{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,11]],"date-time":"2026-07-11T17:34:12Z","timestamp":1783791252290,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":72,"publisher":"ACM","license":[{"start":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T00:00:00Z","timestamp":1700524800000},"content-version":"vor","delay-in-days":6,"URL":"http:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF (National Science Foundation)","doi-asserted-by":"publisher","award":["CNS 1936826, CCF-FMitF-1836978, IIS- 2008559, SaTC-Frontiers-1804648, CCF-2046710, CCF-1652140, and 2039445, CCF-1910681, CNS1936799"],"award-info":[{"award-number":["CNS 1936826, CCF-FMitF-1836978, IIS- 2008559, SaTC-Frontiers-1804648, CCF-2046710, CCF-1652140, and 2039445, CCF-1910681, CNS1936799"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Aro","award":["W911NF-17-1-0405"],"award-info":[{"award-number":["W911NF-17-1-0405"]}]},{"name":"DARPA","award":["HR00112020026, GARD problem under agreement number 885000"],"award-info":[{"award-number":["HR00112020026, GARD problem under agreement number 885000"]}]},{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-19-1-0200, FA9550-18-1-0166"],"award-info":[{"award-number":["FA9550-19-1-0200, FA9550-18-1-0166"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2023,11,15]]},"DOI":"10.1145\/3576915.3623202","type":"proceedings-article","created":{"date-parts":[[2023,11,21]],"date-time":"2023-11-21T12:35:13Z","timestamp":1700570113000},"page":"1880-1894","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":39,"title":["Experimenting with Zero-Knowledge Proofs of Training"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1330-0419","authenticated-orcid":false,"given":"Sanjam","family":"Garg","sequence":"first","affiliation":[{"name":"University of California, Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-8903-6354","authenticated-orcid":false,"given":"Aarushi","family":"Goel","sequence":"additional","affiliation":[{"name":"NTT Research, Sunnyvale, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5877-0436","authenticated-orcid":false,"given":"Somesh","family":"Jha","sequence":"additional","affiliation":[{"name":"University of Wisconsin - Madison, Madison, WI, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6586-8378","authenticated-orcid":false,"given":"Saeed","family":"Mahloujifar","sequence":"additional","affiliation":[{"name":"Meta AI, San Francisco, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6839-4697","authenticated-orcid":false,"given":"Mohammad","family":"Mahmoody","sequence":"additional","affiliation":[{"name":"University of Virginia, Charlottesville, VA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-1494-8176","authenticated-orcid":false,"given":"Guru-Vamsi","family":"Policharla","sequence":"additional","affiliation":[{"name":"University of California, Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-9057-1007","authenticated-orcid":false,"given":"Mingyuan","family":"Wang","sequence":"additional","affiliation":[{"name":"University of California, Berkeley, Berkeley, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2023,11,21]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"[n. d.]. https:\/\/www.jchs.harvard.edu\/blog\/high-income-black-homeowners- receive-higher-interest-rates-low-income-white-homeowners."},{"key":"e_1_3_2_1_2_1","unstructured":"[n. d.]. Can We No Longer Believe Anything We See? - nytimes.com. https: \/\/www.nytimes.com\/2023\/04\/08\/business\/media\/ai-generated-images.html. [Accessed 09-08-2023]."},{"key":"e_1_3_2_1_3_1","unstructured":"2022. https:\/\/worldcoin.org\/blog\/engineering\/intro-to-zkml."},{"key":"e_1_3_2_1_4_1","unstructured":"2022. https:\/\/github.com\/lyronctk\/zator\/tree\/main."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3339819"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-21568-2_25"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134104"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-77886-6_23"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.36"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-17653-2_4"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417893"},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-016-9241-9"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-64378-2_7"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-84259-8_5"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-30057-8_31"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-07085-3_15"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00020"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-89255-7_15"},{"key":"e_1_3_2_1_19_1","volume-title":"Rocco Fazzolari, Daniele Giardino, Alberto Nannarelli, Marco Re, and Sergio Span\u00f2.","author":"Cardarilli Gian Carlo","year":"2021","unstructured":"Gian Carlo Cardarilli, Luca Di Nunzio, Rocco Fazzolari, Daniele Giardino, Alberto Nannarelli, Marco Re, and Sergio Span\u00f2. 2021. A pseudo-softmax function for hardware-based high speed image classification. Scientific reports, Vol. 11, 1 (2021), 15307."},{"key":"e_1_3_2_1_20_1","volume-title":"Secure Computation with Fixed-Point Numbers. In FC 2010 (LNCS","volume":"50","author":"Catrina Octavian","year":"2010","unstructured":"Octavian Catrina and Amitabh Saxena. 2010. Secure Computation with Fixed-Point Numbers. In FC 2010 (LNCS, Vol. 6052), Radu Sion (Ed.). Springer, Heidelberg, 35--50."},{"key":"e_1_3_2_1_21_1","volume-title":"EzPC: Programmable and Efficient Secure Two-Party Computation for Machine Learning. In IEEE European Symposium on Security and Privacy, EuroS&P 2019","author":"Chandran Nishanth","year":"2019","unstructured":"Nishanth Chandran, Divya Gupta, Aseem Rastogi, Rahul Sharma, and Shardul Tripathi. 2019. EzPC: Programmable and Efficient Secure Two-Party Computation for Machine Learning. In IEEE European Symposium on Security and Privacy, EuroS&P 2019, Stockholm, Sweden, June 17-19, 2019. 496--511."},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133997"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.23005"},{"key":"e_1_3_2_1_24_1","volume-title":"Secure Computation for Machine Learning With SPDZ. Workshop on Privacy Preserving Machine Learning at NeurIPS","author":"Chen Valerie","year":"2018","unstructured":"Valerie Chen, Valerio Pastro, and Mariana Raykova. 2018. Secure Computation for Machine Learning With SPDZ. Workshop on Privacy Preserving Machine Learning at NeurIPS (2018)."},{"key":"e_1_3_2_1_25_1","volume-title":"The measure and mismeasure of fairness: A critical review of fair machine learning. arXiv preprint arXiv:1808.00023","author":"Corbett-Davies Sam","year":"2018","unstructured":"Sam Corbett-Davies and Sharad Goel. 2018. The measure and mismeasure of fairness: A critical review of fair machine learning. arXiv preprint arXiv:1808.00023 (2018)."},{"key":"e_1_3_2_1_26_1","volume-title":"Advances in Neural Information Processing Systems 28: Annual Conference on Neural Information Processing Systems 2015","author":"Courbariaux Matthieu","year":"2015","unstructured":"Matthieu Courbariaux, Yoshua Bengio, and Jean-Pierre David. 2015. BinaryConnect: Training Deep Neural Networks with binary weights during propagations. In Advances in Neural Information Processing Systems 28: Annual Conference on Neural Information Processing Systems 2015, December 7-12, 2015, Montreal, Quebec, Canada, Corinna Cortes, Neil D. Lawrence, Daniel D. Lee, Masashi Sugiyama, and Roman Garnett (Eds.). 3123--3131."},{"key":"e_1_3_2_1_27_1","volume-title":"Optimal Approximation - Smoothness Tradeoffs for Soft-Max Functions. In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020","author":"Epasto Alessandro","year":"2020","unstructured":"Alessandro Epasto, Mohammad Mahdian, Vahab S. Mirrokni, and Emmanouil Zampetakis. 2020. Optimal Approximation - Smoothness Tradeoffs for Soft-Max Functions. In Advances in Neural Information Processing Systems 33: Annual Conference on Neural Information Processing Systems 2020, NeurIPS 2020, December 6-12, 2020, virtual, Hugo Larochelle, Marc'Aurelio Ranzato, Raia Hadsell, Maria-Florina Balcan, and Hsuan-Tien Lin (Eds.). https:\/\/proceedings.neurips.cc\/paper\/2020\/hash\/1bd413de70f32142f4a33a94134c5690-Abstract.html"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560633"},{"key":"e_1_3_2_1_29_1","volume-title":"On the Fundamental Limits of Formally (Dis) Proving Robustness in Proof-of-Learning. arXiv preprint arXiv:2208.03567","author":"Fang Congyu","year":"2022","unstructured":"Congyu Fang, Hengrui Jia, Anvith Thudi, Mohammad Yaghini, Christopher A Choquette-Choo, Natalie Dullerud, Varun Chandrasekaran, and Nicolas Papernot. 2022. On the Fundamental Limits of Formally (Dis) Proving Robustness in Proof-of-Learning. arXiv preprint arXiv:2208.03567 (2022)."},{"key":"e_1_3_2_1_30_1","volume-title":"ZEN: An Optimizing Compiler for Verifiable, Zero-Knowledge Neural Network Inferences. Cryptology ePrint Archive, Report 2021\/087. https:\/\/eprint.iacr.org\/2021\/087.","author":"Feng Boyuan","year":"2021","unstructured":"Boyuan Feng, Lianke Qin, Zhenfei Zhang, Yufei Ding, and Shumo Chu. 2021. ZEN: An Optimizing Compiler for Verifiable, Zero-Knowledge Neural Network Inferences. Cryptology ePrint Archive, Report 2021\/087. https:\/\/eprint.iacr.org\/2021\/087."},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/129712.129780"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560653"},{"key":"e_1_3_2_1_33_1","volume-title":"USENIX Security","author":"Giacomelli Irene","year":"2016","unstructured":"Irene Giacomelli, Jesper Madsen, and Claudio Orlandi. 2016. ZKBoo: Faster Zero-Knowledge for Boolean Circuits. In USENIX Security 2016, Thorsten Holz and Stefan Savage (Eds.). USENIX Association, 1069--1083."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1109\/FOCS54457.2022.00092"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/22145.22178"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1137\/0217017"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-15985-5_1"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0036"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-49896-5_11"},{"key":"e_1_3_2_1_40_1","unstructured":"Ulrich Hab\u00f6ck. 2022. A summary on the FRI low degree test. Cryptology ePrint Archive Report 2022\/1216. https:\/\/eprint.iacr.org\/2022\/1216."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/1250790.1250794"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00106"},{"key":"e_1_3_2_1_43_1","volume-title":"Felten","author":"Kalodner Harry A.","year":"2018","unstructured":"Harry A. Kalodner, Steven Goldfeder, Xiaoqi Chen, S. Matthew Weinberg, and Edward W. Felten. 2018. Arbitrum: Scalable, private smart contracts. In USENIX Security 2019, William Enck and Adrienne Porter Felt (Eds.). USENIX Association, 1353--1370."},{"key":"e_1_3_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243805"},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1145\/129712.129782"},{"key":"e_1_3_2_1_46_1","volume-title":"CrypTen: Secure Multi-Party Computation Meets Machine Learning. In Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems 2021","author":"Knott Brian","year":"2021","unstructured":"Brian Knott, Shobha Venkataraman, Awni Y. Hannun, Shubho Sengupta, Mark Ibrahim, and Laurens van der Maaten. 2021. CrypTen: Secure Multi-Party Computation Meets Machine Learning. In Advances in Neural Information Processing Systems 34: Annual Conference on Neural Information Processing Systems 2021, NeurIPS 2021, December 6-14, 2021, virtual. 4961--4973."},{"key":"e_1_3_2_1_47_1","volume-title":"Amrita Roy Chowdhury, and Kamalika Chaudhuri","author":"Kong Zhifeng","year":"2023","unstructured":"Zhifeng Kong, Amrita Roy Chowdhury, and Kamalika Chaudhuri. 2023. Can Membership Inferencing be Refuted? arXiv preprint arXiv:2303.03648 (2023)."},{"key":"e_1_3_2_1_48_1","unstructured":"Seunghwa Lee Hankyung Ko Jihye Kim and Hyunok Oh. 2020. vCNN: Verifiable Convolutional Neural Network. Cryptology ePrint Archive Report 2020\/584. https:\/\/eprint.iacr.org\/2020\/584."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134056"},{"key":"e_1_3_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485379"},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485379"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICAC55051.2022.9911156"},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/SFCS.1994.365746"},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243760"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.12"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1007\/0-387-34805-0_13"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00035"},{"key":"e_1_3_2_1_58_1","volume-title":"USENIX Security","author":"Patra Arpita","year":"2021","unstructured":"Arpita Patra, Thomas Schneider, Ajith Suresh, and Hossein Yalame. 2021. ABY2. 0: Improved Mixed-Protocol Secure Two-Party Computation. In USENIX Security 2021, Michael Bailey and Rachel Greenstadt (Eds.). USENIX Association, 2165--2182."},{"key":"e_1_3_2_1_59_1","volume-title":"International conference on machine learning. PMLR, 8748--8763","author":"Radford Alec","year":"2021","unstructured":"Alec Radford, Jong Wook Kim, Chris Hallacy, Aditya Ramesh, Gabriel Goh, Sandhini Agarwal, Girish Sastry, Amanda Askell, Pamela Mishkin, Jack Clark, et al. 2021. Learning transferable visual models from natural language supervision. In International conference on machine learning. PMLR, 8748--8763."},{"key":"e_1_3_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833697"},{"key":"e_1_3_2_1_61_1","volume-title":"Tiancheng Xie, Ryan Cottone, and Dawn Song.","author":"Rathee Deevashwer","year":"2022","unstructured":"Deevashwer Rathee, Guru Vamsi Policharla, Tiancheng Xie, Ryan Cottone, and Dawn Song. 2022b. ZEBRA: Anonymous Credentials with Practical On-chain Verification and Applications to KYC in DeFi. Cryptology ePrint Archive, Paper 2022\/1286. https:\/\/eprint.iacr.org\/2022\/1286 https:\/\/eprint.iacr.org\/2022\/1286."},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00086"},{"key":"e_1_3_2_1_63_1","volume-title":"USENIX Security","author":"Setty Srinath T. V.","year":"2012","unstructured":"Srinath T. V. Setty, Victor Vu, Nikhil Panpalia, Benjamin Braun, Andrew J. Blumberg, and Michael Walfish. 2012. Taking Proof-Based Verified Computation a Few Steps Closer to Practicality. In USENIX Security 2012, Tadayoshi Kohno (Ed.). USENIX Association, 253--268."},{"key":"e_1_3_2_1_64_1","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359176"},{"key":"e_1_3_2_1_65_1","unstructured":"StarkWare. 2021. ethSTARK Documentation. Cryptology ePrint Archive Report 2021\/582. https:\/\/eprint.iacr.org\/2021\/582."},{"key":"e_1_3_2_1_66_1","volume-title":"31st USENIX Security Symposium (USENIX Security 22)","author":"Thudi Anvith","year":"2022","unstructured":"Anvith Thudi, Hengrui Jia, Ilia Shumailov, and Nicolas Papernot. 2022. On the necessity of auditable algorithmic definitions for machine unlearning. In 31st USENIX Security Symposium (USENIX Security 22). 4007--4022."},{"key":"e_1_3_2_1_67_1","doi-asserted-by":"publisher","DOI":"10.5555\/3241094.3241142"},{"key":"e_1_3_2_1_68_1","doi-asserted-by":"publisher","DOI":"10.2478\/popets-2019-0035"},{"key":"e_1_3_2_1_69_1","volume-title":"Mystique: Efficient Conversions for Zero-Knowledge Proofs with Applications to Machine Learning. In USENIX Security","author":"Weng Chenkai","year":"2021","unstructured":"Chenkai Weng, Kang Yang, Xiang Xie, Jonathan Katz, and Xiao Wang. 2021. Mystique: Efficient Conversions for Zero-Knowledge Proofs with Applications to Machine Learning. In USENIX Security 2021, Michael Bailey and Rachel Greenstadt (Eds.). USENIX Association, 501--518."},{"key":"e_1_3_2_1_70_1","unstructured":"Roman Yampolskiy. 2022. Unownability of AI: Why Legal Ownership of Artificial Intelligence is Hard. (2022)."},{"key":"e_1_3_2_1_71_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417278"},{"key":"e_1_3_2_1_72_1","unstructured":"ZkRollups. 2021. An incomplete guide to rollups. https:\/\/vitalik.ca\/general\/2021\/01\/ 05\/rollup.html."}],"event":{"name":"CCS '23: ACM SIGSAC Conference on Computer and Communications Security","location":"Copenhagen Denmark","acronym":"CCS '23","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623202","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623202","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3576915.3623202","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,21]],"date-time":"2025-08-21T01:56:35Z","timestamp":1755741395000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3576915.3623202"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,11,15]]},"references-count":72,"alternative-id":["10.1145\/3576915.3623202","10.1145\/3576915"],"URL":"https:\/\/doi.org\/10.1145\/3576915.3623202","relation":{},"subject":[],"published":{"date-parts":[[2023,11,15]]},"assertion":[{"value":"2023-11-21","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}