Skip to content
Preprint

Agree on the Model, Verify the Inference: GKR Protocols for HND-Based Transformer Inference

Jul 2026 · 0 citations · 41 references
Computer Science

TL;DR

GKR-HND, a registered-model protocol for verifying the polynomial backbone of Homomorphic--Nonhomomorphic Decomposition Transformers is presented, a registered-model protocol for verifying the polynomial backbone of Homomorphic--Nonhomomorphic Decomposition Transformers.

Abstract

Outsourced Transformer inference exposes clients to model substitution and incomplete execution, while direct replay removes the computational benefit of delegation. We present GKR-HND, a registered-model protocol for verifying the polynomial backbone of Homomorphic--Nonhomomorphic Decomposition Transformers. The retained verifier checks the GKR transcript and registered-weight openings, but delegates expensive public evaluations to an assigned computation worker. Assuming an honest retained verifier and prover--worker non-collusion, the verifier accepts only when the worker's signed, request-bound response agrees with the proof claims. Experiments with pretrained HND models validate the proof path and the delegated public computation without dense-matrix replay.

View source

Similar papers

Open access Oct 2026

Beyond the Output: Inference Attacks on Private Set Union and Multi-Key Private Matching

This work expands the understanding of attacks in this setting by investigating a broader class of functionalities, namely: Private Set Union, PSU-Cardinality, and Meta’s multi-key private matching (MKPM) functionality, and investigates possible mitigations for deploying such systems.

Andrea Raguso, Francesca Falzon, Tianxin Tang et al. · 0 citations
Jul 2026

Zero-Knowledge Proof of Progress: Secure Multi-Phase Capture-the-Flag Competitions

Existing Capture-the-Flag (CTF) platforms trust a single organizer, offer limited auditability, and are vulnerable to infrastructure-level manipulation. We propose zk–MPSFV, a zk-SNARK-based, multi-phase sub-flag verification scheme that replaces centralized scoring with an on-chain, zero-knowledge, publicly verifiable scoreboard. Challenges are decomposed into sub-challenges arranged as a directed acyclic graph (DAG): a team unlocks the next step only after proving completion of all parent nodes. Sub-flags and decryption keys are jointly generated by n organizers and released via an off-chain ($t, n$) Shamir–BLS threshold signature produced through multi-party computation (MPC), preventing any single organizer from leaking or altering keys. Teams submit zk-PLONK proofs that the contract verifies, timestamps, and records immutably. Under standard assumptions (collision-resistant hashing, SNARK soundness/zero-knowledge, IND-CCA2 ECIES, and at least t honest organizers), we prove that zk–MPSFV achieves the stated security goals, including DAG-gated progress, anti-replay, and threshold-robust organizer security, while out-of-band flag sharing remains out of scope. On a three-organizer testbed with 30 simulated teams, setup costs 0.45 ms per sub-flag, proof generation averages 5.34 s on an 8-core system, and on-chain verification costs $\approx$ 170kL2 gas on zkSync Era with a median fee of 1.33 $\times 10^{-6}$ ETH (about ${\$}$0.0046 at ${\$}$3,435/ETH). Stress replays sustain $\approx$ 7 proof transactions/s up to 5000 proofs; extrapolating to 50,000 proofs (1000 teams $\times$ 50 submissions) yields $\approx$ 0.0665 ETH (about ${\$}$200–${\$}$228) and $\approx$ 2 hours of settlement time. Overall, zk-MPSFV is practical for small- to mid-scale, audit-ready progression CTFs.

S. Khanji, Behzad Abdolmaleki, John A. Clark et al. · 0 citations
Book Open access Aug 2026

AegisPath: Privacy-Preserving Interdomain Data-Plane Verification with Versioned Verifiable Evidence

Network verification checks whether forwarding behavior satisfies intended invariants. In interdomain settings, data-plane verification is challenging because forwarding configurations are private, while post-incident review requires repeatable, version-specific checking without costly online coordination. We present AegisPath, it replaces centralized verification with distributed witness generation to protect AS-local configurations, decouples witness generation from repeated auditing through a commit-and-prove design, uses zero-knowledge proofs to answer queries without revealing forwarding paths, and supports incremental updates. Experiments show that offline Secure Multi-Party Computation (SMPC) witness generation takes from thousands to over 104 seconds, online Zero-Knowledge (ZK) auditing remains sub-second, and incremental maintenance yields substantial speedups over full re-computation.

Mingjun Fang, Shuhao Zheng, Zonglun Li et al. · 0 citations
#natural language process... Preprint Sep 2026

A Certificate-Producing Cascade for Equational Implication: The SAIR EQT2 Stage 2 Solver

The SAIR Mathematics Distillation Challenge on Equational Theories asks a solver to classify whether one magma identity implies another and, for either verdict, to return a certificate accepted by a deterministic Lean judge. We present a single-file solver organized as a cheapest-first cascade. Its false branch combines coefficient tests over structured algebra families, bounded finite-model search, an explicit central-groupoid witness, and several infinite-carrier witnesses. Its true branch is a proof-producing ordered unit superposition procedure with Knuth-Bendix ordering, bidirectional demodulation, indexing, memoised substitution, and anytime size deepening. Search results remain outside the trusted base: successful derivations are replayed as small Lean terms, and countermodels are rechecked by the competition judge. The frozen solver is a 189,504-byte Python file with SHA-256 f2392533c9f4c03b.... In local runs through official judge revision 2848228, it produced accepted certificates for all 1,889 rows of the six public sets with no language-model calls. Separate measurements recorded full agreement on the 800 published Stage 1 evaluation-distribution problems, 100 accepted rows in the canonical Marathon manifest without tokens, and 200 accepted rows in the hosted playground. These are regression and playground measurements, not a leaderboard result and not evidence about a hidden set. All quantitative claims are tied to immutable result ledgers; the paper makes no completeness or comparative-superiority claim.

Hao Ma, Wen-Lin Zhang, Manuel Israel Cázares · 0 citations
Open access Aug 2026

TriVer: a lightweight and client-verifiable secure aggregation with dropout tolerance for federated learning

It is proved that TriVer satisfies client data privacy, aggregation correctness, and aggregation-result non-forgeability in the Random Oracle Model under ECDLP hardness, HPRF pseudorandomness, and hash collision resistance, against a fully malicious server that may collude with a subset of aggregators and clients.

Guang-Ye Zhu, Liqiang Wu, Weidong Du · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.