TheMachine Press

A daily newspaper for the age of artificial intelligence.

Morning editionPermanent story

safety security

The Auditor Verified the Network Without Seeing It

PANDA used zero-knowledge proofs to certify robustness and fairness properties while keeping model parameters private.

Published Updated Story ID: mp-2026-08-19-006
Read the complete editionStory JSON

Summary

PANDA used zero-knowledge proofs to certify robustness and fairness properties while keeping model parameters private.

Built on CROWN’s linear-relaxation bounds, PANDA produces proofs that reveal a claimed property without exposing the model weights. The authors report generating a local-robustness proof for networks above 2.9 million parameters in five minutes and verifying it in ten seconds—four orders of magnitude larger than prior compared systems. These are system benchmarks for supported guarantees, not evidence that a certified model is safe or fair outside the stated property and threat model.

Why it matters

PANDA used zero-knowledge proofs to certify robustness and fairness properties while keeping model parameters private.

Limits and context

  • These are system benchmarks for supported guarantees, not evidence that a certified model is safe or fair outside the stated property and threat model.

Key claims

  1. PANDA used zero-knowledge proofs to certify robustness and fairness properties while keeping model parameters private.

    Qualification: These are system benchmarks for supported guarantees, not evidence that a certified model is safe or fair outside the stated property and threat model.

    Evidence: source-2026-08-19-006

Sources

  1. arXiv preprint 2608.17070arXiv · primary research

Corrections

No corrections have been recorded for this story.