{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T13:03:56Z","timestamp":1780664636228,"version":"3.54.1"},"publisher-location":"New York, NY, USA","reference-count":56,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,26]],"date-time":"2026-04-26T00:00:00Z","timestamp":1777161600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,27]]},"DOI":"10.1145\/3767295.3803612","type":"proceedings-article","created":{"date-parts":[[2026,4,24]],"date-time":"2026-04-24T20:20:04Z","timestamp":1777062004000},"page":"1515-1532","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["TAO: Tolerance-Aware Optimistic Verification for Floating-Point Neural Networks"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-3854-9928","authenticated-orcid":false,"given":"Jianzhu","family":"Yao","sequence":"first","affiliation":[{"name":"Princeton University, Princeton, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0000-8416-0826","authenticated-orcid":false,"given":"Hongxu","family":"Su","sequence":"additional","affiliation":[{"name":"The Hong Kong University of Science and Technology (Guangzhou), Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0002-8470-1017","authenticated-orcid":false,"given":"Taobo","family":"Liao","sequence":"additional","affiliation":[{"name":"University of Illinois Urbana-Champaign, Urbana, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3397-9844","authenticated-orcid":false,"given":"Zerui","family":"Cheng","sequence":"additional","affiliation":[{"name":"Princeton University, Princeton, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-4426-9736","authenticated-orcid":false,"given":"Huan","family":"Zhang","sequence":"additional","affiliation":[{"name":"University of Illinois Urbana-Champaign, Urbana, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6918-2699","authenticated-orcid":false,"given":"Xuechao","family":"Wang","sequence":"additional","affiliation":[{"name":"The Hong Kong University of Science and Technology (Guangzhou), Guangzhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3171-8667","authenticated-orcid":false,"given":"Pramod","family":"Viswanath","sequence":"additional","affiliation":[{"name":"Princeton University, Princeton, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2026,4,26]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3620665.3640366"},{"key":"e_1_3_2_1_2_1","volume-title":"Alexey Titov, Brian Wilcox, Viktor Kolobaric, Marc Brinkmann, Oguzhan Ersoy, Ben Fielding, and Joseph Bonneau.","author":"Arun Arasu","year":"2025","unstructured":"Arasu Arun, Adam St Arnaud, Alexey Titov, Brian Wilcox, Viktor Kolobaric, Marc Brinkmann, Oguzhan Ersoy, Ben Fielding, and Joseph Bonneau. 2025. Verde: Verification via refereed delegation for machine learning programs. arXiv preprint arXiv:2502.19405 (2025)."},{"key":"e_1_3_2_1_3_1","volume-title":"Dbpedia: A nucleus for a web of open data. In international semantic web conference","author":"Auer S\u00f6ren","year":"2007","unstructured":"S\u00f6ren Auer, Christian Bizer, Georgi Kobilarov, Jens Lehmann, Richard Cyganiak, and Zachary Ives. 2007. Dbpedia: A nucleus for a web of open data. In international semantic web conference. Springer, 722\u2013735."},{"key":"e_1_3_2_1_4_1","volume-title":"Phantom: Privacy-Preserving Deep Neural Network Model Obfuscation in Heterogeneous TEE and GPU System. 34th USENIX Security Symposium.","author":"Bai Juyang","year":"2025","unstructured":"Juyang Bai, Md Hafizul Islam Chowdhuryy, Jingtao Li, Fan Yao, Chaitali Chakrabarti, and Deliang Fan. 2025. Phantom: Privacy-Preserving Deep Neural Network Model Obfuscation in Heterogeneous TEE and GPU System. 34th USENIX Security Symposium."},{"key":"e_1_3_2_1_5_1","volume-title":"Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS). 445\u2013454","author":"Canetti Ran","unstructured":"Ran Canetti, Ben Riva, and Guy N. Rothblum. 2011. Practical Delegation of Computation Using Multiple Servers. In Proceedings of the 18th ACM Conference on Computer and Communications Security (CCS). 445\u2013454."},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ic.2013.03.003"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627703.3650088"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.52202\/075280-0056"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/MICRO50266.2020.00083"},{"key":"e_1_3_2_1_10_1","volume-title":"opml: Optimistic machine learning on blockchain. arXiv preprint arXiv:2401.17555","author":"Conway KD","year":"2024","unstructured":"KD Conway, Cathie So, Xiaohang Yu, and Kartin Wong. 2024. opml: Optimistic machine learning on blockchain. arXiv preprint arXiv:2401.17555 (2024)."},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2009.5206848"},{"key":"e_1_3_2_1_12_1","volume-title":"Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies","volume":"1","author":"Devlin Jacob","year":"2019","unstructured":"Jacob Devlin, Ming-Wei Chang, Kenton Lee, and Kristina Toutanova. 2019. Bert: Pre-training of deep bidirectional transformers for language understanding. In Proceedings of the 2019 conference of the North American chapter of the association for computational linguistics: human language technologies, volume 1 (long and short papers). 4171\u20134186."},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/CloudNet62863.2024.10815750"},{"key":"e_1_3_2_1_14_1","volume-title":"Safetynets: Verifiable execution of deep neural networks on an untrusted cloud. Advances in Neural Information Processing Systems 30","author":"Ghodsi Zahra","year":"2017","unstructured":"Zahra Ghodsi, Tianyu Gu, and Siddharth Garg. 2017. Safetynets: Verifiable execution of deep neural networks on an untrusted cloud. Advances in Neural Information Processing Systems 30 (2017)."},{"key":"e_1_3_2_1_15_1","volume-title":"What every computer scientist should know about floating-point arithmetic. ACM computing surveys (CSUR) 23, 1","author":"Goldberg David","year":"1991","unstructured":"David Goldberg. 1991. What every computer scientist should know about floating-point arithmetic. ACM computing surveys (CSUR) 23, 1 (1991), 5\u201348."},{"key":"e_1_3_2_1_16_1","volume-title":"Yael Tauman Kalai, and Guy N. Rothblum","author":"Goldwasser Shafi","year":"2008","unstructured":"Shafi Goldwasser, Yael Tauman Kalai, and Guy N. Rothblum. 2008. Delegating Computation: Interactive Proofs for Muggles. In STOC. 113\u2013122."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR.2016.90"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"crossref","unstructured":"Nicholas J Higham. 2002. Accuracy and stability of numerical algorithms. SIAM.","DOI":"10.1137\/1.9780898718027"},{"key":"e_1_3_2_1_19_1","series-title":"SIAM journal on scientific computing 41, 5","volume-title":"A new approach to probabilistic rounding error analysis","author":"Higham Nicholas J","year":"2019","unstructured":"Nicholas J Higham and Theo Mary. 2019. A new approach to probabilistic rounding error analysis. SIAM journal on scientific computing 41, 5 (2019), A2815\u2013A2835."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00106"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88806-0_9"},{"key":"e_1_3_2_1_22_1","first-page":"94720","article-title":"IEEE standard 754 for binary floating-point arithmetic","volume":"754","author":"Kahan William","year":"1996","unstructured":"William Kahan. 1996. IEEE standard 754 for binary floating-point arithmetic. Lecture Notes on the Status of IEEE 754, 94720-1776 (1996), 11.","journal-title":"Lecture Notes on the Status of IEEE"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3456867"},{"key":"e_1_3_2_1_24_1","volume-title":"27th USENIX Security Symposium (USENIX Security 18)","author":"Kalodner Harry","year":"2018","unstructured":"Harry Kalodner, Steven Goldfeder, Xiaoqi Chen, S Matthew Weinberg, and Edward W Felten. 2018. Arbitrum: Scalable, private smart contracts. In 27th USENIX Security Symposium (USENIX Security 18). 1353\u20131370."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3187002"},{"key":"e_1_3_2_1_26_1","volume-title":"International Conference on Learning Representations.","author":"Madry Aleksander","year":"2018","unstructured":"Aleksander Madry, Aleksandar Makelov, Ludwig Schmidt, Dimitris Tsipras, and Adrian Vladu. 2018. Towards Deep Learning Models Resistant to Adversarial Attacks. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_27_1","volume-title":"Pointer Sentinel Mixture Models. In International Conference on Learning Representations.","author":"Merity Stephen","year":"2017","unstructured":"Stephen Merity, Caiming Xiong, James Bradbury, and Richard Socher. 2017. Pointer Sentinel Mixture Models. In International Conference on Learning Representations."},{"key":"e_1_3_2_1_28_1","volume-title":"Conference on the theory and application of cryptographic techniques. Springer, 369\u2013378","author":"Merkle Ralph C","year":"1987","unstructured":"Ralph C Merkle. 1987. A digital signature based on a conventional encryption function. In Conference on the theory and application of cryptographic techniques. Springer, 369\u2013378."},{"key":"e_1_3_2_1_29_1","volume-title":"Arbigraph: Verifiable Turing-Complete Execution Delegation. Cryptology ePrint Archive","author":"Mirkin Michael","year":"2025","unstructured":"Michael Mirkin, Hongyin Chen, Ohad Eitan, Gal Granot, and Ittay Eyal. 2025. Arbigraph: Verifiable Turing-Complete Execution Delegation. Cryptology ePrint Archive (2025)."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2025.240449"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0105"},{"key":"e_1_3_2_1_32_1","unstructured":"NVIDIA Corporation. 2024. CUDA C Programming Guide. https:\/\/docs.nvidia.com\/cuda\/cuda-c-programming-guide\/ Version 12.x."},{"key":"e_1_3_2_1_33_1","unstructured":"Optimism. 2025. Fault Proof. https:\/\/specs.optimism.io\/fault-proof\/index.html. OP Stack Specification. Accessed: 2025-09-23."},{"key":"e_1_3_2_1_34_1","unstructured":"Optimism. 2025. Multithreaded Cannon Fault Proof Virtual Machine. https:\/\/specs.optimism.io\/fault-proof\/cannon-fault-proof-vm.html. OP Stack Specification. Accessed: 2025-09-23."},{"key":"e_1_3_2_1_35_1","unstructured":"PyTorch Contributors. 2024. Reproducibility. https:\/\/docs.pytorch.org\/docs\/stable\/notes\/randomness.html. PyTorch 2.8 documentation. Last updated: 2024-11-26. Accessed: 2025-09-23."},{"key":"e_1_3_2_1_36_1","unstructured":"PyTorch Contributors. 2025. torch.fx. https:\/\/docs.pytorch.org\/docs\/main\/fx.html. PyTorch main documentation. Last updated: 2025-07-15. Accessed: 2025-09-23."},{"key":"e_1_3_2_1_37_1","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Qu Wenjie","year":"2025","unstructured":"Wenjie Qu, Yijun Sun, Xuanming Liu, Tao Lu, Yanpei Guo, Kai Chen, and Jiaheng Zhang. 2025. zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM Inference. In 34th USENIX Security Symposium (USENIX Security 25)."},{"key":"e_1_3_2_1_38_1","volume-title":"Liu","author":"Raffel Colin","year":"2019","unstructured":"Colin Raffel, Noam Shazeer, Adam Roberts, Katherine Lee, Sharan Narang, Michael Matena, Yanqi Zhou, Wei Li, and Peter J. Liu. 2019. Exploring the Limits of Transfer Learning with a Unified Text-to-Text Transformer. arXiv e-prints (2019). arXiv:1910.10683"},{"key":"e_1_3_2_1_39_1","doi-asserted-by":"publisher","DOI":"10.1109\/CVPR52688.2022.01042"},{"key":"e_1_3_2_1_40_1","volume-title":"SC24-W: Workshops of the International Conference for High Performance Computing, Networking, Storage and Analysis","author":"Shanmugavelu Sanjif","unstructured":"Sanjif Shanmugavelu, Mathieu Taillefumier, Christopher Culver, Oscar Hernandez, Mark Coletti, and Ada Sedova. 2024. Impacts of floatingpoint non-associativity on reproducibility for HPC and deep learning applications. In SC24-W: Workshops of the International Conference for High Performance Computing, Networking, Storage and Analysis. IEEE, 170\u2013179."},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.4230\/LIPIcs.AFT.2024.5"},{"key":"e_1_3_2_1_42_1","first-page":"95639","article-title":"Optimistic verifiable training by controlling hardware nondeterminism","volume":"37","author":"Srivastava Megha","year":"2024","unstructured":"Megha Srivastava, Simran Arora, and Dan Boneh. 2024. Optimistic verifiable training by controlling hardware nondeterminism. Advances in Neural Information Processing Systems 37 (2024), 95639\u201395661.","journal-title":"Advances in Neural Information Processing Systems"},{"key":"e_1_3_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670334"},{"key":"e_1_3_2_1_44_1","volume-title":"No Soundness in the Real World: On the Challenges of the Verification of Deployed Neural Networks. arXiv preprint arXiv:2506.01054","author":"Sz\u00e1sz Attila","year":"2025","unstructured":"Attila Sz\u00e1sz, Bal\u00e1zs B\u00e1nhelyi, and M\u00e1rk Jelasity. 2025. No Soundness in the Real World: On the Challenges of the Verification of Deployed Neural Networks. arXiv preprint arXiv:2506.01054 (2025)."},{"key":"e_1_3_2_1_45_1","unstructured":"Qwen Team. 2025. Qwen3 Technical Report. arXiv:2505.09388 [cs.CL] https:\/\/arxiv.org\/abs\/2505.09388"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"crossref","unstructured":"Jason Teutsch and Christian Reitwie\u00dfner. 2024. A scalable verification solution for blockchains. In Aspects of Computation and Automata Theory with Applications. World Scientific 377\u2013424.","DOI":"10.1142\/9789811278631_0015"},{"key":"e_1_3_2_1_47_1","volume-title":"Verifiable and Private Execution of Neural Networks in Trusted Hardware. In International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=rJVorjCcKQ","author":"Tramer Florian","year":"2019","unstructured":"Florian Tramer and Dan Boneh. 2019. Slalom: Fast, Verifiable and Private Execution of Neural Networks in Trusted Hardware. In International Conference on Learning Representations (ICLR). https:\/\/openreview.net\/forum?id=rJVorjCcKQ"},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0061"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274696"},{"key":"e_1_3_2_1_50_1","volume-title":"2025 USENIX Annual Technical Conference (USENIX ATC 25)","author":"Xie Peichen","year":"2025","unstructured":"Peichen Xie, Yanjie Gao, Yang Wang, and Jilong Xue. 2025. Revealing {Floating-Point} Accumulation Orders in {Software\/Hardware} Implementations. In 2025 USENIX Annual Technical Conference (USENIX ATC 25). 1425\u20131440."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISSRE.2019.00020"},{"key":"e_1_3_2_1_52_1","volume-title":"Proof of Sampling: A Nash Equilibrium-Based Verification Protocol for Decentralized Systems. arXiv preprint arXiv:2405.00295","author":"Zhang Yue","year":"2024","unstructured":"Yue Zhang, Shouqiao Wang, Sijun Tan, Xiaoyuan Liu, Ciamac C Moallemi, and Raluca Ada Popa. 2024. Proof of Sampling: A Nash Equilibrium-Based Verification Protocol for Decentralized Systems. arXiv preprint arXiv:2405.00295 (2024)."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/P2P.2005.32"},{"key":"e_1_3_2_1_54_1","first-page":"196","article-title":"Atom: Low-bit quantization for efficient and accurate llm serving","volume":"6","author":"Zhao Yilong","year":"2024","unstructured":"Yilong Zhao, Chien-Yu Lin, Kan Zhu, Zihao Ye, Lequn Chen, Size Zheng, Luis Ceze, Arvind Krishnamurthy, Tianqi Chen, and Baris Kasikci. 2024. Atom: Low-bit quantization for efficient and accurate llm serving. Proceedings of Machine Learning and Systems 6 (2024), 196\u2013209.","journal-title":"Proceedings of Machine Learning and Systems"},{"key":"e_1_3_2_1_55_1","unstructured":"Zishuo Zhao Zhixuan Fang Xuechao Wang Xi Chen Hongxu Su Haibo Xiao and Yuan Zhou. 2025. Proof-of-Learning with Incentive Security. arXiv:2404.09005 [cs.CR] https:\/\/arxiv.org\/abs\/2404.09005"},{"key":"e_1_3_2_1_56_1","volume-title":"Agatha: Smart contract for DNN computation. arXiv preprint arXiv:2105.04919","author":"Zheng Zihan","year":"2021","unstructured":"Zihan Zheng, Peichen Xie, Xian Zhang, Shuo Chen, Yang Chen, Xiaobing Guo, Guangzhong Sun, Guangyu Sun, and Lidong Zhou. 2021. Agatha: Smart contract for DNN computation. arXiv preprint arXiv:2105.04919 (2021)."}],"event":{"name":"EUROSYS '26: 21st European Conference on Computer Systems","location":"McEwan Hall\/The University of Edinburgh Edinburgh Scotland UK","acronym":"EUROSYS '26","sponsor":["SIGOPS ACM Special Interest Group on Operating Systems"]},"container-title":["Proceedings of the 21st European Conference on Computer Systems"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3767295.3803612","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,5]],"date-time":"2026-06-05T12:14:29Z","timestamp":1780661669000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3767295.3803612"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,26]]},"references-count":56,"alternative-id":["10.1145\/3767295.3803612","10.1145\/3767295"],"URL":"https:\/\/doi.org\/10.1145\/3767295.3803612","relation":{},"subject":[],"published":{"date-parts":[[2026,4,26]]},"assertion":[{"value":"2026-04-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}