Paper 2026/1557
Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification
Abstract
Privacy-preserving machine learning auditing protocols allow auditors to assess models for properties such as accuracy or fairness, without revealing their internals or training data. This makes them especially attractive for auditing models deployed in sensitive domains such as healthcare or finance. For these protocols to be meaningful in real-world audit settings, though, their guarantees must reflect how the model will behave once deployed, rather than merely certifying its behavior during an audit. Existing security definitions often miss this mark: most certify model behavior only on a fixed audit dataset, without ensuring that the same guarantees generalize to other datasets drawn from the same distribution. As we show, this gap allows a model provider to attack many cryptographic model certification (CMC) schemes built on secure zero knowledge proofs (ZKP) by carefully engineering training data, resulting in models that exhibit benign behavior during an audit, but pathological behavior in practice. For example, we empirically demonstrate that an attacker can certify that a model achieves over 99% accuracy on an audit dataset, but less than 30% accuracy on fresh samples from the same distribution. To address this gap, we formalize rigorous cryptographic security notions tailored to CMC frameworks, introduce a generic protocol template, and prove that it satisfies these requirements. Our results thus offer both cautionary evidence about existing approaches and constructive guidance for designing secure, privacy-preserving ML auditing protocols.
Metadata
- Available format(s)
-
PDF
- Publication info
- Published elsewhere. Major revision. USENIX Security 2026
- Keywords
- machine learningmodel certificationzero knowledge proofs
- Contact author(s)
-
cartervluck @ gmail com
olive franzese @ vectorinstitute ai
elisawem @ andrew cmu edu
takahashi akira 58s @ gmail com
antigonipoly @ gmail com
nicolas papernot @ utoronto ca - History
- 2026-08-03: approved
- 2026-07-29: received
- See all versions
- Short URL
- https://ia.cr/2026/1557
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2026/1557,
author = {Carter Luck and Olive Franzese-McLaughlin and Elisaweta Masserova and Akira Takahashi and Antigoni Polychroniadou and Nicolas Papernot},
title = {Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification},
howpublished = {Cryptology {ePrint} Archive, Paper 2026/1557},
year = {2026},
url = {https://eprint.iacr.org/2026/1557}
}