As artificial intelligence becomes increasingly integrated into society, ensuring its trustworthiness is a central scientific and technological challenge.
We believe that aspects such as privacy, fairness, safety, and integrity should not be overlooked as we develop a technology with such broad impact.
Cryptography, the science of establishing trust in computation through mathematical guarantees, provides a key set of tools for addressing these problems.
Our research studies how cryptographic methods can support AI systems whose security and correctness do not depend solely on trusting their operators.
We pursue foundational research, seeking solutions with provable guarantees under well-defined, realistic models.
This emphasis on principled methods is intended to produce broadly applicable insights rather than remedies tailored to individual systems.
A major research goal is
privacy-preserving inference: enabling users to access remote AI models without revealing their queries, or even to access their privately owned outsourced models without exposing them.
This forms part of our broader work on secure computation for AI and private data access, including
private information retrieval (PIR).
We investigate recent techniques based on PIR,
encrypted matrix–vector products (EMVP), and
trapdoored matrices (TDM) [1–4].
Our work spans new protocol design, practical implementations, and cryptanalysis aimed at strengthening confidence in the underlying security assumptions.
Ultimately, we seek to demonstrate that privacy-preserving inference can be practical in real-world settings.
We also study
watermarking for generative AI, which embeds a hidden signal in generated content (e.g., text or images) so that it can be identified as AI-generated.
A desired property of watermarking is
robustness: namely that adversarial modifications of the generated output cannot remove the hidden signal.
Existing methods demonstrate that watermarking is feasible, but important limitations remain: cryptographic approaches provide formal guarantees yet are robust only against restricted classes of adversarial modifications [5–7], while learned systems such as SynthID can require heavy model training and deployment infrastructure [8].
We study
semantic watermarking, aiming to establish formal foundations for watermarks that remain detectable even after meaning-preserving transformations.
Another focus is the use of
game theory to promote fairness and integrity in AI. Relevant questions include how to attribute a model’s value to its training data [9] and how to reward genuine contributions while discouraging free-riding in federated learning [10].
More broadly, cryptographic applications to AI include proof systems for
model integrity [12,13], the study and prevention of
backdoors [11], and many other emerging problems.
The lab continually seeks new research directions at the intersection of cryptography and AI.
References
[1] C. Chen, Y. Ishai,
T. Mour, and A. Rosen, “Secret-Key PIR from Random Linear Codes,” in
Proceedings of the 58th Annual ACM Symposium on Theory of Computing (STOC 2026), 2026.
[eprint.iacr.org]
[2] F. Benhamouda, C. Chen, S. Halevi, Y. Ishai, H. Krawczyk,
T. Mour, T. Rabin, and A. Rosen, “Encrypted Matrix–Vector Products from Secret Dual Codes,” in
Proceedings of the 2025 ACM SIGSAC Conference on Computer and Communications Security (CCS 2025), 2025.
[eprint.iacr.org]
[3] M. Braverman and S. Newman, “Practical Secure Delegated Linear Algebra with Trapdoored Matrices,” in
Theory of Cryptography Conference (TCC 2025), 2025.
[arxiv.org]
[4] V. Vaikuntanathan and O. Zamir, “Improving Algorithmic Efficiency Using Cryptography: Trapdoored Matrices and Applications,” in
Proceedings of the 2026 Annual ACM–SIAM Symposium on Discrete Algorithms (SODA 2026), pp. 2554–2574, 2026.
[arxiv.org]
[5] M. Christ, S. Gunn, and O. Zamir, “Undetectable Watermarks for Language Models,” in
Proceedings of the 37th Conference on Learning Theory (COLT 2024), vol. 247, pp. 1125–1139, 2024.
[proceeding.mlr.press]
[6] M. Christ and S. Gunn, “Pseudorandom Error-Correcting Codes,” in
Advances in Cryptology—CRYPTO 2024, LNCS 14925, pp. 325–347, 2024.
[eprint.iacr.org]
[7] N. Golowich and A. Moitra, “Edit Distance Robust Watermarks via Indexing Pseudorandom Codes,” in
Advances in Neural Information Processing Systems 37 (NeurIPS 2024), 2024.
[arxiv.org]
[8] S. Gowal et al., “SynthID-Image: Image Watermarking at Internet Scale,” arXiv preprint arXiv:2510.09263, 2025.
[arxiv.org]
[9] A. Ghorbani and J. Zou, “Data Shapley: Equitable Valuation of Data for Machine Learning,” in
Proceedings of the 36th International Conference on Machine Learning (ICML 2019), vol. 97, pp. 2242–2251, 2019.
[proceeding.mlr.press]
[10] Y. Fraboni, R. Vidal, and M. Lorenzi, “Free-rider Attacks on Model Aggregation in Federated Learning,” in
Proceedings of the 24th International Conference on Artificial Intelligence and Statistics (AISTATS 2021), vol. 130, pp. 1846–1854, 2021.
[proceeding.mlr.press]
[11] S. Goldwasser, M. P. Kim, V. Vaikuntanathan, and O. Zamir, “Planting Undetectable Backdoors in Machine Learning Models,” in
Proceedings of the 63rd IEEE Annual Symposium on Foundations of Computer Science (FOCS 2022), 2022.
[arxiv.org]
[12] H. Jia, M. Yaghini, C. A. Choquette-Choo, N. Dullerud, A. Thudi, V. Chandrasekaran, and N. Papernot, “Proof-of-Learning: Definitions and Practice,” in
Proceedings of the 42nd IEEE Symposium on Security and Privacy, pp. 1039–1056, 2021.
[arxiv.org]
[13] Z. Ghodsi, T. Gu, and S. Garg, “SafetyNets: Verifiable Execution of Deep Neural Networks on an Untrusted Cloud,” in
Advances in Neural Information Processing Systems 30 (NeurIPS 2017), pp. 4672–4681, 2017.
[arxiv.org]
Last updated: July 22, 2026.
Author names are sorted alphabetically.
1. C. Chen, Y. Ishai, A. Jain,
T. Mour, A. Rosen, and C. Xing, "Doubly-Efficient Secret-Key PIR with Low Storage Overhead”, 2026.
[preprint]