# STARK proofs ELI5 by Henri | Devcon SEA

- Channel: [Devcon](https://streameth.org/devcon)
- Date: 2025-10-09
- Duration: 08:17
- Topics: Science & Technology
- Watch: https://streameth.org/watch/yt-eHPp8mFCS6E
- YouTube: https://www.youtube.com/watch?v=eHPp8mFCS6E

## Description

Let's face it, ZK proofs are intimidating. But they don't have to be!
ZK proofs are complex not because of the depth math they use, but because of the large number of fields of mathematics they leverage features from.
In this talk, we'll break down STARK proofs into simple blocks and colorful analogies so that you get a good high level overview of how they work

Speaker(s): Henri
Skill level: Intermediate
Track: Applied Cryptography
Keywords: ZKP, Use cases of cryptography, STARK, eli5

Follow us: https://twitter.com/efdevcon, https://twitter.com/ethereum, https://warpcast.com/devcon
Learn more about devcon: https://www.devcon.org/
Learn more about ethereum: https://ethereum.org/ 

Visit the https://archive.devcon.org/ to gain access to the entire library of Devcon talks with the ease of filtering, playlists, personalized suggestions, decentralized access on Swarm, IPFS and more.

Devcon is the Ethereum conference for developers, researchers, thinkers, and makers. 
Devcon SEA was held in Bangkok, Thailand on Nov 12 - Nov 15, 2024.
Devcon is organized and presented by the Ethereum Foundation. To find out more, please visit https://ethereum.foundation/

## Transcript

[Music] [Music] everyone um welcome my name is H Lio I work at the Stark Foundation where I'm the head of ecosystem and I'm going to try to explain Stark proof like you're a 5-year-old there's many ways to explain proof this is mine it's not perfect but I hope you learn something so how I'm going to go about it is the following way I'm going to first explain quickly what is proving what we're trying to achieve I'm going to talk about something that is called arithmetization I'm going to talk about execution traces and how they get used into proofs I'm going to talk about error correction code and I'm going to try to put everything together so that you have a clearer picture so first let's talk about proving what is proving proving is a person trying to execute a computer code and trying to and that person is called a prover and he's trying to convince the verifier that the execution happened correctly without the verifier having to reexecute the computation now the kicker where this gets interesting is that there's an asymmetry between prover and verifier and it's very efficient for the verifier to verify rather than reexecute so we Save A Lot on compute on the verifier side that's what we're trying to do so first now how do we do that we first use one step that is called arithmetization so arithmetization from a high level perspective is the act of turning a computation into a set of polinomial that represent s computation I'm not going to go too deep into that but assume the following when you use a computer you know that your computer program can be turned into logic that gets executed on transistors and on zeros and ones you can get the same result by having your competition represented as pols and you when you design a computer program that you want to prove you have an expected polinomial which is the polinomial where every execution of your program will have points falling on it okay now let's talk about an execution Trace what is an execution trace the execution Trace is the equivalent of the stepbystep log of you executing a program if you were using a CPU for example it would be the register of the list of all actions all all registers all caner all memory steps at every single step of the execution of your program so executing your program is the sequence of all those specific steps now what do we do with this execution Trace when we run um when you're trying to prove is we're turning that execution Trace also into a polom so you take all those data points and you turn them into points and you interpolate a polinomial that will go through this execution Trace so now you have two polinomial right you have the expected polinomial the one that defines the program you're trying to prove and you have the executed polinomial which represents the execution you just ran so what do we do with that we apply something on top of it that is called error correction code error correction code is something that is used in telecommunication to transmit data and verify its Integrity it gives you two property one you can detect error very easily and two you can recover from those errors but we're not trying to recover from errors we're trying to detect those so we're using those techniques on those two pols to check if the execution polinomial is as close as possible or the closest way possible to the expected polinomial that's how error correction code is used in Stark proof so now wrapping it up what we're trying trying to do is to convince the verifier that the execution happened over the same polinomial that the polinomial he was expecting which was defining the computer problem he was trying to solve and with error correction code we're just taking any tiny mistake that might have happened somewhere and we're amplifying it so instead of having to check every point in the execution the verifier can just take a few points and then check using error correct ction code whether there were there was an error somewhere I hope that makes sense and you learned something and here's the actual explain five explanation of Stark proofs Stark proofs are 5 years old worst nightmare when you're going to the swimming pool and somebody tells you hey if you pee it's going to turn red and everybody will see it Stark proofs are the exact same thing for computation if you try to cheat at a single place it's going to blow up everywhere and everybody will see it and we'll know you're a cheater and you're not going to be able to convince the verifier that you U did your computation correctly voila thank you thank you Harry we should probably invent something that makes your pee turns red in the pool right any question ah there's one I'll do this one um how do error correcting codes and polinomial commitment schemes differ um I'm not entirely sure I can uh answer this question I don't know enough about it I'm sorry oh I see another hand here this lady by the way thank you so much for the ei5 um want to really understand bit more when you say you take a few points out at the ECC stage you take a few points points and amplify it is that to right to understand that as a statistical probability that it might have an error that you cannot detect because the sampling wasn't done you know to capture those points or is that just we should feel comfortable believing that as long as it passes it is error free I'm not sure I understand your question but I think what you're saying is is there uh like sampling depending on how much samples you're taking you have a different level of certainty yes that's actually the case when you're taking samples you're going to see error with a probability and the more sample you take the lower the probability of you catching a of not catching an error is all right any other questions for Henry oh there's one here uh Hey so do I understand properly that this verifier need to have this execution polinomial like a like a sample that it needs to check whether it's following the same steps yes it does get a form of a it does get some sample uh from the execution Trace originally in proof there are like protocols so that the verifier asks theover hey can I get this point can I get this point and then he verifies a few but using some fancy cry graphic technique you can actually get away with just giving the prover can get away with giving a bunch of random points and having the verifier just use them off the bat we take one more question ah there's one there uh if the approver can can select the points to send to the verifier can he select the points in such way that the ver Fire won't be able to detect the so the fancy cryptographic technique I mentioned makes it so that e can't select points that are comfortable for him so um so then like he can't really cheat hopefully
