{
  "schema_version": "1.4.0",
  "rubric_version": "1.1",
  "license": "CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/)",
  "record": {
    "id": "I-0025",
    "slug": "verilora",
    "title": "VeriLoRA",
    "aliases": [
      "zkLoRA fine-tuning"
    ],
    "status": "draft",
    "last_reviewed": "2026-10-08",
    "review_interval_days": 90,
    "steward": null,
    "provenance": {
      "drafted_by": "ai",
      "reviewed_by": []
    },
    "risk_flags": [],
    "flags": [],
    "one_liner": "Proves individual low-rank language-model fine-tuning steps, including forward propagation, gradient computation and parameter updates, without revealing private weights or training data.",
    "summary": "VeriLoRA is a zero-knowledge proof framework for low-rank adaptation (LoRA) fine-tuning of language models. It proves forward propagation, backward propagation and adapter-parameter updates using sumcheck, lookup arguments and polynomial commitments. The NDSS 2026 paper evaluates single-sample steps on six LLaMA and OPT configurations from 3 to 13 billion parameters, using one NVIDIA A100 with 80 GB memory. Proving took 121.93–249.38 seconds per step, with 156–554 seconds for commitment generation reported separately. Verification took 1.87–3.73 seconds. Public code is linked from the paper. The evidence covers individual LoRA steps. It does not demonstrate proof generation for an entire fine-tuning run or full-parameter pretraining, and the finite-field representation uses rescaling for non-arithmetic operations [[S-3080]].",
    "category": "cryptographic-computational",
    "secondary_categories": [],
    "verifies": [
      {
        "claim": "C-0007",
        "role": "primary",
        "note": "Proves the declared computation for individual LoRA fine-tuning steps. The evidence is narrower than a full-run training or compute-budget claim (S-3080)."
      }
    ],
    "threat_model": "adversarial",
    "adversarial_evaluation": "analysis",
    "hardware_requirement": "none",
    "prover_cooperation": "required",
    "confidentiality": "preserving",
    "depends_on": [],
    "readiness": {
      "assessment": true,
      "level": "R2",
      "scope": "proving single-sample LoRA fine-tuning steps for 3–13-billion-parameter language models",
      "rubric_version": "1.1",
      "rationale": "Peer-reviewed results and linked public code demonstrate individual LoRA steps at language-model scale.\n- **R1** met: the paper defines proofs for forward propagation, backward propagation and parameter updates, with a security analysis under cryptographic assumptions [[S-3080]].\n- **R2** met through published end-to-end single-step results on six model configurations using one A100 80 GB GPU, with implementation and experiment details and linked public code [[S-3080]].\n- **R3** not met: the demonstrated use is a research experiment, without documented production use or another party's reliance on the proofs [[S-3080]].",
      "evidence": [
        "S-3080"
      ],
      "next_level_gaps": [
        "A production-grade, available LoRA proving implementation, or another party's documented reliance on its proofs."
      ],
      "confidence": "medium",
      "assessed_by": [
        "ai-draft"
      ],
      "assessed_on": "2026-10-08",
      "status": "current",
      "dispute": null
    },
    "flaws": [
      {
        "assessment": true,
        "title": "Arithmetic representation needs rescaling",
        "kind": "open-question",
        "severity": "minor",
        "status": "open",
        "description": "The implementation uses rescaling to represent non-arithmetic operations in finite-field proofs. The authors test precision choices to limit accuracy changes (S-3080).",
        "sources": [
          "S-3080"
        ],
        "response": null
      }
    ],
    "blockers": [
      {
        "text": "Each single-sample step took 121.93–249.38 seconds to prove, with commitment generation taking another 156–554 seconds in the reported experiments.",
        "theme": "performance-compatibility",
        "blocked_by": null,
        "sources": [
          "S-3080"
        ]
      }
    ],
    "challenge_themes": [
      "performance-compatibility",
      "protocol-soundness",
      "evidence-binding"
    ],
    "organizations": [],
    "people": [],
    "sources": [
      {
        "source": "S-3080",
        "supports": "LoRA step scope; proof primitives; cryptographic assumptions; rescaling; hardware; per-step timings; public code",
        "locator": "§IV–V; §VI-A–VI-D; Figure 2; Table I"
      }
    ],
    "concepts": [
      "K-0010",
      "K-0024",
      "K-0014"
    ],
    "kind": "research-prototype",
    "developer": [],
    "realises": [
      "M-0005"
    ],
    "homepage": "https://www.ndss-symposium.org/ndss-paper/verilora-fine-tuning-large-language-models-with-verifiable-security-via-zero-knowledge-proofs/",
    "repo": "https://github.com/liaoguofu/zkLoRA",
    "type": "implementation",
    "url": "https://trustbutveri.fyi/implementations/verilora/",
    "source_file": "content/implementations/verilora.md",
    "flags_all": [],
    "body_markdown": "## What it is\n\nVeriLoRA is a zero-knowledge proof framework for low-rank adaptation (LoRA), a form of language-model\nfine-tuning that updates adapter matrices while keeping the base model fixed [[S-3080]]. Published at NDSS\n2026, it implements [[M-0005|zero-knowledge proofs of training constraints]] for individual fine-tuning\nsteps [[S-3080]].\n\n## How it works\n\nThe proof covers the forward pass, backward pass and parameter update of a LoRA step. Sumcheck verifies\narithmetic relationships, lookup arguments cover non-arithmetic operations, and Hyrax polynomial\ncommitments bind the values used by the subproofs [[S-3080]]. The protocol uses Fiat–Shamir challenges for\nnon-interactive proofs, with a security analysis under commitment and random-oracle assumptions\n[[S-3080]].\n\nThe implementation extends zkLLM's inference code with proof routines for backward propagation and\nupdates. It runs layer computations sequentially on the GPU, keeping peak device memory below 80 GB\nin the reported experiments [[S-3080]].\n\n## Evidence\n\n- The paper tests six LLaMA and OPT configurations from 3 to 13 billion parameters on one NVIDIA A100\n  80 GB GPU. Each measurement covers a minibatch containing one sample [[S-3080]].\n- Proving took 121.93–249.38 seconds per step. Commitment generation took 156–554 seconds, a separately\n  reported cost that dominates wall-clock latency in the authors' evaluation [[S-3080]].\n- Verification took 1.87–3.73 seconds. Commitment sizes ranged from 135.59 to 232.67 MB [[S-3080]].\n- The paper links public implementation code in the zkLoRA repository [[S-3080]].\n\n## Limitations\n\nThe reported experiments prove individual LoRA steps on one sample. LoRA updates a small set of adapter\nparameters, and the evidence does not cover full-parameter pretraining [[S-3080]]. The authors report\nproving approximately three orders of magnitude slower than their no-proof step baselines, with ratios\ndepending on the model and prover setup [[S-3080]]. Rescaling choices affect the finite-field\nrepresentation of non-arithmetic operations, and the authors evaluate precision settings to limit\naccuracy changes [[S-3080]].",
    "body_text": "What it is VeriLoRA is a zero-knowledge proof framework for low-rank adaptation (LoRA), a form of language-model fine-tuning that updates adapter matrices while keeping the base model fixed [S-3080]. Published at NDSS 2026, it implements zero-knowledge proofs of training constraints for individual fine-tuning steps [S-3080]. How it works The proof covers the forward pass, backward pass and parameter update of a LoRA step. Sumcheck verifies arithmetic relationships, lookup arguments cover non-arithmetic operations, and Hyrax polynomial commitments bind the values used by the subproofs [S-3080]. The protocol uses Fiat–Shamir challenges for non-interactive proofs, with a security analysis under commitment and random-oracle assumptions [S-3080]. The implementation extends zkLLM's inference code with proof routines for backward propagation and updates. It runs layer computations sequentially on the GPU, keeping peak device memory below 80 GB in the reported experiments [S-3080]. Evidence - The paper tests six LLaMA and OPT configurations from 3 to 13 billion parameters on one NVIDIA A100 80 GB GPU. Each measurement covers a minibatch containing one sample [S-3080]. - Proving took 121.93–249.38 seconds per step. Commitment generation took 156–554 seconds, a separately reported cost that dominates wall-clock latency in the authors' evaluation [S-3080]. - Verification took 1.87–3.73 seconds. Commitment sizes ranged from 135.59 to 232.67 MB [S-3080]. - The paper links public implementation code in the zkLoRA repository [S-3080]. Limitations The reported experiments prove individual LoRA steps on one sample. LoRA updates a small set of adapter parameters, and the evidence does not cover full-parameter pretraining [S-3080]. The authors report proving approximately three orders of magnitude slower than their no-proof step baselines, with ratios depending on the model and prover setup [S-3080]. Rescaling choices affect the finite-field representation of non-arithmetic operations, and the authors evaluate precision settings to limit accuracy changes [S-3080].",
    "referenced_by": []
  }
}