{"id":"https://openalex.org/W3197909455","doi":"https://doi.org/10.1145/3460120.3485379","title":"zkCNN: Zero Knowledge Proofs for Convolutional Neural Network Predictions and Accuracy","display_name":"zkCNN: Zero Knowledge Proofs for Convolutional Neural Network Predictions and Accuracy","publication_year":2021,"publication_date":"2021-11-12","ids":{"openalex":"https://openalex.org/W3197909455","doi":"https://doi.org/10.1145/3460120.3485379","mag":"3197909455"},"language":"en","primary_location":{"id":"doi:10.1145/3460120.3485379","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3460120.3485379","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},"type":"preprint","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100430611","display_name":"Tianyi Liu","orcid":"https://orcid.org/0000-0003-1540-5177"},"institutions":[{"id":"https://openalex.org/I91045830","display_name":"Texas A&M University","ror":"https://ror.org/01f5ytq51","country_code":"US","type":"education","lineage":["https://openalex.org/I91045830"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Tianyi Liu","raw_affiliation_strings":["Texas A&amp;M University &amp; Shanghai Key Laboratory of Privacy-Preserving Computation, College Station, TX, USA","Texas A&M University & Shanghai Key Laboratory of Privacy-Preserving Computation, College Station, TX, USA"],"affiliations":[{"raw_affiliation_string":"Texas A&amp;M University &amp; Shanghai Key Laboratory of Privacy-Preserving Computation, College Station, TX, USA","institution_ids":["https://openalex.org/I91045830"]},{"raw_affiliation_string":"Texas A&M University & Shanghai Key Laboratory of Privacy-Preserving Computation, College Station, TX, USA","institution_ids":["https://openalex.org/I91045830"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034405994","display_name":"Xiang Xie","orcid":"https://orcid.org/0000-0001-5044-9576"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xiang Xie","raw_affiliation_strings":["Shanghai Key Laboratory of Privacy-Preserving Computation, Shanghai, China"],"affiliations":[{"raw_affiliation_string":"Shanghai Key Laboratory of Privacy-Preserving Computation, Shanghai, China","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100434296","display_name":"Yupeng Zhang","orcid":"https://orcid.org/0000-0003-0378-3146"},"institutions":[{"id":"https://openalex.org/I91045830","display_name":"Texas A&M University","ror":"https://ror.org/01f5ytq51","country_code":"US","type":"education","lineage":["https://openalex.org/I91045830"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Yupeng Zhang","raw_affiliation_strings":["Texas A&amp;M University, College Station, TX, USA","[Texas A&M University, College station, TX, USA]"],"affiliations":[{"raw_affiliation_string":"Texas A&amp;M University, College Station, TX, USA","institution_ids":["https://openalex.org/I91045830"]},{"raw_affiliation_string":"[Texas A&M University, College station, TX, USA]","institution_ids":["https://openalex.org/I91045830"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5100430611"],"corresponding_institution_ids":["https://openalex.org/I91045830"],"apc_list":null,"apc_paid":null,"fwci":0.5644143,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.72868077,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":96},"biblio":{"volume":"2021","issue":null,"first_page":"2968","last_page":"2985"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10036","display_name":"Advanced Neural Network Applications","score":0.9970999956130981,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11612","display_name":"Stochastic Gradient Optimization Techniques","score":0.9890000224113464,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/mathematical-proof","display_name":"Mathematical proof","score":0.8164538145065308},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.804567277431488},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.7642977237701416},{"id":"https://openalex.org/keywords/gas-meter-prover","display_name":"Gas meter prover","score":0.697583794593811},{"id":"https://openalex.org/keywords/pooling","display_name":"Pooling","score":0.6373456120491028},{"id":"https://openalex.org/keywords/scheme","display_name":"Scheme (mathematics)","score":0.578073263168335},{"id":"https://openalex.org/keywords/deep-learning","display_name":"Deep learning","score":0.4824872314929962},{"id":"https://openalex.org/keywords/zero-knowledge-proof","display_name":"Zero-knowledge proof","score":0.4822412431240082},{"id":"https://openalex.org/keywords/artificial-neural-network","display_name":"Artificial neural network","score":0.46137890219688416},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4350019693374634},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.40743425488471985},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3995212912559509},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.17106658220291138},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.12465420365333557}],"concepts":[{"id":"https://openalex.org/C108710211","wikidata":"https://www.wikidata.org/wiki/Q11538","display_name":"Mathematical proof","level":2,"score":0.8164538145065308},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.804567277431488},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.7642977237701416},{"id":"https://openalex.org/C159718280","wikidata":"https://www.wikidata.org/wiki/Q5526353","display_name":"Gas meter prover","level":3,"score":0.697583794593811},{"id":"https://openalex.org/C70437156","wikidata":"https://www.wikidata.org/wiki/Q7228652","display_name":"Pooling","level":2,"score":0.6373456120491028},{"id":"https://openalex.org/C77618280","wikidata":"https://www.wikidata.org/wiki/Q1155772","display_name":"Scheme (mathematics)","level":2,"score":0.578073263168335},{"id":"https://openalex.org/C108583219","wikidata":"https://www.wikidata.org/wiki/Q197536","display_name":"Deep learning","level":2,"score":0.4824872314929962},{"id":"https://openalex.org/C176329583","wikidata":"https://www.wikidata.org/wiki/Q191943","display_name":"Zero-knowledge proof","level":3,"score":0.4822412431240082},{"id":"https://openalex.org/C50644808","wikidata":"https://www.wikidata.org/wiki/Q192776","display_name":"Artificial neural network","level":2,"score":0.46137890219688416},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4350019693374634},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.40743425488471985},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3995212912559509},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.17106658220291138},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.12465420365333557},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1145/3460120.3485379","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3460120.3485379","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2021 ACM SIGSAC Conference on Computer and Communications Security","raw_type":"proceedings-article"},{"id":"mag:3197909455","is_oa":false,"landing_page_url":"https://eprint.iacr.org/2021/673.pdf","pdf_url":null,"source":{"id":"https://openalex.org/S2764847869","display_name":"IACR Cryptology ePrint Archive","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":["https://openalex.org/P4322614454"],"host_organization_lineage_names":["Cryptology ePrint Archive"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"IACR Cryptology ePrint Archive","raw_type":null}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Partnerships for the goals","id":"https://metadata.un.org/sdg/17","score":0.4300000071525574}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":22,"referenced_works":["https://openalex.org/W1599026900","https://openalex.org/W2049982182","https://openalex.org/W2071520502","https://openalex.org/W2082647621","https://openalex.org/W2112796928","https://openalex.org/W2171337840","https://openalex.org/W2475905526","https://openalex.org/W2496543269","https://openalex.org/W2515122689","https://openalex.org/W2536319456","https://openalex.org/W2676157184","https://openalex.org/W2765206040","https://openalex.org/W2766710082","https://openalex.org/W2794536744","https://openalex.org/W2883585522","https://openalex.org/W2954625838","https://openalex.org/W2963122961","https://openalex.org/W2964279767","https://openalex.org/W2968027060","https://openalex.org/W2982474429","https://openalex.org/W3015343560","https://openalex.org/W3097836574"],"related_works":["https://openalex.org/W2967526509","https://openalex.org/W3176862352","https://openalex.org/W3022540164","https://openalex.org/W3007108375","https://openalex.org/W2970297683","https://openalex.org/W3087293054","https://openalex.org/W3037838205","https://openalex.org/W3105170486","https://openalex.org/W3006898349","https://openalex.org/W1908861217","https://openalex.org/W3198519141","https://openalex.org/W3010768098","https://openalex.org/W1526092162","https://openalex.org/W3042924862","https://openalex.org/W2283732559","https://openalex.org/W3209192622","https://openalex.org/W3164074916","https://openalex.org/W3091477414","https://openalex.org/W2325237720","https://openalex.org/W5947967"],"abstract_inverted_index":{"Deep":[0],"learning":[1,56],"techniques":[2],"with":[3,44,145,202],"neural":[4,42,75],"networks":[5,43,76],"are":[6,37],"developing":[7],"prominently":[8],"in":[9,16,23,62,192],"recent":[10],"years":[11],"and":[12,143,164,183,206,231],"have":[13],"been":[14],"deployed":[15],"numerous":[17],"applications.":[18],"Despite":[19],"their":[20],"great":[21],"success,":[22],"many":[24],"scenarios":[25],"it":[26],"is":[27,48,98,133,151,189,219,228,235],"important":[28],"for":[29,73,138,170],"the":[30,35,52,81,84,92,102,109,120,156,167,175,178,184,197,216,232,246,249],"users":[31],"to":[32,50,87,89,118,214,244],"validate":[33],"that":[34,91],"inferences":[36],"truly":[38],"computed":[39],"by":[40,101],"legitimate":[41],"high":[45],"accuracy,":[46],"which":[47,150,218],"referred":[49],"as":[51],"integrity":[53],"of":[54,83,94,122,181,200,248],"machine":[55],"predictions.":[57],"To":[58],"address":[59],"this":[60,63],"issue,":[61],"paper,":[64],"we":[65],"propose":[66],"zkCNN,":[67],"a":[68,95,123,128,134,146],"zero":[69],"knowledge":[70],"proof":[71,226],"scheme":[72,79,113,188,240],"convolutional":[74,176],"(CNN).":[77],"The":[78,225],"allows":[80],"owner":[82],"CNN":[85,125,171,199,251],"model":[86,110,126],"prove":[88,119,245],"others":[90],"prediction":[93],"data":[96],"sample":[97],"indeed":[99],"calculated":[100],"model,":[103],"without":[104],"leaking":[105],"any":[106],"information":[107],"about":[108],"itself.":[111],"Our":[112,187,239],"can":[114,195,241],"also":[115,160],"be":[116],"generalized":[117],"accuracy":[121,247],"secret":[124],"on":[127,166,252],"public":[129],"dataset.":[130],"Underlying":[131],"zkCNN":[132],"new":[135],"sumcheck":[136],"protocol":[137],"proving":[139],"fast":[140],"Fourier":[141],"transforms":[142],"convolutions":[144],"linear":[147],"prover":[148],"time,":[149],"even":[152],"faster":[153,221],"than":[154,222],"computing":[155],"result":[157],"asymptotically.":[158],"We":[159],"introduce":[161],"several":[162],"improvements":[163],"generalizations":[165],"interactive":[168],"proofs":[169],"predictions,":[172],"including":[173],"verifying":[174],"layer,":[177],"activation":[179],"function":[180],"ReLU":[182],"max":[185],"pooling.":[186],"highly":[190],"efficient":[191],"practice.":[193],"It":[194,209],"support":[196],"large":[198],"VGG16":[201],"15":[203],"million":[204],"parameters":[205],"16":[207],"layers.":[208],"only":[210,236],"takes":[211],"88.3":[212],"seconds":[213],"generate":[215],"proof,":[217],"1264\u00d7":[220],"existing":[223],"schemes.":[224],"size":[227],"341":[229],"kilobytes,":[230],"verifier":[233],"time":[234],"59.3":[237],"milliseconds.":[238],"further":[242],"scale":[243],"same":[250],"20":[253],"images.":[254]},"counts_by_year":[{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":2}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
