Mechanism · Training-transcript verification (proof-of-learning)

Sources

On this page
  1. AH. Jia et al. (2021). Proof-of-Learning: Definitions and Practice. 2021 IEEE Symposium on Security and Privacy (SP), pp. 1039-1056. Source recordSupports: PoL definition, transcript contents, verification, security analysis, limits · Definition 1; Algorithm 2; §IV–VI; Table I
  2. BCleverHans Lab (2021). Proof-of-Learning: code for Proof-of-Learning: Definitions and Practice. GitHub. Source recordSupports: public PoL implementation (train and verify scripts); rationale for the cost of forging · README
  3. AR. Zhang et al. (2022). "Adversarial Examples" for Proof-of-Learning. 2022 IEEE Symposium on Security and Privacy (SP), pp. 1408-1422. Source recordSupports: independent demonstrated spoofing attack; countermeasures · abstract; §III–V
  4. AC. Fang et al. (2023). Proof-of-Learning is Currently More Broken Than You Think. 8th IEEE European Symposium on Security and Privacy (EuroS&P 2023). Source recordSupports: structurally correct and stochastic spoofing; robustness conclusion; response to Zhang et al. · abstract; §2.3; attack sections; conclusion
  5. BY. Shavit (2023). What does it take to catch a Chinchilla? Verifying Rules on Large-Scale Neural Network Training via Compute Monitoring. arXiv. Source recordSupports: training-transcript verification for rules; chip logging; open problems; costs · §4; §5; §5.1; §5.2; §6.1; Table 1
  6. AD. Choi et al. (2023). Tools for Verifying Neural Models' Training Data. Advances in Neural Information Processing Systems 36 (NeurIPS 2023). Source recordSupports: proof-of-training-data protocol, experiments, defended attacks, costs, limits · §3; §4.1–4.4; §6; §7; App. A
  7. AM. Srivastava et al. (2024). Optimistic Verifiable Training by Controlling Hardware Nondeterminism. Advances in Neural Information Processing Systems 37 (NeurIPS 2024). Source recordSupports: exact-replication verifiable training: rounding logs, Merkle-tree dispute search, experiments, overheads, 1-of-n auditor assumption, limitations · abstract; §3–§5; limitations
  8. BA. Arun et al. (2025). Verde: Verification via Refereed Delegation for Machine Learning Programs. arXiv. Source recordSupports: Verde dispute narrowing for training jobs; RepOps LoRA fine-tuning overhead · §3; Table 2
  9. BGensyn (2026). gensyn-ai/ree: Gensyn Reproducible Execution Environment (GitHub repository). GitHub. Source recordSupports: Gensyn's REE release limited to reproducible LLM inference (provider-reported) · README
  10. AS. Waiwitlikhit et al. (2024). Trustless Audits without Revealing Data or Models. 41st International Conference on Machine Learning (ICML 2024). Source recordSupports: cryptographic alternative (ZK proofs of SGD) · abstract

Search

Full search page