arXivDaily arXiv每日学术速递 周一至周五更新
arXiv周末暂无论文更新,休息一下吧,周末愉快~~
arXiv 2608.17070cs.LGcs.CRcs.LO

可验证但隐私性强:用于神经网络保障的可扩展零知识证明

Certified but Private: Scalable Zero-Knowledge Proofs for Neural Network Guarantees

Youwei Zhong, Ben Merbaum, Timos Antonopoulos, Ning Luo, Charalampos Papamanthou, Katerina Sotiraki, Ruzica Piskac

首次发表
浏览论文内容

中文总结 AI 辅助

提出基于零知识证明的PANDA系统,可在不泄露神经网络私有参数的情况下高效证明其鲁棒性与公平性,支持参数超290万的网络,规模远超同类方案且开销更低。

中文摘要 AI 辅助

随着机器学习模型的部署日益广泛,这些模型的鲁棒性和公平性的形式化保障在安全关键场景和合规场景中变得愈发重要。然而,模型参数通常是商业机密,无法向审计人员或终端用户披露。为此,我们提出PANDA,这是一个使用零知识证明(ZKP)来证明模型鲁棒性和公平性属性而不泄露其私有参数的可扩展系统。PANDA构建于CROWN之上,CROWN是一个高效的鲁棒性认证框架,被用于许多最先进的神经网络形式化验证工具中。PANDA的核心贡献是一种用于证明非线性激活层线性松弛边界的新算法,该算法能生成简单、轻量的证明。值得注意的是,我们的系统可在5分钟内为参数超过290万的神经网络生成本地鲁棒性证明,并能在10秒内完成验证。此前基于ZKP的鲁棒性系统依赖指数时间算法,无法扩展到非平凡网络。相比之下,PANDA的复杂度随网络中神经元数量呈多项式级扩展,这使我们能够支持比现有方法大4个数量级的神经网络,同时显著降低证明者的开销。

英文摘要

With the growing deployment of machine learning models, formal guarantees of the robustness and fairness of these models have become increasingly important in safety-critical and legal-compliance settings. However, model parameters are often commercial secrets that cannot be disclosed to auditors or end users. To this end, we present PANDA, a scalable system that uses zero-knowledge proofs (ZKPs) to prove the robustness and fairness properties of a model without revealing its private parameters. PANDA is built on top of CROWN, an efficient robustness certification framework that is used in many state-of-the-art formal verification tools for neural networks. The core contribution of PANDA is a novel algorithm for proving linear relaxation bounds for non-linear activation layers, yielding simple, lightweight proofs. Remarkably, our system can generate proofs of local robustness for neural networks with more than 2.9M parameters in 5 minutes, and can verify them in 10 seconds. Prior ZKP-based robustness system rely on exponential-time algorithms that cannot scale to nontrivial networks. In contrast, PANDA scales polynomially in the number of neurons in a network, allowing us to support neural networks 4 orders of magnitude larger than previous approaches with significantly reduced prover overhead.

发表机构

  • Yale University(耶鲁大学)
  • University of Illinois Urbana-Champaign(伊利诺伊大学厄巴纳-香槟分校)

机构由 AI 辅助整理,请以论文原文为准。

补充信息

↑