Paper 2025/2211

Architecture-private Zero-knowledge Proof of Neural Networks

Yanpei Guo, National University of Singapore
Zhanpeng Guo, Xidian University
Wenjie Qu, National University of Singapore
Jiaheng Zhang, National University of Singapore
Abstract

A zero-knowledge proof of machine learning (zkML) enables a party to prove that it has correctly executed a committed model using some public input, without revealing any information about the model itself. An ideal zkML scheme should conceal both the model architecture and the model parameters. However, existing zkML approaches for neural networks primarily focus on hiding model parameters. For convolutional neural network (CNN) models, these schemes reveal the entire architecture, including number and sequence of layers, kernel sizes, strides, and residual connections. In this work, we initiate the study of architecture-private zkML for neural networks, with a focus on CNN models. Our core contributions includes 1) parametrized rank-one constraint system (pR1CS), a generalization of R1CS, allowing the prover to commit to the model architecture in a more friendly manner; 2) a proof of functional relation scheme to demonstrate the committed architecture is valid. Our scheme matches the prover complexity of BFG+23 (CCS'23), the current state-of-the-art in zkML for CNNs. Concretely, on VGG16 model, when batch proving 64 instances, our scheme achieves only 30% slower prover time than BFG+23 (CCS'23) and 2.3$\times$ faster than zkCNN (CCS'21). This demonstrates that our approach can hide the architecture in zero-knowledge proofs for neural networks with minor overhead. In particular, proving a matrix multiplication using our pR1CS can be at least 3$\times$ faster than using conventional R1CS, highlighting the effectiveness of our optimizations.

Metadata
Available format(s)
PDF
Category
Applications
Publication info
Preprint.
Contact author(s)
guo yanpei @ u nus edu
zhanp guo @ gmail com
wenjiequ @ u nus edu
jhzhang @ nus edu sg
History
2025-12-11: approved
2025-12-08: received
See all versions
Short URL
https://ia.cr/2025/2211
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2025/2211,
      author = {Yanpei Guo and Zhanpeng Guo and Wenjie Qu and Jiaheng Zhang},
      title = {Architecture-private Zero-knowledge Proof of Neural Networks},
      howpublished = {Cryptology {ePrint} Archive, Paper 2025/2211},
      year = {2025},
      url = {https://eprint.iacr.org/2025/2211}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.