{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T15:40:55Z","timestamp":1783438855384,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":63,"publisher":"ACM","license":[{"start":{"date-parts":[[2025,6,4]],"date-time":"2025-06-04T00:00:00Z","timestamp":1748995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"name":"UKRI","award":["EP\\\/T022485\\\/1"],"award-info":[{"award-number":["EP\\\/T022485\\\/1"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2025,6,4]]},"DOI":"10.1145\/3716815.3729011","type":"proceedings-article","created":{"date-parts":[[2025,6,5]],"date-time":"2025-06-05T18:35:32Z","timestamp":1749148532000},"page":"49-59","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":3,"title":["A Framework for Cryptographic Verifiability of End-to-End AI Pipelines"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-1296-9254","authenticated-orcid":false,"given":"Kar","family":"Balan","sequence":"first","affiliation":[{"name":"DECaDE Centre for the Decentralized Digital Economy, University of Surrey, Guildford, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2870-6120","authenticated-orcid":false,"given":"Robert","family":"Learney","sequence":"additional","affiliation":[{"name":"Digital Catapult, London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1082-4321","authenticated-orcid":false,"given":"Tim","family":"Wood","sequence":"additional","affiliation":[{"name":"Digital Catapult, London, United Kingdom"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,6,5]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2000. Personal Information Protection and Electronic Documents Act (PIPEDA). Government of Canada Justice Laws Website. https:\/\/laws-lois.justice.gc.ca\/eng\/acts\/P-8.6\/ Accessed: 2024-09--18."},{"key":"e_1_3_2_1_2_1","unstructured":"2016. Regulation (EU) 2016\/679 of the European Parliament and of the Council of 27 April 2016 on the Protection of Natural Persons with Regard to the Processing of Personal Data and on the Free Movement of Such Data (General Data Protection Regulation - GDPR). Official Journal of the European Union. https:\/\/eur-lex.europa.eu\/eli\/reg\/2016\/679\/oj Accessed: 2024-09--18."},{"key":"e_1_3_2_1_3_1","unstructured":"2018. California Consumer Privacy Act of 2018 (CCPA). State of California Department of Justice. https:\/\/oag.ca.gov\/privacy\/ccpa Accessed: 2024-09--18."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3670316"},{"key":"e_1_3_2_1_6_1","unstructured":"Associated Press. 2024. Telling the Story - Standards. https:\/\/www.ap.org\/about\/news-values-and-principles\/telling-the-story\/. Accessed: 2024-09--13."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/3626495.3626506"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/3697294.3697306"},{"key":"e_1_3_2_1_9_1","unstructured":"Eli Ben-Sasson Iddo Bentov Yinon Horesh and Michael Riabzev. 2018. Scalable transparent and post-quantum secure computational integrity. IACR Cryptol. ePrint Arch. (2018) 46. http:\/\/eprint.iacr.org\/2018\/046"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-36594-2_18"},{"key":"e_1_3_2_1_11_1","unstructured":"Camera Bits. 2024. Camera Bits Introduces Its Solution for Protecting Provenance of C2PA-Signed Photos in Effort to Help Combat Fake Imagery. https:\/\/home.camerabits.com\/2024\/05\/06\/press-release-camera-bits-introduces-its-solution-for-protecting-provenance-of-c2pa-signed-photos-in-effort-to-help-combat-fake-imagery\/. Accessed: 2024-09--12."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-07085-3_15"},{"key":"e_1_3_2_1_13_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Carlini Nicholas","year":"2021","unstructured":"Nicholas Carlini, Florian Tram\u00e8r, Eric Wallace, Matthew Jagielski, Ariel Herbert-Voss, Katherine Lee, Adam Roberts, Tom Brown, Dawn Song, \u00dalfar Erlingsson, Alina Oprea, and Colin Raffel. 2021. Extracting Training Data from Large Language Models. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 2633--2650. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/carlini-extracting"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/3627703.3650088"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/MCG.2024.3380168"},{"key":"e_1_3_2_1_16_1","unstructured":"Trisha Datta Binyi Chen and Dan Boneh. 2024. VerITAS: Verifying Image Transformations at Scale. Cryptology ePrint Archive Paper 2024\/1066. https:\/\/eprint.iacr.org\/2024\/1066"},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-030--86520--7_36"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SaTML64287.2025.00033"},{"key":"e_1_3_2_1_19_1","volume-title":"Do You Need a Zero Knowledge Proof? Cryptology ePrint Archive","author":"Ernstberger Jens","year":"2024","unstructured":"Jens Ernstberger, Stefanos Chaliasos, Liyi Zhou, Philipp Jovanovic, and Arthur Gervais. 2024. Do You Need a Zero Knowledge Proof? Cryptology ePrint Archive (2024)."},{"key":"e_1_3_2_1_20_1","volume-title":"https:\/\/www.edpb.europa.eu\/system\/files\/2024--12\/edpb_opinion_202428_ai-models_en.pdf Adopted on","author":"Protection Board European Data","year":"2024","unstructured":"European Data Protection Board. 2024. Opinion 28\/2024 on Certain Data Protection Aspects Related to the Processing of Personal Data in the Context of AI Models. https:\/\/www.edpb.europa.eu\/system\/files\/2024--12\/edpb_opinion_202428_ai-models_en.pdf Adopted on 17 December 2024."},{"key":"e_1_3_2_1_21_1","volume-title":"Ali Shahin Shamsabadi, and Hamed Haddadi","author":"Franzese Olive","year":"2024","unstructured":"Olive Franzese, Ali Shahin Shamsabadi, and Hamed Haddadi. 2024. OATH: Efficient and Flexible Zero-Knowledge Proofs of End-to-End ML Fairness. arXiv:2410.02777 [cs.CY] https:\/\/arxiv.org\/abs\/2410.02777"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2022-0079"},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623202"},{"key":"e_1_3_2_1_24_1","volume-title":"Delegation of computation without rejection problem from designated verifier CS-proofs. Cryptology ePrint Archive","author":"Goldwasser Shafi","year":"2011","unstructured":"Shafi Goldwasser, Huijia Lin, and Aviad Rubinstein. 2011. Delegation of computation without rejection problem from designated verifier CS-proofs. Cryptology ePrint Archive (2011)."},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","unstructured":"Feng Hao. 2017. Schnorr Non-interactive Zero-Knowledge Proof. RFC 8235. https:\/\/doi.org\/10.17487\/RFC8235","DOI":"10.17487\/RFC8235"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1109\/GLOBECOM48099.2022.10000784"},{"key":"e_1_3_2_1_27_1","unstructured":"IBM. 2024. What is fine-tuning? https:\/\/www.ibm.com\/topics\/fine-tuning"},{"key":"e_1_3_2_1_28_1","unstructured":"Daniel Kang Kobi Gurkan and Anna Rose. 2023. Fighting AI-Generated Audio with Attested Microphones and ZK-SNARKs: The Attested Audio Experiment. https:\/\/medium.com\/@danieldkang\/fighting-ai-generated-audio-with-attested-microphones-and-zk-snarks-the-attested-audio-experiment-d6ea0fc296ac Accessed: 2024-09--16."},{"key":"e_1_3_2_1_29_1","unstructured":"Daniel Kang Tatsunori Hashimoto Ion Stoica and Yi Sun. 2022. ZK-IMG: Attested Images via Zero-Knowledge Proofs to Fight Disinformation. arXiv:2211.04775 [cs.CR] https:\/\/arxiv.org\/abs\/2211.04775"},{"key":"e_1_3_2_1_30_1","volume-title":"NeurIPS RegulateML Workshop. arXiv:2210","author":"Kang Daniel","year":"2023","unstructured":"Daniel Kang, Tatsunori Hashimoto, Ion Stoica, and Yi Sun. 2023. Scaling up Trustless DNN Inference with Zero-Knowledge Proofs. In NeurIPS RegulateML Workshop. arXiv:2210.08674 [cs.CR] https:\/\/arxiv.org\/abs\/2210.08674"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453110"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/3576915.3623134"},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/3460120.3485379"},{"key":"e_1_3_2_1_34_1","volume-title":"Data Authenticity, Consent, and Provenance for AI Are All Broken: What Will It Take to Fix Them? An MIT Exploration of Generative AI (March","author":"Longpre Shayne","year":"2024","unstructured":"Shayne Longpre, Robert Mahari, Naana Obeng-Marnu, William Brannon, Tobin South, Jad Kabbara, and Sandy Pentland. 2024. Data Authenticity, Consent, and Provenance for AI Are All Broken: What Will It Take to Fix Them? An MIT Exploration of Generative AI (March 2024). Available at: https:\/\/mit-genai.pubpub.org\/pub\/uk7op8zs."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-030--42504--3_26"},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2024.112115"},{"key":"e_1_3_2_1_37_1","volume-title":"Federated learning: Collaborative machine learning without centralized training data. Google Research Blog 3","author":"McMahan Brendan","year":"2017","unstructured":"Brendan McMahan and Daniel Ramage. 2017. Federated learning: Collaborative machine learning without centralized training data. Google Research Blog 3 (2017). https:\/\/research.google\/blog\/federated-learning-collaborative-machine-learning-without-centralized-training-data"},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1137\/S0097539795284959"},{"key":"e_1_3_2_1_39_1","unstructured":"Modulus Labs. 2023. The cost of intelligence: Proving machine learning inference with zero-knowledge. Available at: https:\/\/drive.google.com\/file\/d\/1tylpowpaqcOhKQtYolPlqvx6R2Gv4IzE\/view."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103180"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.23"},{"key":"e_1_3_2_1_42_1","volume-title":"Zhao Ren, Phi Le Nguyen, Alan Wee-Chung Liew, Hongzhi Yin, and Quoc Viet Hung Nguyen.","author":"Nguyen Thanh Tam","year":"2024","unstructured":"Thanh Tam Nguyen, Thanh Trung Huynh, Zhao Ren, Phi Le Nguyen, Alan Wee-Chung Liew, Hongzhi Yin, and Quoc Viet Hung Nguyen. 2024. A Survey of Machine Unlearning. arXiv:2209.02299 [cs.LG] https:\/\/arxiv.org\/abs\/2209.02299"},{"key":"e_1_3_2_1_43_1","unstructured":"OpenAI. 2024. C2PA in DALL\u00b7E 3. https:\/\/help.openai.com\/en\/articles\/8912793-c2pa-in-dall-e-3. Accessed: 2024-09--12."},{"key":"e_1_3_2_1_44_1","first-page":"257","article-title":"Regulation (EU) 2024\/1689 on laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) and amending certain Union legislative acts. https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/1689\/oj","author":"European Parliament and Council","year":"2024","unstructured":"European Parliament and Council. 2024. Regulation (EU) 2024\/1689 on laying down harmonised rules on artificial intelligence (Artificial Intelligence Act) and amending certain Union legislative acts. https:\/\/eur-lex.europa.eu\/eli\/reg\/2024\/1689\/oj. Official Journal of the European Union, L 257, 25.07.2024, p. 1--103.","journal-title":"Official Journal of the European Union"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2021.108621"},{"key":"e_1_3_2_1_47_1","volume-title":"Spartan: Efficient and General-Purpose zkSNARKs Without Trusted Setup. In Advances in Cryptology -- CRYPTO","author":"Setty Srinath","year":"2020","unstructured":"Srinath Setty. 2020. Spartan: Efficient and General-Purpose zkSNARKs Without Trusted Setup. In Advances in Cryptology -- CRYPTO 2020, Daniele Micciancio and Thomas Ristenpart (Eds.). Springer International Publishing, Cham, 704--737."},{"key":"e_1_3_2_1_48_1","volume-title":"Confidential-PROFITT: Confidential PROof of FaIr Training of Trees. In The Eleventh International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=iIfDQVyuFD","author":"Shamsabadi Ali Shahin","year":"2023","unstructured":"Ali Shahin Shamsabadi, Sierra Calanda Wyllie, Nicholas Franzese, Natalie Dullerud, S\u00e9bastien Gambs, Nicolas Papernot, Xiao Wang, and Adrian Weller. 2023. Confidential-PROFITT: Confidential PROof of FaIr Training of Trees. In The Eleventh International Conference on Learning Representations. https:\/\/openreview.net\/forum?id=iIfDQVyuFD"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1007\/978--3-031--18283--9_12"},{"key":"e_1_3_2_1_50_1","unstructured":"Sony. 2024. Sony Delivers Highly Anticipated Firmware Updates Including C2PA Compliancy and Ensuring Authenticity of Images. https:\/\/www.sony.co.uk\/presscentre\/sony-delivers-highly-anticipated-firmware-updates-including-c2pa-compliancy-and-ensuring-authenticity-of-images. Accessed: 2024-09--12."},{"key":"e_1_3_2_1_51_1","unstructured":"Tobin South Alexander Camuto Shrey Jain Shayla Nguyen Robert Mahari Christian Paquin Jason Morton and Alex 'Sandy' Pentland. 2024. Verifiable evaluations of machine learning models using zkSNARKs. arXiv:2402.02675 [cs.LG] https:\/\/arxiv.org\/abs\/2402.02675"},{"key":"e_1_3_2_1_52_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3520863"},{"key":"e_1_3_2_1_53_1","volume-title":"Theory of Cryptography","author":"Valiant Paul","unstructured":"Paul Valiant. 2008. Incrementally Verifiable Computation or Proofs of Knowledge Imply Time\/Space Efficiency. In Theory of Cryptography, Ran Canetti (Ed.). Springer Berlin Heidelberg, Berlin, Heidelberg, 1--18."},{"key":"e_1_3_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.5555\/3692070.3694106"},{"key":"e_1_3_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.56553\/popets-2023-0061"},{"key":"e_1_3_2_1_56_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2023.01.130"},{"key":"e_1_3_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2024.3403370"},{"key":"e_1_3_2_1_58_1","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Weng Chenkai","year":"2021","unstructured":"Chenkai Weng, Kang Yang, Xiang Xie, Jonathan Katz, and Xiao Wang. 2021. Mystique: Efficient Conversions for Zero-Knowledge Proofs with Applications to Machine Learning. In 30th USENIX Security Symposium (USENIX Security 21). USENIX Association, 501--518. https:\/\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/weng"},{"key":"e_1_3_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3358993"},{"key":"e_1_3_2_1_60_1","volume-title":"Generative AI Law (GenLaw) '24, ICML 2024,","author":"Woisetschl\u00e4ger Herbert","year":"2024","unstructured":"Herbert Woisetschl\u00e4ger, Simon Mertel, Christoph Kr\u00f6nke, Ruben Mayer, and Hans-Arno Jacobsen. 2024. Federated Learning and AI Regulation in the European Union: Who is Liable? -- An Interdisciplinary Analysis. Presented at Generative AI Law (GenLaw) '24, ICML 2024, available at https:\/\/blog.genlaw.org\/pdfs\/genlaw_icml2024\/16.pdf."},{"key":"e_1_3_2_1_61_1","unstructured":"Zhibo Xing Zijian Zhang Jiamou Liu Ziang Zhang Meng Li Liehuang Zhu and Giovanni Russello. 2023. Zero-knowledge Proof Meets Machine Learning in Verifiability: A Survey. arXiv:2310.14848 [cs.LG] https:\/\/arxiv.org\/abs\/2310.14848"},{"key":"e_1_3_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1109\/tetci.2024.3379240"},{"key":"e_1_3_2_1_63_1","volume-title":"Proceedings of the 41st International Conference on Machine Learning (Proceedings of Machine Learning Research","volume":"55705","author":"Yadav Chhavi","year":"2024","unstructured":"Chhavi Yadav, Amrita Roy Chowdhury, Dan Boneh, and Kamalika Chaudhuri. 2024. FairProof : Confidential and Certifiable Fairness for Neural Networks. In Proceedings of the 41st International Conference on Machine Learning (Proceedings of Machine Learning Research, Vol. 235), Ruslan Salakhutdinov, Zico Kolter, Katherine Heller, Adrian Weller, Nuria Oliver, Jonathan Scarlett, and Felix Berkenkamp (Eds.). PMLR, 55682--55705. https:\/\/proceedings.mlr.press\/v235\/yadav24a.html"},{"key":"e_1_3_2_1_64_1","volume-title":"NeurIPS Workshop on Statistical Frontiers in LLMs and Foundation Models. arXiv:2411","author":"Zhang Eva","year":"2024","unstructured":"Eva Zhang, Akilesh Potti, and Micah Goldblum. 2024. vTune: Verifiable Fine-Tuning Through Backdooring. In NeurIPS Workshop on Statistical Frontiers in LLMs and Foundation Models. arXiv:2411.06611 [cs.LG] https:\/\/arxiv.org\/abs\/2411.06611"},{"key":"e_1_3_2_1_66_1","doi-asserted-by":"publisher","DOI":"10.1109\/TPDS.2021.3068195"}],"event":{"name":"CODASPY '25:CODASPY '25","location":"Pittsburgh PA USA","acronym":"CODASPY '25","sponsor":["sigsac ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 10th ACM International Workshop on Security and Privacy Analytics"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3716815.3729011","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3716815.3729011","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:18:53Z","timestamp":1750295933000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3716815.3729011"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,6,4]]},"references-count":63,"alternative-id":["10.1145\/3716815.3729011","10.1145\/3716815"],"URL":"https:\/\/doi.org\/10.1145\/3716815.3729011","relation":{},"subject":[],"published":{"date-parts":[[2025,6,4]]},"assertion":[{"value":"2025-06-05","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}