VeriLoRA

R2Demonstrated

VeriLoRA is a zero-knowledge proof framework for low-rank adaptation (LoRA) fine-tuning of language models.

It proves forward propagation, backward propagation and adapter-parameter updates using sumcheck, lookup arguments and polynomial commitments. The NDSS 2026 paper evaluates single-sample steps on six LLaMA and OPT configurations from 3 to 13 billion parameters, using one NVIDIA A100 with 80 GB memory. Proving took 121.93–249.38 seconds per step, with 156–554 seconds for commitment generation reported separately.

Verification took 1.87–3.73 seconds. Public code is linked from the paper.

The evidence covers individual LoRA steps. It does not demonstrate proof generation for an entire fine-tuning run or full-parameter pretraining, and the finite-field representation uses rescaling for non-arithmetic operations 1.

Peer-reviewed results and linked public code demonstrate individual LoRA steps at language-model scale.

  • R1 met: the paper defines proofs for forward propagation, backward propagation and parameter updates, with a security analysis under cryptographic assumptions 1.
  • R2 met through published end-to-end single-step results on six model configurations using one A100 80 GB GPU, with implementation and experiment details and linked public code 1.
  • R3 not met: the demonstrated use is a research experiment, without documented production use or another party's reliance on the proofs 1.

Assessed use: proving single-sample LoRA fine-tuning steps for 3–13-billion-parameter language models

Rubric assessment and gaps →

On this page

What it is

VeriLoRA is a zero-knowledge proof framework for low-rank adaptation (LoRA), a form of language-model fine-tuning that updates adapter matrices while keeping the base model fixed 1. Published at NDSS 2026, it implements zero-knowledge proofs of training constraints for individual fine-tuning steps 1.

How it works

The proof covers the forward pass, backward pass and parameter update of a LoRA step. Sumcheck verifies arithmetic relationships, lookup arguments cover non-arithmetic operations, and Hyrax polynomial commitments bind the values used by the subproofs 1. The protocol uses Fiat–Shamir challenges for non-interactive proofs, with a security analysis under commitment and random-oracle assumptions 1.

The implementation extends zkLLM's inference code with proof routines for backward propagation and updates. It runs layer computations sequentially on the GPU, keeping peak device memory below 80 GB in the reported experiments 1.

Search

Full search page