Paper 2026/1356
Spain: Succinct proofs for numerical computations
Abstract
In a succinct proof protocol, a verifier gets assurance that an untrusted prover executed an agreed computation, without requiring the verifier to re-execute the computation itself. In little more than a decade, this area has undergone a remarkable transformation from theory to implemented systems. This activity is extremely exciting. But there is a catch. To apply succinct proofs, one needs to translate one's computation to a set of equations, or constraints. The required translation has so far completely blocked systematic support for numerical computations, namely those for which the bulk of the computation uses approximations of real numbers. This paper fills that void with the design, implementation, and evaluation of a system called Spain. The starting insight of Spain is that since numerical computations inherently have approximation error, the constraint formalism should likewise allow for approximate satisfiability. Based on this insight, Spain introduces a new proof protocol and new ways to translate computations to constraints. Spain's implementation improves over natural baselines by multiple orders of magnitude.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- Published elsewhere. OSDI'26
- Keywords
- probabilistic proofsinteractive proofsoutsourced computationverifiable computationR1CSfloating-point
- Contact author(s)
-
zd @ nyu edu
nmg8962 @ nyu edu
zh3083 @ nyu edu
hz2166 @ nyu edu
sff5097 @ nyu edu
mw155 @ nyu edu - History
- 2026-07-03: approved
- 2026-07-01: received
- See all versions
- Short URL
- https://ia.cr/2026/1356
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1356,
author = {Zachary DeStefano and Noah Golub and Zile Huang and Julius Zhang and Sam Frank and Michael Walfish},
title = {Spain: Succinct proofs for numerical computations},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1356},
year = {2026},
url = {https://eprint.iacr.org/2026/1356}
}