Private Machine Learning with ZKML - Laurence Kirk | Extropy.IO
ETH Belgrade Community·Tue, Oct 7, 2025, 12:00 AM
Speaker
Private Machine Learning with ZKML - Laurence Kirk | Extropy.IO
Transcript
Thank you for inviting me. Uh just wanted to say actually that the previous talk I thought was great a really good call for action around privacy. I'm going to sort of move along in that direction a little bit and talk particularly around about zero knowledge proofs uh and then how they can be applied to machine learning. Now the uh notes for this are available. Hopefully you'll be able to scan that.
That will take you to this uh website maths.xp.io. There's links in that to a number of talks. So you get lots of uh talks about other things about maths etc.
Um but uh for this talk I've actually got far more than I'm going to be able to cover. So I'm going to skip through uh some parts of it. And it is intended as a really an introduction. Um and what I want to talk about um is really what is ZKML itself and what challenges do we face with it? What frameworks are out there to help us build using that?
What is the sort of the state-of-the-art? What are the latest developments? And if you're interested, why you can go from here? What what you can do? As I say, it's a general gentle introduction.
Uh so um some of the the notes you'll see are get quite complex but I'm going to skip through a lot of those and really just concentrate on the beginning part. Okay. So uh machine learning. So that's an aspect of artificial intelligence. Fortunately I'm sure you're all very familiar with machine learning.
You've probably all used large language models yourselves. So I don't have to say too much about it. One point uh I need to talk about though is that there are two uh two parts I want to talk about with machine learning or two processes. The first one is the idea where we train a machine learning model to do something. Uh and then the second part that once we have that trained model then we can use it.
So when you're using your large language model your you know chat GPT etc it's already been trained and you are uh using it with its uh configuration already in place. And that's when you're doing that when you're using it with once it's trained that is called the inference stage uh of machine learning. So yeah I talked about the idea of this model. So this is something that is going to be trained uh on some input data and hopefully it's going to be able to generalize. It should be able to uh uh be trained to take on on training data and then be able to apply that and uh do something useful with new data which is really what we want.
um this can be a very uh involved process. The training in terms of computation is much uh greater than is needed when we do the inference stage when we're actually using uh these parts. So um in terms of the components, many uh machine learning models are built of neural networks uh and they're built in layers. So we have uh we'll start off with an input layer. uh we'll have these things called hidden layers and there will be many many of these and then we have some output and what the training is doing is setting up the links between the the nodes within these layers and setting up the the weights uh that they're uh within those layers.
Uh more particularly uh it looks like this. You have inputs coming in the each of the the nodes in the network will have weights. They are then as you are doing the inference stage those are multiplied by the inputs we then come to the the sum of all of those we then run a function over that called the activation function and for each node in the the network. So for each one of these circles it will then decide whether it's going to pass on an output to the next layer or not. Okay this is very much simplifying things.
Um also we have the possibility of doing bias as well. So this is something that doesn't depend on the input but it's kind of tweaking one of these nodes to uh to change its value. All right. Now uh in terms of the size of these things the large language models we have now are huge. Uh so in if you think of those weights so each of the the inputs going to the next layer has a has a weight.
uh with large language models now uh they are running with hundreds of billions or even trillions of weights and the number of layers is hundreds of layers. So these things are absolutely huge but they are very uh very useful. They they seem to work very well. All right. So uh but we're concerned with privacy.
Uh why would we want that with machine learning? What's the point? Um, so maybe we will have some uh confidential data that we're using for training. So we want privacy around that. Maybe the the actual parameters when we've trained this model, maybe those parameters have business value and you don't you wouldn't want other people to to know how you've trained your model and the the the result of that training.
And then also when we're using the model, the input that you're providing to the large language model or whatever type of machine learning that could also be confidential. Now I won't ask for a show of hands, but I imagine you know you've you've probably used things like chat GPT. You've typed in a prompt. Uh most people will do that and really not care what happens to that information that they send in there. But some people do uh may worry about that.
Of course, it depends on the data. um you you'll probably be happy asking uh it to to write a small piece of code for you and doing a very simple prompt. But then if you start to put in information that could be confidential or have business value, then we start to see that privacy can be important. Um so what what can we do? Well, we could just run uh do everything locally.
We could just do everything in private um which will be possible and then you're you're guaranteed uh to have privacy. Uh and in fact this kind of comes back to some of the questions from the the last talk about how can we get privacy in blockchains. There are blockchains that do this that do offchain computation. Um but we could do that anyway with our large language model. But what if we want to be able to share the model in some way or maybe we want to be able to share the training of the model.
We may want our model to be trained using the experience that other people have had in other models. And is that possible to do? and I'm going to uh answer these questions. Okay, so zero knowledge proofs uh I'm going to skip through a lot of this but basically they allow us to do some uh verifiable computation and the important part is that having done some computation come up with a result we can verify that is correct and do that succinctly much more quickly than it would take to do the whole computation again otherwise there wouldn't be any point that's uh one aspect of them the other aspect is that we can do computation over private inputs. So I could do some computation using some private data.
I could send the result of that to someone uh assuming that I don't mind them seeing the result. Uh and I could also send them a proof that that computation had been done correctly and they wouldn't be able to reverse engineer it or find out what the inputs were. Okay. Uh I'm going to skip through uh more details about those. Uh this is just showing some of the different types of frameworks.
uh zero knowledge proving systems we have we have starks and snarks etc. Um there's a great article, the Cambrian Explosion. Do do take a look at that. All right, so ZKML, is this really anything more than just getting some buzzwords and putting them together? We've got ZK, which is very popular.
We've got machine learning. We've just put these things together. Does it actually give us anything? Well, yes, it does. So, we can do computation and verify that.
So maybe we can verify some of the computation that is being done within the the machine learning but also perhaps we can do machine learning with some privacy as well and uh still get results that can be verified. And I've got some uh potential use cases here. There's there are lots uh really any any way or anywhere that you would want some privacy um then that could be used things like private KYC so for for financial systems uh identity systems where you want some kind of differential privacy um lots of applications in DeFi health care obviously because we want to have uh patient data being kept confidential etc. Uh this diagram here represents uh this is a little bit old but it does represent uh some of the ecosystem in ZKML as it has developed. Uh not all of these things are still around though but I will be mentioning some mentioning some of them.
Certainly on the hardware side there's quite a lot going on. Uh there are companies building special chips to do uh ZK uh and cryptography uh and do that very efficiently and very fast and that's being used for ZKML as well. Um, we see some very interesting use cases. I don't know if people are familiar with Worldcoin. Uh, not don't think they're here, but you often see them at conferences.
Uh, they have an orb that will uh scan your retina and it allows them to create an ID, but it allows um to keep the biometric information private. Okay. Now, um challenges. So, machine learning that's just some computation. We we've trained our model.
We're going to run that model against some inputs. That's just doing some computation, some sums, etc. doing the activation function. ZK is good at proving computation. So, it should be a piece of cake just to put these things together and get the ZK to to verify that computation.
Unfortunately, it's not the case. And this comes the well, one two two main reasons. One is complexity. They're both very complex areas. So you know getting them uh making sure they're working correctly is not trivial.
But the biggest problem we really have is to do with the underlying mathematics uh that these depend upon. So machine learning uh involves creating large matrices doing lots of floatingoint operations using floatingoint numbers doing sort of everyday maths. Zero knowledge proofs are much more restricted. When we do zero knowledge proofs, we restrict the types of numbers that we use. We operate uh on integers.
We uh operate on what are called finite fields. So these are sets of integers that have a maximum value. This means we do modular arithmetic. The the zero proofs work but only because we are restricting ourselves in the type of maths. So when we try to put these two things together, we've got a major problem that uh we the underlying representation uh is not the same for both of them.
Um one way you can get around that I just mentioning here that the idea of quantization, you could have a floatingoint number and you could effectively multiply that up until it becomes an integer. As long as you remember how much you've multiplied it, then that would work. So we could do that but obviously that's an extra layer that we're adding to the whole system uh and that is affecting the the performance of it. You can do quantization generally where you just kind of miss off some of the precision. Uh and in machine learning that does happen but then your machine learning model doesn't end up working as well as it could do.
So that that's a problem. Uh another point is determinism. Zero knowledge proofs uh have to be completely deterministic. they have to have exactly uh the same results no matter who does it or where or uh yeah for the for the proof to be valid with uh machine learning. Now in a way they are deterministic but the way that they are used they often introduce randomness.
So for example when you if you're using things to generate images uh they often use randomness uh within that and ZK really doesn't like the idea of randomness. It doesn't work well with that. And I just want to say I really like this uh this final quote here. Um reality has a surprising amount of detail. I think that's a a great thing to bear in mind.
Okay. So um with ZKML people are trying to do this. So I'm not I don't want to be too um pessimistic. Um it's not hopeless. So people are making progress.
Uh but where we're doing that is on the inference stage, the training stage because that is so computationally complex. uh that's still very difficult to do and create proofs of just because it takes so long. Okay. What what would it look like then um if we do some ZKML and why would where would you use this? Well, this is uh a diagram from uh a ZKML framework called Tensor Plan and the idea behind it is is that we have someone who wants to use a machine learning model.
they're the consumer and they are providing an input X and they're outsourcing the machine learning to somebody else. So they're relying on somebody to do the machine learning for them that that person takes that uh you know has the weights in their model uh that takes the input that our consumer has done and creates some output. But with ZKML we can also create a proof and we can create a proof of how that computation was done and we can prove things like did they use the the correct model. If you send off your uh data to run through a machine learning model then maybe they will use the the best model but maybe they will use some cheap model and all that kind of thing. So you want to know you know that it's been done correctly.
So once we have that proof and the output that can go back to the consumer and they can check then very quickly that the machine learning was done correctly. Um how do we actually do this and can we easily model something like a neural network uh in in zero knowledge? If you do it in a very naive approach and the way that we've used zero knowledge generally uh it's very difficult. Okay. Um so we have to do a number of tweaks.
Uh I'm going to have to to skip through uh a lot of this, but we we can tweak the way that we do ZK to try to make it more machine learning friendly. Another way another uh way we can do it is to use recursion uh use recursive proofs. That works kind of nicely because we have all these layers and you can recursively go through the layers of a neural network. So that's that's one approach that is useful. Um if you're looking to build something with uh ZKML, one of the best frameworks uh one of the best libraries is Ezekiel uh which allows you to do that.
You can take an existing large sorry an existing model machine learning model uh maybe you've written that uh in tensorflow something like that uh and then you can use the Ezekiel library to uh create zero knowledge proofs from that. So this is this is one of the um I think the yeah most practical ways that we can do this at the moment. Um I won't say much more about that other than it uh you to do this you have to put the model in a standard format which is the the onyx format. Okay. Um I'm just going to skip through uh the rest of it.
uh some of the latest research people have done this was a project where because we have this problem of weights within the model people have worked out ways to do machine learning without weights and that's what we have with zero gravity uh also uh let me go on um yeah I'll just mention this also this happened last year um so we had this view that uh it's too complex we can't do zkml uh easily but this last year Um people have done this. They did manage to prove uh GPT2 which is an earlier version but it had more than a billion weights and they managed to get that to they managed to create a proof from that. The actual proof itself uh well they it took 90 hours to set up the system and then the proof itself took 90 hours to to compute. So it's not great performance but they managed to do it. So that was a a step forward.
Okay. Um, another approach has been used, GKR. I'm not not going to talk about that. That gets quite complex. Um, but we have, yeah, people doing so ZKDL, people are building special tweaks and changing the way we do ZK to work better with machine learning.
So, there's lots of links here in uh, to papers to show you how that can be done. Uh, also, Nethermind have come up with this uh, ZK system called zinc which doesn't rely on integers. So it changes the maths that we use in ZK. So we can use rational numbers. So that's something else that that can help.
Um the other approaches, there's optimistic machine learning. I won't go into that. Uh federated machine learning. These are other approaches. Uh but finally, I've got some links for you if you want to find out more.
Worldcoin that I mentioned earlier, they have great resources. There's links there to their introduction. Um the zero knowledge podcast is always good for anything in zero knowledge but also ZKML. Um there's links there to lots of different projects. Um we are also we we run courses and we have uh an academy that's just starting.
This is going to be some online courses that you will be able to do. Um if you find me uh here tomorrow, I'll can give you a discount code for uh those courses as well. All right, I think I'm probably out of time. So thank you very much for your attention and happy to answer some questions. So do we have Yeah, there is a questions over there.
Thank you for your presentation. And uh I have a question regarding um application of ZK proving or any kind of proving in uh machine learning. How far are we from real implementation? What are your thoughts about that?
Well uh we we can do this. So for example with Ezekiel you can do that. You can take some models uh that you've written just using standard machine learning and create proofs from that. uh but at the moment we're just the problem is performance. It just takes a long time to to create all of this.
So for uh machine learning models that are complex and very large uh it's it's uh quite difficult at the moment.
I'm I'm aware of that. So I'm asking uh what are your thoughts uh when it will be um
well
applicable in sense of okay in a two years four years or how you envision that. So people are making advances. We're doing tweaks to the cryptography etc. that's helping. So I think within two years maybe we'll get to be able to do some of the maybe there's some of the simpler large language models that we have at the moment because we've already done chat GPT2.
So we've passed a billion weights. So we've managed to do that okay in 90 hours but that's not great but so I think yeah in a couple of years we'll probably be starting to do things reasonably on some of the models we see at the moment. There's always going to be a gap though you know by that time the model sort of increased again.
There is a lot of uh room for improvement essentially.
Yeah there is.
Thank you.
Um thanks for the presentation. Um I like I'm not familiar with all of the different um neural network types but I as far as I know um there are different kinds and they have different um structures. So I'm wondering like I know about the KCNN like it was the only paper that I actually read read but um like does it really uh differ from like different neural network types like in terms of benchmark or like in terms of the success of the uh proof systems to like you know to actually have verifiable ML because I'm wondering like okay ZK CNN was good and could be improved and the other works that you have presented um like I actually kind of um you know I'm not I wasn't sure about if like this like all these methods going to be be applying to every single different ML models like or ML types let's say. Um so I would be I would be happy if you could answer this.
Yeah sure. Uh yeah, I think that's that's a good point and I think with the way that things are improving is that they are taking some uh say some specific techniques. So with like convolutional networks, they're taking techniques of how they work and then improving small parts of that. So I think it's we're not going to see uh yeah it's not going to be sort of moving you know everything moving together at once. we're probably going to see specific types of machine of networks and neural nets uh going at different paces as they manage to sort of tweak various aspects of them.
So yeah, I think that's that's very that's very
Thank you. Also another short question u quite similar to the previous one. um like is a is there a better better approach to like accelerate the ZK in terms of ML you know than than hardware acceleration right now because I'm not sure you know the tweaking cryptography is you know is is it that promising or hardware acceleration is the best hope also asking as a FH researcher so I understand your pain
yeah so uh yeah I think uh hardware is going to help but uh a lot of the work that's going on is is on cryptographic side and looking at the way that we actually create the zero knowledge proofs and getting techniques there better and more adapted to the what to what we want to the the architecture of neural networks. So yeah, we're not relying just on the hardware.
Thank you.
Okay.
Um thank you. Um maybe a bit more technical question. Um you mentioned in in machine learning models that most of them using uh neural networks uh I mean matrix multiplications is is there a consensus on the kind of zero knowledge part which kind of proofs are are best for this is is it going in one direction you know elliptic curve based or recursion based or whatever or or you know it's very diverse and not really
uh moving thinking of just one direction.
So, uh I think so recursion I think is very promising but recursion generally in zero knowledge is perhaps at an earlier stage than sort of the you know other sort of the standard types of of snarks for example. So um one some techniques that have been useful are um using things called lookup tables which are which have been used in zero knowledge proofs anyway uh but they are particularly they they work particularly well in solving some of the problems we have with machine learning but in terms of things like you know are starks better or snarks I I don't think of that level there's uh anything I could say but some very specific techniques are do work better but I think recursion for example particularly because we are seeing quite a breakthrough on the sort of the folding scheme side as well. I think there's a lot of potential there. I think that will help out. Yeah.
Thank you.
Automatic transcript — names and jargon may be misspelled.