs, proof-of-personhood systems) no longer answer the central security question of the 2025 digital environment: âWas this action performed by a conscious human being?â Proof-of-Being addresses this foundational problem through HISPU (Human Intention Semantic Proof Unit) â a probabilistically unforgeable, fully anonymous attestation of human presence based on ontological randomness and multi-layered semanticâphysiologicalâcontextual proofs. HISPU verifies being rather than identity, enabling anonymous but provably human actions across digital systems. Key contributions of this work: ¡ Introduction of ontological randomness as a fourth fundamental source of cryptographic unpredictability (beyond mathematical, physical, and hybrid entropy sources). ¡ Formal definition of the HISPU primitive and seven foundational axioms of ontological cryptography. ¡ Demonstration that no computational system â including superintelligent AGI â can forge a valid HISPU under the Ontological Security Assumption. ¡ Clear conceptual separation between proving human being (ontological presence) and proving identity (social personhood). Applications include: ¡ AGI safety and human-in-the-loop supervisory gates ¡ Sybil-resistant DAO voting and decentralized governance ¡ Intention-based economic systems ¡ Bot-resistant democratic systems, legal smart contracts, and high-stakes authentication ¡ Verifiable human authorship in generative AI ecosystems ¡ Neurotechnology consent verification and BCI safety ¡ Web4 / Noospheric Web intention-layer protocols This work positions Proof-of-Being as a foundational infrastructure for safe humanâAI coexistence and represents the first major shift in digital trust since DiffieâHellman (1976) and zero-knowledge proofs (1985). Keywords: proof-of-being, ontological cryptography, HISPU, proof of intention, ontological randomness, human verification, AGI safety, human-in-the-loop verification, post-AGI trust, intention-based economy, sybil resistance, digital ontology, privacy-preserving verification, human-AI coexistence, consciousness proof, non-simulatable proofs, machine unforgeability.
M. Saravana Karthikeyan, R. Rajasree, R. Santhana Krishnan, C. Gayathri ¡ 6 authors
Secure and efficient healthcare data sharing is critical for modern medical ecosystems, yet existing systems often suffer from limited scalability, privacy risks, and lack of intelligent data management. This study proposes MedVault, a hybrid blockchain-cloud-AI framework designed for secure, patient-centric healthcare data management. The architecture employs Corda for on-chain storage of consent records, metadata, and audit logs, while large medical datasets are encrypted and stored off-chain in AWS S3 with PostgreSQL metadata management. Security is reinforced using AES-256 encryption, Proxy Re-Encryption (PRE), Zero-Knowledge Proofs (ZKP), and decentralized identity management via Hyperledger Indy and Aries, while a FHIR-based gateway ensures seamless integration with electronic health records (EHRs). Intelligence is incorporated through deep learning models, including Autoencoders for anomaly detection, CNNLSTM for medical data analytics, Graph Neural Networks (GNNs) for consent prediction, DNNs for risk assessment, and Federated Learning (FL) for privacy-preserving distributed model training. Variational Autoencoders (VAEs) generate synthetic datasets, and Explainable AI techniques (SHAP, LIME) ensure interpretability. Extensive evaluations demonstrate that Corda-MedVault outperforms Hyperledger Fabric, Ethereum, and traditional centralized approaches across metrics such as blockchain latency, throughput, auditability, off-chain storage efficiency, energy consumption, anomaly detection, and consent prediction. Overall, the proposed system provides a scalable, energy-efficient, privacypreserving, and intelligent platform for real-time healthcare data sharing, offering a robust solution for secure and compliant medical data management.
Artificial Intelligence as a Service (AIaaS) enables users to query a model hosted by a service provider and receive inference results from a pre-trained model. Although AIaaS makes artificial intelligence more accessible, particularly for resource-limited users, it also raises verifiability and privacy concerns for the client and server, respectively. While zero-knowledge proof techniques can address these concerns simultaneously, they incur high proving costs due to the non-linear operations involved in AI inference and suffer from precision loss because they rely on fixed-point representations to model real numbers.
James Hsin-yu Chiang, Ivan Damgürd, William R. Duro, Sunniva Engan ¡ 6 authors
We propose efficient, post-quantum threshold ring signatures constructed from one-wayness of AES encryption and the VOLE-in-the-Head zero-knowledge proof system. Our scheme scales efficiently to large rings and extends the linkable ring signatures paradigm. We define and construct key-binding deterministic tags to achieve linkability. We then extend our threshold ring signatures to realize post-quantum anonymous ledger transactions in the spirit of Monero. Finally, our deterministic tags also enable succinct aggregation using approximate lower bound arguments of knowledge; this allows us to achieve succinct (approximate) multi-signatures without SNARKs. Our constructions assume symmetric key primitives only.
Ashwin Karthikeyan, Hengyu Liu, Kuldeep S. Meel, Ning Luo
Efficient zero-knowledge proofs (ZKPs) have been restricted to NP statements so far, whereas they exist for all statements in PSPACE. This work presents the first practical zero-knowledge (ZK) protocols for PSPACE-complete statements by enabling ZK proofs of QBF (Quantified Boolean Formula) evaluation. The core idea is to validate quantified resolution proofs (Q-Res) in ZK. We develop an efficient polynomial encoding of Q-Res proofs, enabling proof validation through low-overhead arithmetic checks. We also design a ZK protocol to prove knowledge of a winning strategy related to the QBF, which is often equally important in practice. We implement our protocols and evaluate them on QBFEVAL. The results show that our protocols can verify 72% of QBF evaluations via Q-Res proof and 82% of instances' winning strategies within 100 seconds, for instances where such proofs or strategies can be obtained.
Zero-knowledge proofs of training (zkPoT) allow a party to prove that a model is trained correctly on a committed dataset without revealing any additional information about the model or the dataset. Existing zkPoT protocols prove the entire training process in zero knowledge; i.e., they prove that the final model was obtained in an iterative fashion starting from the training data and a random seed (and potentially other parameters) and applying the correct algorithm at each iteration. This approach inherently requires the prover to perform work linear to the number of iterations.
In many fields, the need to securely collect and aggregate data from distributed systems is growing. However, designs that rely solely on encrypted data transmission make it difficult to trace malicious users. To address this challenge, we have enhanced the secure aggregation (SA) protocol proposed by Bell et al. (CCS 2020) by introducing verification features that ensure compliance with user inputs and encryption processes while preserving data privacy. We present LZKSA, a quantum-safe secure aggregation system with input verification. LZKSA employs seven zero-knowledge proof (ZKP) protocols based on the Ring Learning with Errors problem, specifically designed for secure aggregation. These protocols verify whether users have correctly used SA keys and their Lâ, L2 norms and cosine similarity of data, meet specified constraints, to exclude malicious users from current and future aggregation processes. The specialized ZKPs we propose significantly enhance proof efficiency. In practical federated learning scenarios, our experimental evaluations demonstrate that the proof generation time for Lâ and L2 constraints is reduced to about 10-3 of that required by the current state-of-the-art method, RoFL (S&P 2023), and ACORN (USENIX 2023). For example, the proof generation/verification time of RoFL, ACORN and LZKSA for Lâ is 94s/29.9s, 78.7s/33.9s, and 0.02s/0.0062s for CIFAR10, respectively.