Kaizen

R2Demonstrated

Kaizen is a zero-knowledge proof-of-training system for deep neural networks.

It proves that committed model parameters result from a public training algorithm applied to a committed dataset, keeping the model and data private. Specialized sumcheck proofs verify individual gradient-descent iterations, then recursive composition combines them into a proof whose size and verification time do not grow with the number of iterations. The CCS 2024 paper reports training proofs for a 10-million-parameter VGG-11 with batch size 16.

Proving took about 15 minutes per iteration; the 1.63 MB proof verified in 130 milliseconds. The demonstrated computation uses fixed-point arithmetic and a public architecture and training specification. The evidence covers image-model training, and the per-iteration proving cost is a substantial obstacle to larger runs 1.

The peer-reviewed paper specifies the protocol and reports end-to-end training-proof results against a cheating prover.

  • R1 met: the paper defines training correctness for a committed model and dataset, public specifications and cryptographic assumptions 1.
  • R2 met through reproducible published results for VGG-11 with 10 million parameters and batch size 16, including recursive composition, prover time and verification cost 1.
  • R3 not met: the paper establishes a research demonstration without documenting production use or another party's reliance on a proof for a verification decision 1.

Assessed use: proving gradient-descent training of small image models on committed data

Rubric assessment and gaps →

On this page

What it is

Kaizen is a zero-knowledge proof-of-training system for deep neural networks, published at CCS 2024 1. It implements zero-knowledge proofs of training constraints by proving that committed weights result from the stated training procedure on a committed dataset 1.

How it works

The model owner commits to the dataset and model. The training algorithm and specifications, such as architecture and batch size, are public. A proof then attests that the committed model was correctly trained under that specification without revealing further information about the private weights or data 1.

Kaizen specializes sumcheck-based proofs for gradient descent. These proofs check each iteration, and recursive composition combines the iteration proofs. Aggregatable polynomial commitments reduce the cost of that composition. The number of iterations need not be fixed before training starts 1.

After each iteration, the prover produces a commitment to the updated parameters with a proof covering the executed iterations. Proof size and verifier time are independent of the number of iterations and dataset size 1.

Search

Full search page