Original title:
Využití důkazů s nulovou znalostí ve strojovém učení
Translated title:
Use of Zero-Knowledge Proofs in Machine Learning
Authors:
Vaňo, Michal ; Homoliak, Ivan (referee) ; Perešíni, Martin (advisor) Document type: Master’s theses
Year:
2026
Language:
eng Publisher:
Vysoké učení technické v Brně. Fakulta informačních technologií Abstract:
[eng][cze]
Federatívne učenie (FL) umožňuje spoločné trénovanie modelu bez priameho zdieľania údajov, ale často sa spolieha na silné predpoklady o čestnom správaní klienta a servera. To je dôvod, prečo štandardné FL protokoly poskytujú iba obmedzenú záruku ohľadom výpočtov na strane klienta, integrity odoslaných informácii, alebo ohľadom správnosti agregácie na strane servera. Táto diplomová práca skúma použitie systémov s nulovými znalosťami (ZKP) spolu s podpornými metódami na vytvorenie dôvery v FL prostredí. V tejto práci sa po úvode k FL a ZKP ďalej skúma prehľad existujúcich ZKP nástrojov v prostredí FL. Na základe tejto analýzy je vytvorená kategorizácia existujúcich prístupov FL založených na ZKP, ktorá je postavená najmä na cieľoch daného systému. Na základe identifikovaných možností zlepšenia práca navrhuje overiteľný protokol váženej agregácie. V tomto protokole je každý prijatý príspevok previazaný s autorizovanou váhou, prípustnou skrytou aktualizáciou, konzistentným váženým vstupom a výslednou aktualizáciou modelu, ktorú je možné verejne overiť prepočítaním. Tento protokol bol implementovaný ako prototyp s plne funkčnými kryptografickými komponentami. Následne je tento protokol vyhodnotený.
Federated learning (FL) enables collaborative model training without directly sharing data, but it often relies on strong assumptions about honest behavior by both clients and the server. As a result, standard FL protocols provide only limited guarantees regarding client-side computation and results, the integrity of submitted information, and the correctness of server-side aggregation. This thesis examines the use of zero-knowledge proof systems (ZKPs), together with supporting methods, to establish trust in FL environments. After introducing FL and ZKPs, the thesis reviews existing ZKP tools and their use in the context of FL. Based on this analysis, it proposes a categorization of existing ZK-based FL approaches, structured primarily around the goals of each system. After identifying potential areas for improvement, the thesis introduces a verifiable weighted aggregation protocol in which each accepted contribution is linked to an authorized influence value, an admissible hidden update, a consistent weighted input, and a publicly recomputable final model update. The protocol was implemented as an end-to-end prototype with real cryptographic components. This prototype is later evaluated.
Keywords:
bezpečná agregácia; Bulletproofs; dôkazy s nulovou znalosťou; federatívne učenie; Groth16; PLONK; SNARK; STARK; strojové učenie so zachovaním súkromia; Bulletproofs; federated learning; Groth16; PLONK; privacy-preserving machine learning; secure aggregation; SNARK; STARK; zero-knowledge proofs
Institution: Brno University of Technology
(web)
Document availability information: Fulltext is available in the Brno University of Technology Digital Library. Original record: http://hdl.handle.net/11012/260303