{"id":"https://openalex.org/W7139923894","doi":"https://doi.org/10.48550/arxiv.2603.19025","title":"Towards Verifiable AI with Lightweight Cryptographic Proofs of Inference","display_name":"Towards Verifiable AI with Lightweight Cryptographic Proofs of Inference","publication_year":2026,"publication_date":"2026-03-19","ids":{"openalex":"https://openalex.org/W7139923894","doi":"https://doi.org/10.48550/arxiv.2603.19025"},"language":null,"primary_location":{"id":"doi:10.48550/arxiv.2603.19025","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.19025","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"type":"preprint","indexed_in":["datacite"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://doi.org/10.48550/arxiv.2603.19025","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5049556814","display_name":"Pranay Anchuri","orcid":"https://orcid.org/0000-0003-4377-5036"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Anchuri, Pranay","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5007176053","display_name":"Matteo Campanelli","orcid":"https://orcid.org/0000-0001-8184-4704"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Campanelli, Matteo","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5072037854","display_name":"Paul Cesaretti","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Cesaretti, Paul","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5013831409","display_name":"Rosario Gennaro","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Gennaro, Rosario","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5027680930","display_name":"Tushar M. Jois","orcid":"https://orcid.org/0000-0002-2740-8407"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Jois, Tushar M.","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"middle","author":{"id":"https://openalex.org/A5130246879","display_name":"Hasan S. Kayman","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Kayman, Hasan S.","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]},{"author_position":"last","author":{"id":"https://openalex.org/A5130222021","display_name":"Tugce Ozdemir","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Ozdemir, Tugce","raw_affiliation_strings":[],"raw_orcid":null,"affiliations":[]}],"institutions":[],"countries_distinct_count":0,"institutions_distinct_count":7,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":null,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":null,"cited_by_percentile_year":null,"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7476999759674072,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11689","display_name":"Adversarial Robustness in Machine Learning","score":0.7476999759674072,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10237","display_name":"Cryptography and Data Security","score":0.09440000355243683,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10764","display_name":"Privacy-Preserving Technologies in Data","score":0.04899999871850014,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/verifiable-secret-sharing","display_name":"Verifiable secret sharing","score":0.722100019454956},{"id":"https://openalex.org/keywords/soundness","display_name":"Soundness","score":0.6402000188827515},{"id":"https://openalex.org/keywords/cryptographic-protocol","display_name":"Cryptographic protocol","score":0.5843999981880188},{"id":"https://openalex.org/keywords/cryptography","display_name":"Cryptography","score":0.5834000110626221},{"id":"https://openalex.org/keywords/cryptographic-primitive","display_name":"Cryptographic primitive","score":0.5663999915122986},{"id":"https://openalex.org/keywords/gas-meter-prover","display_name":"Gas meter prover","score":0.5536999702453613},{"id":"https://openalex.org/keywords/protocol","display_name":"Protocol (science)","score":0.54830002784729},{"id":"https://openalex.org/keywords/mathematical-proof","display_name":"Mathematical proof","score":0.5353999733924866}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7605000138282776},{"id":"https://openalex.org/C85847156","wikidata":"https://www.wikidata.org/wiki/Q59015987","display_name":"Verifiable secret sharing","level":3,"score":0.722100019454956},{"id":"https://openalex.org/C39920170","wikidata":"https://www.wikidata.org/wiki/Q693083","display_name":"Soundness","level":2,"score":0.6402000188827515},{"id":"https://openalex.org/C33884865","wikidata":"https://www.wikidata.org/wiki/Q1254335","display_name":"Cryptographic protocol","level":3,"score":0.5843999981880188},{"id":"https://openalex.org/C178489894","wikidata":"https://www.wikidata.org/wiki/Q8789","display_name":"Cryptography","level":2,"score":0.5834000110626221},{"id":"https://openalex.org/C15927051","wikidata":"https://www.wikidata.org/wiki/Q246593","display_name":"Cryptographic primitive","level":4,"score":0.5663999915122986},{"id":"https://openalex.org/C159718280","wikidata":"https://www.wikidata.org/wiki/Q5526353","display_name":"Gas meter prover","level":3,"score":0.5536999702453613},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.5530999898910522},{"id":"https://openalex.org/C2780385302","wikidata":"https://www.wikidata.org/wiki/Q367158","display_name":"Protocol (science)","level":3,"score":0.54830002784729},{"id":"https://openalex.org/C108710211","wikidata":"https://www.wikidata.org/wiki/Q11538","display_name":"Mathematical proof","level":2,"score":0.5353999733924866},{"id":"https://openalex.org/C55439883","wikidata":"https://www.wikidata.org/wiki/Q360812","display_name":"Correctness","level":2,"score":0.5228000283241272},{"id":"https://openalex.org/C2779960059","wikidata":"https://www.wikidata.org/wiki/Q7113681","display_name":"Overhead (engineering)","level":2,"score":0.47290000319480896},{"id":"https://openalex.org/C2776214188","wikidata":"https://www.wikidata.org/wiki/Q408386","display_name":"Inference","level":2,"score":0.445499986410141},{"id":"https://openalex.org/C75291252","wikidata":"https://www.wikidata.org/wiki/Q1315756","display_name":"TRACE (psycholinguistics)","level":2,"score":0.4108000099658966},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.3246000111103058},{"id":"https://openalex.org/C6943359","wikidata":"https://www.wikidata.org/wiki/Q875276","display_name":"Boolean satisfiability problem","level":2,"score":0.29319998621940613},{"id":"https://openalex.org/C120314980","wikidata":"https://www.wikidata.org/wiki/Q180634","display_name":"Distributed computing","level":1,"score":0.2903999984264374},{"id":"https://openalex.org/C134261354","wikidata":"https://www.wikidata.org/wiki/Q938438","display_name":"Statistical inference","level":2,"score":0.27320000529289246},{"id":"https://openalex.org/C206880738","wikidata":"https://www.wikidata.org/wiki/Q431667","display_name":"Automated theorem proving","level":2,"score":0.27090001106262207},{"id":"https://openalex.org/C97399411","wikidata":"https://www.wikidata.org/wiki/Q825367","display_name":"Coin flipping","level":2,"score":0.2535000145435333},{"id":"https://openalex.org/C93996380","wikidata":"https://www.wikidata.org/wiki/Q44127","display_name":"Server","level":2,"score":0.2508000135421753},{"id":"https://openalex.org/C164155591","wikidata":"https://www.wikidata.org/wiki/Q2067766","display_name":"Satisfiability modulo theories","level":2,"score":0.2506999969482422}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.48550/arxiv.2603.19025","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.19025","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":null,"raw_source_name":null,"raw_type":"article"}],"best_oa_location":{"id":"doi:10.48550/arxiv.2603.19025","is_oa":true,"landing_page_url":"https://doi.org/10.48550/arxiv.2603.19025","pdf_url":null,"source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"article"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions","score":0.6009598970413208}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":0,"referenced_works":[],"related_works":[],"abstract_inverted_index":{"When":[0],"large":[1,30],"AI":[2],"models":[3,92],"are":[4,15],"deployed":[5],"as":[6],"cloud-based":[7],"services,":[8],"clients":[9],"have":[10],"no":[11],"guarantee":[12],"that":[13,64,137,205,216,230],"responses":[14],"correct":[16,248],"or":[17],"were":[18],"produced":[19],"by":[20,172],"the":[21,83,98,108,185,190,209,239],"intended":[22],"model.":[23],"Rerunning":[24],"inference":[25,102,112],"locally":[26],"is":[27],"infeasible":[28],"for":[29,54,140],"models,":[31],"and":[32,62,117,156,202,215],"existing":[33],"cryptographic":[34,67,180],"proof":[35,181],"systems":[36],"--":[37,43],"while":[38],"providing":[39],"strong":[40],"correctness":[41],"guarantees":[42],"introduce":[44],"prohibitive":[45],"prover":[46,105],"overhead":[47],"(e.g.,":[48],"hundreds":[49],"of":[50,78,100,111,123,175,187,192,255],"seconds":[51],"per":[52],"query":[53],"billion-parameter":[55],"models).":[56],"We":[57,81,233],"present":[58,235],"a":[59,70,120,135,142,236,252],"verification":[60],"framework":[61],"protocol":[63,136,213,237],"replaces":[65],"full":[66],"proofs":[68],"with":[69,158,194],"lightweight,":[71],"sampling-based":[72],"approach":[73,168],"grounded":[74],"in":[75,238,251],"statistical":[76,210],"properties":[77,211],"neural":[79],"networks.":[80],"formalize":[82],"conditions":[84],"under":[85],"which":[86],"trace":[87,110],"separation":[88],"between":[89],"functionally":[90],"dissimilar":[91],"can":[93],"be":[94],"leveraged":[95],"to":[96,107,131,145,178,189,227],"argue":[97],"security":[99],"verifiable":[101],"protocols.":[103],"The":[104],"commits":[106],"execution":[109],"via":[113],"Merkle-tree-based":[114],"vector":[115],"commitments":[116],"opens":[118],"only":[119],"small":[121],"number":[122,254],"entries":[124],"along":[125],"randomly":[126],"sampled":[127],"paths":[128],"from":[129,184],"output":[130,249],"input.":[132],"This":[133],"yields":[134],"trades":[138],"soundness":[139],"efficiency,":[141],"tradeoff":[143],"well-suited":[144],"auditing,":[146],"large-scale":[147],"deployment":[148],"settings":[149],"where":[150,243],"repeated":[151],"queries":[152],"amplify":[153],"detection":[154],"probability,":[155],"scenarios":[157],"rationally":[159],"incentivized":[160],"provers":[161],"who":[162],"face":[163],"penalties":[164],"upon":[165],"detection.":[166,232],"Our":[167],"reduces":[169],"proving":[170],"times":[171],"several":[173],"orders":[174],"magnitude":[176],"compared":[177],"state-of-the-art":[179],"systems,":[182],"going":[183],"order":[186,191],"minutes":[188],"milliseconds,":[193],"moderately":[195],"larger":[196],"proofs.":[197],"Experiments":[198],"on":[199],"ResNet-18":[200],"classifiers":[201],"Llama-2-7B":[203],"confirm":[204],"common":[206],"architectures":[207],"exhibit":[208],"our":[212],"requires,":[214],"natural":[217],"adversarial":[218],"strategies":[219],"(gradient-descent":[220],"reconstruction,":[221],"inverse":[222],"transforms,":[223],"logit":[224],"swapping)":[225],"fail":[226],"produce":[228],"traces":[229],"evade":[231],"additionally":[234],"refereed":[240],"delegation":[241],"model,":[242],"two":[244],"competing":[245],"servers":[246],"enable":[247],"identification":[250],"logarithmic":[253],"rounds.":[256]},"counts_by_year":[],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2026-03-21T00:00:00"}
