PANDA Offers Private, Scalable ZKPs for Neural Network Guarantees

Youwei Zhong, Ben Merbaum, Timos Antonopoulos, Ning Luo, Charalampos Papamanthou, Katerina Sotiraki, Ruzica Piskac· August 19, 2026 View original

Key takeaways

  • PANDA uses ZKPs to prove neural network robustness and fairness without revealing parameters.
  • It offers a scalable solution, supporting models with millions of parameters.
  • A novel algorithm for linear relaxation bounds makes proofs lightweight and efficient.
  • PANDA significantly outperforms previous ZKP-based robustness systems in speed and scale.

Who benefits

FinanceHealthcareDefenseAutomotiveGovernment

Summary

PANDA is a new scalable system that uses Zero-Knowledge Proofs (ZKPs) to certify neural network robustness and fairness without revealing private model parameters. It significantly outperforms previous ZKP-based methods, proving properties for models with millions of parameters in minutes.

A new research paper introduces PANDA, a groundbreaking system designed to address the critical need for formal guarantees in machine learning models while preserving privacy. As AI models are increasingly deployed in sensitive applications, proving their robustness and fairness is paramount, but model parameters are often proprietary secrets. PANDA leverages Zero-Knowledge Proofs (ZKPs) to allow auditors or end-users to verify these properties without ever accessing the confidential model parameters. Built upon the efficient CROWN robustness certification framework, PANDA's core innovation is a novel algorithm for proving linear relaxation bounds for non-linear activation layers, resulting in remarkably lightweight proofs. This advancement enables PANDA to generate proofs of local robustness for neural networks with over 2.9 million parameters in just five minutes, with verification taking only ten seconds. This represents a monumental leap over prior ZKP-based systems, which relied on exponential-time algorithms and could not scale to networks of this size, making PANDA capable of supporting models four orders of magnitude larger.

Why it matters

PANDA provides a crucial solution for deploying trustworthy AI in regulated industries, allowing companies to certify model properties like robustness and fairness while protecting their intellectual property.

How to implement this in your domain

  1. 1Assess current AI model deployment strategies for privacy and compliance requirements.
  2. 2Investigate PANDA's ZKP methodology for certifying robustness and fairness in sensitive models.
  3. 3Collaborate with cryptography and AI security experts to integrate ZKP solutions into model validation.
  4. 4Develop internal protocols for generating and verifying ZKPs for AI model guarantees.
  5. 5Explore regulatory implications and potential for using ZKPs as proof of compliance for AI systems.

Original post by Youwei Zhong, Ben Merbaum, Timos Antonopoulos, Ning Luo, Charalampos Papamanthou, Katerina Sotiraki, Ruzica Piskac

"arXiv:2608.17070v1 Announce Type: new Abstract: With the growing deployment of machine learning models, formal guarantees of the robustness and fairness of these models have become increasingly important in safety-critical and legal-compliance settings. However, model parameters…"

View on X

Originally posted by Youwei Zhong, Ben Merbaum, Timos Antonopoulos, Ning Luo, Charalampos Papamanthou, Katerina Sotiraki, Ruzica Piskac on X · view source

Want to go deeper?

Turn these trends into skills with Learnijoy's hands-on AI & tech courses.

Explore courses

More in AI Engineering & DevTools