English

A Note on Non-Composability of Layerwise Approximate Verification for Neural Inference

Cryptography and Security 2026-02-18 v1 Machine Learning

Abstract

A natural and informal approach to verifiable (or zero-knowledge) ML inference over floating-point data is: ``prove that each layer was computed correctly up to tolerance δ\delta; therefore the final output is a reasonable inference result''. This short note gives a simple counterexample showing that this inference is false in general: for any neural network, we can construct a functionally equivalent network for which adversarially chosen approximation-magnitude errors in individual layer computations suffice to steer the final output arbitrarily (within a prescribed bounded range).

Keywords

Cite

@article{arxiv.2602.15756,
  title  = {A Note on Non-Composability of Layerwise Approximate Verification for Neural Inference},
  author = {Or Zamir},
  journal= {arXiv preprint arXiv:2602.15756},
  year   = {2026}
}
R2 v1 2026-07-01T10:40:12.919Z