safety security
The Auditor Verified the Network Without Seeing It
PANDA used zero-knowledge proofs to certify robustness and fairness properties while keeping model parameters private.
Summary
PANDA used zero-knowledge proofs to certify robustness and fairness properties while keeping model parameters private.
Built on CROWN’s linear-relaxation bounds, PANDA produces proofs that reveal a claimed property without exposing the model weights. The authors report generating a local-robustness proof for networks above 2.9 million parameters in five minutes and verifying it in ten seconds—four orders of magnitude larger than prior compared systems. These are system benchmarks for supported guarantees, not evidence that a certified model is safe or fair outside the stated property and threat model.
Why it matters
PANDA used zero-knowledge proofs to certify robustness and fairness properties while keeping model parameters private.
Limits and context
- These are system benchmarks for supported guarantees, not evidence that a certified model is safe or fair outside the stated property and threat model.
Key claims
PANDA used zero-knowledge proofs to certify robustness and fairness properties while keeping model parameters private.
Qualification: These are system benchmarks for supported guarantees, not evidence that a certified model is safe or fair outside the stated property and threat model.
Evidence: source-2026-08-19-006
Sources
- arXiv preprint 2608.17070arXiv · primary research
Corrections
No corrections have been recorded for this story.