CMA-ZK: Chunked Mask Commitments for Zero-Knowledge-Ready Auditing of Federated Unlearning
PDF

Keywords

verifiable machine unlearning
federated learning
zero-knowledge proof
Merkle transparency
task masks
educational AI governance

Abstract

Federated machine unlearning has a trust problem. A model provider may claim to have removed a task or client contribution, yet a data subject cannot infer honest execution from the final weights alone. The supplied course architecture proposes recording masks and deletion states on a consortium blockchain, but placing complete model state on-chain or proving an entire training trajectory would create high latency, energy cost, and metadata exposure. This paper proposes CMA-ZK, a Chunked Mask Commitment architecture for zero-knowledge-ready unlearning audits. Task masks, parameter increments, and authorization bits are committed in fixed-size chunks under an append-only Merkle root. A withdrawal affects only the relevant chunks and their declared dependencies. The proof interface verifies that the old commitment was valid, the authorized mask was reset, the repair update used an allowed state transition, and the new chunks aggregate to the next public root. Raw records, complete gradients, and unaffected parameters remain at institutional edge nodes. We construct a seeded discrete-event model with eight workers, 9,000 requests, Poisson arrivals, and lognormal service times. At an arrival rate of two requests per second, CMA-ZK achieves 0.40 s median and 0.68 s p95 latency, compared with 2.30 s and 3.88 s for a checkpoint-proof design. A retraining-plus-monolithic-proof design saturates at approximately 0.83 requests per second and reaches 6,108 s p95 latency in the same scenario. Under the declared workload parameters, CMA-ZK uses 7.8 ms verification time, an 18 KB proof, and 1.7 Wh per request. The study supports a conditional scaling hypothesis. It does not demonstrate that a real proof system will achieve those values. Trustworthy deployment still requires circuit verification, randomness governance, key management, statistical unlearning tests, and independent log monitoring.

PDF

References

Bourtoule, L., Chandrasekaran, V., Choquette-Choo, C. A., et al. (2021). Machine Unlearning. 2021 IEEE Symposium on Security and Privacy, 141-159. https://doi.org/10.1109/SP40001.2021.00019

Sekhari, A., Acharya, J., Kamath, G., and Suresh, A. T. (2021). Remember What You Want to Forget: Algorithms for Machine Unlearning. NeurIPS 34, 18075-18086. https://proceedings.neurips.cc/paper/2021/hash/9627c45df543c816a3ddf2d8ea686a99-Abstract.html

Eisenhofer, T., Riepel, D., Chandrasekaran, V., et al. (2025). Verifiable and Provably Secure Machine Unlearning. IEEE SaTML. https://doi.org/10.1109/SaTML64287.2025.00033

Jia, H., Yaghini, M., Choquette-Choo, C. A., et al. (2021). Proof-of-Learning: Definitions and Practice. 2021 IEEE Symposium on Security and Privacy. https://arxiv.org/abs/2103.05633

Fang, C., Jia, H., Thudi, A., et al. (2022). Proof-of-Learning Is Currently More Broken Than You Think. arXiv:2208.03567. https://arxiv.org/abs/2208.03567

Liu, G., Ma, X., Yang, Y., Wang, C., and Liu, J. (2020). Federated Unlearning. arXiv:2012.13891. https://arxiv.org/abs/2012.13891

Fraboni, Y., Van Waerebeke, M., Scaman, K., et al. (2024). SIFU: Sequential Informed Federated Unlearning for Efficient and Provable Client Unlearning in Federated Optimization. AISTATS, PMLR 238, 3457-3465. https://proceedings.mlr.press/v238/fraboni24a.html

Nguyen, T.-H., Vu, H.-P., Nguyen, D. T., et al. (2024). Empirical Study of Federated Unlearning: Efficiency and Effectiveness. ACML, PMLR 222, 959-974. https://proceedings.mlr.press/v222/nguyen24a.html

Weng, J., Yao, S., Du, Y., et al. (2022). Proof of Unlearning: Definitions and Instantiation. arXiv:2210.11334. https://arxiv.org/abs/2210.11334

Laurie, B., Langley, A., and Kasper, E. (2013). Certificate Transparency. RFC 6962. https://datatracker.ietf.org/doc/html/rfc6962

Groth, J. (2016). On the Size of Pairing-Based Non-interactive Arguments. EUROCRYPT 2016, LNCS 9666, 305-326. https://doi.org/10.1007/978-3-662-49896-5_11

Tabassi, E. (2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST AI 100-1. https://doi.org/10.6028/NIST.AI.100-1

European Parliament and Council. (2024). Regulation (EU) 2024/1689: Artificial Intelligence Act. https://eur-lex.europa.eu/eli/reg/2024/1689/oj

Özdenizci, O., Rueckert, E., and Legenstein, R. (2025). Privacy-Aware Lifelong Learning. arXiv:2505.10941. https://arxiv.org/abs/2505.10941

Tao, J., Liu, Z., Lyu, R., and Cao, X. (2026). A Scalable Data Governance Architecture for Privacy-Aware Intelligent Learning Systems in Lifelong. Course-supplied PDF manuscript.