Paper 2026/1557

Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification

Carter Luck, University of Massachusetts Amherst
Olive Franzese-McLaughlin, Vector Institute, University of Toronto
Elisaweta Masserova, Carnegie Mellon University
Akira Takahashi, J.P. Morgan
Antigoni Polychroniadou, J.P. Morgan
Nicolas Papernot, Vector Institute, University of Toronto
Abstract

Privacy-preserving machine learning auditing protocols allow auditors to assess models for properties such as accuracy or fairness, without revealing their internals or training data. This makes them especially attractive for auditing models deployed in sensitive domains such as healthcare or finance. For these protocols to be meaningful in real-world audit settings, though, their guarantees must reflect how the model will behave once deployed, rather than merely certifying its behavior during an audit. Existing security definitions often miss this mark: most certify model behavior only on a fixed audit dataset, without ensuring that the same guarantees generalize to other datasets drawn from the same distribution. As we show, this gap allows a model provider to attack many cryptographic model certification (CMC) schemes built on secure zero knowledge proofs (ZKP) by carefully engineering training data, resulting in models that exhibit benign behavior during an audit, but pathological behavior in practice. For example, we empirically demonstrate that an attacker can certify that a model achieves over 99% accuracy on an audit dataset, but less than 30% accuracy on fresh samples from the same distribution. To address this gap, we formalize rigorous cryptographic security notions tailored to CMC frameworks, introduce a generic protocol template, and prove that it satisfies these requirements. Our results thus offer both cautionary evidence about existing approaches and constructive guidance for designing secure, privacy-preserving ML auditing protocols.

Metadata
Available format(s)
PDF
Publication info
Published elsewhere. Major revision. USENIX Security 2026
Keywords
machine learningmodel certificationzero knowledge proofs
Contact author(s)
cartervluck @ gmail com
olive franzese @ vectorinstitute ai
elisawem @ andrew cmu edu
takahashi akira 58s @ gmail com
antigonipoly @ gmail com
nicolas papernot @ utoronto ca
History
2026-08-03: approved
2026-07-29: received
See all versions
Short URL
https://ia.cr/2026/1557
License
Creative Commons Attribution
CC BY

BibTeX

@misc{cryptoeprint:2026/1557,
      author = {Carter Luck and Olive Franzese-McLaughlin and Elisaweta Masserova and Akira Takahashi and Antigoni Polychroniadou and Nicolas Papernot},
      title = {Certified in Theory, Broken in Practice: Assumption Gaps in Cryptographic Model Certification},
      howpublished = {Cryptology {ePrint} Archive, Paper 2026/1557},
      year = {2026},
      url = {https://eprint.iacr.org/2026/1557}
}
Note: In order to protect the privacy of readers, eprint.iacr.org does not use cookies or embedded third party content.