English

VeriLoRA: Fine-Tuning Large Language Models with Verifiable Security via Zero-Knowledge Proofs

Cryptography and Security 2025-12-03 v3 Artificial Intelligence

Abstract

Fine-tuning large language models (LLMs) is crucial for adapting them to specific tasks, yet it remains computationally demanding and raises concerns about correctness and privacy, particularly in untrusted environments. Although parameter-efficient methods like Low-Rank Adaptation (LoRA) significantly reduce resource requirements, ensuring the security and verifiability of fine-tuning under zero-knowledge constraints remains an unresolved challenge. To address this, we introduce VeriLoRA, the first framework to integrate LoRA fine-tuning with zero-knowledge proofs (ZKPs), achieving provable security and correctness. VeriLoRA employs advanced cryptographic techniques -- such as lookup arguments, sumcheck protocols, and polynomial commitments -- to verify both arithmetic and non-arithmetic operations in Transformer-based architectures. The framework provides end-to-end verifiability for forward propagation, backward propagation, and parameter updates during LoRA fine-tuning, while safeguarding the privacy of model parameters and training data. Leveraging GPU-based implementations, VeriLoRA demonstrates practicality and efficiency through experimental validation on open-source LLMs like LLaMA, scaling up to 13 billion parameters. By combining parameter-efficient fine-tuning with ZKPs, VeriLoRA bridges a critical gap, enabling secure and trustworthy deployment of LLMs in sensitive or untrusted environments.

Keywords

Cite

@article{arxiv.2508.21393,
  title  = {VeriLoRA: Fine-Tuning Large Language Models with Verifiable Security via Zero-Knowledge Proofs},
  author = {Guofu Liao and Taotao Wang and Shengli Zhang and Jiqun Zhang and Shi Long and Dacheng Tao},
  journal= {arXiv preprint arXiv:2508.21393},
  year   = {2025}
}

Comments

This paper has been accepted for publication at the Network and Distributed System Security Symposium (NDSS) 2026

R2 v1 2026-07-01T05:11:36.646Z