{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,6]],"date-time":"2026-06-06T01:10:19Z","timestamp":1780708219880,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":47,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,22]],"date-time":"2024-04-22T00:00:00Z","timestamp":1713744000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,22]]},"DOI":"10.1145\/3627703.3650088","type":"proceedings-article","created":{"date-parts":[[2024,4,18]],"date-time":"2024-04-18T06:28:28Z","timestamp":1713421708000},"page":"560-574","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":50,"title":["ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0003-5931-6579","authenticated-orcid":false,"given":"Bing-Jyue","family":"Chen","sequence":"first","affiliation":[{"name":"UIUC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-8734-9961","authenticated-orcid":false,"given":"Suppakit","family":"Waiwitlikhit","sequence":"additional","affiliation":[{"name":"Stanford University, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5373-0088","authenticated-orcid":false,"given":"Ion","family":"Stoica","sequence":"additional","affiliation":[{"name":"UC Berkeley, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9860-9938","authenticated-orcid":false,"given":"Daniel","family":"Kang","sequence":"additional","affiliation":[{"name":"UIUC, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,4,22]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2023. The minimal neural network that achieves 99% on MNIST. https:\/\/github.com\/ruslangrimov\/mnist-minimal-mnistmodel"},{"key":"e_1_3_2_1_2_1","volume-title":"A guide to fully homomorphic encryption. Cryptology ePrint Archive","author":"Armknecht Frederik","year":"2015","unstructured":"Frederik Armknecht, Colin Boyd, Christopher Carr, Kristian Gj\u00f8steen, Angela J\u00e4schke, Christian A Reuter, and Martin Strand. 2015. A guide to fully homomorphic encryption. Cryptology ePrint Archive (2015)."},{"key":"e_1_3_2_1_3_1","volume-title":"What did Twitter's 'open source' algorithm actually reveal? Not a lot. Engadget","author":"Bell Karissa","year":"2023","unstructured":"Karissa Bell. 2023. What did Twitter's 'open source' algorithm actually reveal? Not a lot. Engadget (2023). https:\/\/www.engadget.com\/what-did-twitters-open-source-algorithm-actually-reveal-not-a-lot-194652809.html"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"crossref","unstructured":"Eli Ben-Sasson Iddo Bentov Yinon Horesh and Michael Riabzev. 2018. Scalable transparent and post-quantum secure computational integrity. Cryptology ePrint Archive Paper 2018\/046. https:\/\/eprint.iacr.org\/2018\/046 https:\/\/eprint.iacr.org\/2018\/046.","DOI":"10.1088\/1475-7516\/2018\/03\/046"},{"key":"e_1_3_2_1_5_1","volume-title":"The state of artificial intelligence-based FDA-approved medical devices and algorithms: an online database. NPJ digital medicine 3, 1","author":"Benjamens Stan","year":"2020","unstructured":"Stan Benjamens, Pranavsingh Dhunnoo, and Bertalan Mesk\u00f3. 2020. The state of artificial intelligence-based FDA-approved medical devices and algorithms: an online database. NPJ digital medicine 3, 1 (2020), 118."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-016-9241-9"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-92078-4_3"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3326937.3341261"},{"key":"e_1_3_2_1_9_1","volume-title":"Proceedings of the 4th USENIX Conference on Hot Topics in Security. USENIX Association Berkeley, CA, USA, 8--8.","author":"Dua Akshay","year":"2009","unstructured":"Akshay Dua, Nirupama Bulusu, Wu-Chang Feng, and Wen Hu. 2009. Towards trustworthy participatory sensing. In Proceedings of the 4th USENIX Conference on Hot Topics in Security. USENIX Association Berkeley, CA, USA, 8--8."},{"key":"e_1_3_2_1_10_1","volume-title":"ZEN: An optimizing compiler for verifiable, zero-knowledge neural network inferences. Cryptology ePrint Archive","author":"Feng Boyuan","year":"2021","unstructured":"Boyuan Feng, Lianke Qin, Zhenfei Zhang, Yufei Ding, and Shumo Chu. 2021. ZEN: An optimizing compiler for verifiable, zero-knowledge neural network inferences. Cryptology ePrint Archive (2021)."},{"key":"e_1_3_2_1_11_1","volume-title":"IFIP congress","author":"Freivalds Rusins","unstructured":"Rusins Freivalds. 1977. Probabilistic Machines Can Use Less Running Time.. In IFIP congress, Vol. 839. 842."},{"key":"e_1_3_2_1_12_1","unstructured":"Ariel Gabizon. 2021. From AIRs to RAPs - how PLONK-style arithmetization works. https:\/\/hackmd.io\/@aztec-network\/plonk-arithmetiization-air. (2021). https:\/\/hackmd.io\/@aztec-network\/plonk-arithmetiization-air"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1145\/1734583.1734592"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-46493-0_38"},{"key":"e_1_3_2_1_15_1","unstructured":"Itay Hubara Matthieu Courbariaux Daniel Soudry Ran El-Yaniv and Yoshua Bengio. 2017. Quantized neural networks: training neural networks with low precision weights and activations. J. Mach. Learn. Res. (2017) 6869--6898."},{"key":"e_1_3_2_1_16_1","volume-title":"Quantization and Training of Neural Networks for Efficient Integer-Arithmetic-Only Inference. 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition","author":"Jacob Benoit","year":"2017","unstructured":"Benoit Jacob, Skirmantas Kligys, Bo Chen, Menglong Zhu, Matthew Tang, Andrew G. Howard, Hartwig Adam, and Dmitry Kalenichenko. 2017. Quantization and Training of Neural Networks for Efficient Integer-Arithmetic-Only Inference. 2018 IEEE\/CVF Conference on Computer Vision and Pattern Recognition (2017), 2704--2713."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-53140-2_25"},{"key":"e_1_3_2_1_18_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Juvekar Chiraag","year":"2018","unstructured":"Chiraag Juvekar, Vinod Vaikuntanathan, and Anantha Chandrakasan. 2018. {GAZELLE}: A low latency framework for secure neural network inference. In 27th USENIX Security Symposium (USENIX Security 18). 1651--1669."},{"key":"e_1_3_2_1_19_1","volume-title":"Scaling up Trustless DNN Inference with Zero-Knowledge Proofs. arXiv preprint arXiv:2210.08674","author":"Kang Daniel","year":"2022","unstructured":"Daniel Kang, Tatsunori Hashimoto, Ion Stoica, and Yi Sun. 2022. Scaling up Trustless DNN Inference with Zero-Knowledge Proofs. arXiv preprint arXiv:2210.08674 (2022)."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-17373-8_11"},{"key":"e_1_3_2_1_21_1","unstructured":"Will Knight. 2023. OpenAI's CEO Says the Age of Giant AI Models Is Already Over. https:\/\/www.wired.com\/story\/openai-ceo-sam-altman-the-age-of-giant-ai-models-is-already-over\/"},{"key":"e_1_3_2_1_22_1","first-page":"4961","article-title":"Crypten: Secure multi-party computation meets machine learning","volume":"34","author":"Knott Brian","year":"2021","unstructured":"Brian Knott, Shobha Venkataraman, Awni Hannun, Shubho Sengupta, Mark Ibrahim, and Laurens van der Maaten. 2021. Crypten: Secure multi-party computation meets machine learning. Advances in Neural Information Processing Systems 34 (2021), 4961--4973.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_23_1","volume-title":"Accountable algorithms. Ph. D. Dissertation","author":"Kroll Joshua Alexander","unstructured":"Joshua Alexander Kroll. 2015. Accountable algorithms. Ph. D. Dissertation. Princeton University."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00092"},{"key":"e_1_3_2_1_25_1","volume-title":"Gu-Yeon Wei, and David Brooks.","author":"Lam Maximilian","year":"2022","unstructured":"Maximilian Lam, Michael Mitzenmacher, Vijay Janapa Reddi, Gu-Yeon Wei, and David Brooks. 2022. Tabula: Efficiently Computing Nonlinear Activation Functions for Secure Neural Network Inference. arXiv preprint arXiv:2203.02833 (2022)."},{"key":"e_1_3_2_1_26_1","volume-title":"vCNN: Verifiable convolutional neural network based on zk-SNARKs. Cryptology ePrint Archive","author":"Lee Seunghwa","year":"2020","unstructured":"Seunghwa Lee, Hankyung Ko, Jihye Kim, and Hyunok Oh. 2020. vCNN: Verifiable convolutional neural network based on zk-SNARKs. Cryptology ePrint Archive (2020)."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485379"},{"key":"e_1_3_2_1_28_1","volume-title":"International conference on machine learning. PMLR, 7102--7110","author":"Lou Qian","year":"2021","unstructured":"Qian Lou and Lei Jiang. 2021. Hemet: A homomorphic-encryption-friendly privacy-preserving mobile neural network architecture. In International conference on machine learning. PMLR, 7102--7110."},{"key":"e_1_3_2_1_29_1","volume-title":"Cuzk: Accelerating zero-knowledge proof with a faster parallel multi-scalar multiplication algorithm on gpus. Cryptology ePrint Archive","author":"Lu Tao","year":"2022","unstructured":"Tao Lu, Chengkun Wei, Ruijing Yu, Chaochao Chen, Wenjing Fang, Lei Wang, Zeke Wang, and Wenzhi Chen. 2022. Cuzk: Accelerating zero-knowledge proof with a faster parallel multi-scalar multiplication algorithm on gpus. Cryptology ePrint Archive (2022)."},{"key":"e_1_3_2_1_30_1","unstructured":"James McGirk. 2023. The State of Zero-Knowledge Machine Learning (zkML). (2023). https:\/\/blog.spectral.finance\/the-state-of-zero-knowledge-machine-learning-zkml\/"},{"key":"e_1_3_2_1_31_1","volume-title":"29th USENIX Security Symposium (USENIX Security 20)","author":"Mishra Pratyush","year":"2020","unstructured":"Pratyush Mishra, Ryan Lehmkuhl, Akshayaram Srinivasan, Wenting Zheng, and Raluca Ada Popa. 2020. Delphi: A cryptographic inference service for neural networks. In 29th USENIX Security Symposium (USENIX Security 20). 2505--2522."},{"key":"e_1_3_2_1_32_1","volume-title":"Jianyu Huang, Narayanan Sundaraman, Jongsoo Park, Xiaodong Wang, Udit Gupta, Carole-Jean Wu, Alisson G Azzolini, et al.","author":"Naumov Maxim","year":"2019","unstructured":"Maxim Naumov, Dheevatsa Mudigere, Hao-Jun Michael Shi, Jianyu Huang, Narayanan Sundaraman, Jongsoo Park, Xiaodong Wang, Udit Gupta, Carole-Jean Wu, Alisson G Azzolini, et al. 2019. Deep learning recommendation model for personalization and recommendation systems. arXiv preprint arXiv:1906.00091 (2019)."},{"key":"e_1_3_2_1_33_1","first-page":"27730","article-title":"Training language models to follow instructions with human feedback","volume":"35","author":"Ouyang Long","year":"2022","unstructured":"Long Ouyang, Jeffrey Wu, Xu Jiang, Diogo Almeida, Carroll Wain-wright, Pamela Mishkin, Chong Zhang, Sandhini Agarwal, Katarina Slama, Alex Ray, et al. 2022. Training language models to follow instructions with human feedback. Advances in Neural Information Processing Systems 35 (2022), 27730--27744.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_34_1","volume-title":"It's time to reveal all recommendation algorithms - by law if necessary. The Register","author":"Pesce Mark","year":"2023","unstructured":"Mark Pesce. 2023. It's time to reveal all recommendation algorithms - by law if necessary. The Register (2023). https:\/\/www.theregister.com\/2023\/04\/13\/reveal_all_recommendation_algorithms\/"},{"key":"e_1_3_2_1_35_1","unstructured":"PSE. 2023. Perpetual Powers of Tau. https:\/\/github.com\/privacy-scaling-explorations\/perpetualpowersoftau"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISCA45697.2020.00045"},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2018.00474"},{"key":"e_1_3_2_1_39_1","unstructured":"Victor Sanh Lysandre Debut Julien Chaumond and Thomas Wolf. 2019. DistilBERT a distilled version of BERT: smaller faster cheaper and lighter. In NeurIPS EMC2 Workshop."},{"key":"e_1_3_2_1_40_1","volume-title":"Confidential-PROFITT: Confidential PROof of FaIr Training of Trees. In The Eleventh International Conference on Learning Representations.","author":"Shamsabadi Ali Shahin","year":"2022","unstructured":"Ali Shahin Shamsabadi, Sierra Calanda Wyllie, Nicholas Franzese, Natalie Dullerud, S\u00e9bastien Gambs, Nicolas Papernot, Xiao Wang, and Adrian Weller. 2022. Confidential-PROFITT: Confidential PROof of FaIr Training of Trees. In The Eleventh International Conference on Learning Representations."},{"key":"e_1_3_2_1_41_1","volume-title":"3rd International Conference on Learning Representations, ICLR","author":"Simonyan Karen","year":"2015","unstructured":"Karen Simonyan and Andrew Zisserman. 2015. Very Deep Convolutional Networks for Large-Scale Image Recognition. In 3rd International Conference on Learning Representations, ICLR 2015, San Diego, CA, USA, May 7-9, 2015, Conference Track Proceedings."},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"crossref","unstructured":"Justin Thaler et al. 2022. Proofs arguments and zero-knowledge. Foundations and Trends\u00ae in Privacy and Security 4 2-4 (2022) 117--660.","DOI":"10.1561\/3300000030"},{"key":"e_1_3_2_1_43_1","unstructured":"Twitter. 2023. Twitter's Recommendation Algorithm. (2023). https:\/\/blog.twitter.com\/engineering\/en_us\/topics\/open-source\/2023\/twitter-recommendation-algorithm"},{"key":"e_1_3_2_1_44_1","volume-title":"pvCNN: Privacy-Preserving and Verifiable Convolutional Neural Network Testing. arXiv preprint arXiv:2201.09186","author":"Weng Jiasi","year":"2022","unstructured":"Jiasi Weng, Jian Weng, Gui Tang, Anjia Yang, Ming Li, and Jia-Nan Liu. 2022. pvCNN: Privacy-Preserving and Verifiable Convolutional Neural Network Testing. arXiv preprint arXiv:2201.09186 (2022)."},{"key":"e_1_3_2_1_45_1","unstructured":"zcash. 2022. halo2. https:\/\/zcash.github.io\/halo2\/"},{"key":"e_1_3_2_1_46_1","volume-title":"LQ-Nets: Learned Quantization for Highly Accurate and Compact Deep Neural Networks. In European Conference on Computer Vision (ECCV).","author":"Zhang Dongqing","year":"2018","unstructured":"Dongqing Zhang, Jiaolong Yang, Dongqiangzi Ye, and Gang Hua. 2018. LQ-Nets: Learned Quantization for Highly Accurate and Compact Deep Neural Networks. In European Conference on Computer Vision (ECCV)."},{"key":"e_1_3_2_1_47_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2017.43"}],"event":{"name":"EuroSys '24: Nineteenth European Conference on Computer Systems","location":"Athens Greece","acronym":"EuroSys '24","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the Nineteenth European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627703.3650088","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3627703.3650088","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T01:08:22Z","timestamp":1755824902000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3627703.3650088"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,22]]},"references-count":47,"alternative-id":["10.1145\/3627703.3650088","10.1145\/3627703"],"URL":"https:\/\/doi.org\/10.1145\/3627703.3650088","relation":{},"subject":[],"published":{"date-parts":[[2024,4,22]]},"assertion":[{"value":"2024-04-22","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}