Implementation · Kaizen · Draft
Evidence & limits
On this page
R2Demonstrated for proving gradient-descent training of small image models on committed data
The peer-reviewed paper specifies the protocol and reports end-to-end training-proof results against a cheating prover.
- R1 met: the paper defines training correctness for a committed model and dataset, public specifications and cryptographic assumptions 1.
- R2 met through reproducible published results for VGG-11 with 10 million parameters and batch size 16, including recursive composition, prover time and verification cost 1.
- R3 not met: the paper establishes a research demonstration without documenting production use or another party's reliance on a proof for a verification decision 1.
Assessed use: proving gradient-descent training of small image models on committed data
Rubric assessment
- A production-grade, available proof-of-training implementation, or another party's documented reliance on its proofs.
Assessed 2026-10-08 against rubric v1.1.
Evidence
- The CCS 2024 paper reports proofs for VGG-11 with 10 million parameters at batch size 16 1.
- The prover took about 15 minutes per iteration. The authors compare this with generic recursive proofs and report 24 times faster proving and 27 times lower prover memory overhead 1.
- The aggregate proof was 1.63 MB, with 130 milliseconds of verification. Those figures are independent of the number of training iterations and the size of the dataset 1.
Limitations
The experiments cover image-model training. Even at that scale, each proven iteration takes minutes 1. The computation uses fixed-point arithmetic, and the architecture and training specification are public 1. The proof's statement is correctness of the committed training computation, which the paper distinguishes from proving inference with the resulting model 1.
Known flaws
Blockers
Proving a VGG-11 gradient-descent iteration with 10 million parameters and batch size 16 took about 15 minutes.