Paper 2025/2152
Sum-check protocol for approximate computations
Abstract
Motivated by the mismatch between floating-point arithmetic, which is intrinsically approximate, and verifiable computing protocols for exact computations, we develop a generalization of the sum-check protocol. Our generalization proves claims of the form $\sum_{x \in \{0,1\}^v} g(x) \approx H$, where $g$ is a low-degree $v$-variate polynomial over an integral domain $\mathbb{U}$. The verifier performs its check in each round of the protocol using a tunable error parameter $\delta$. If $\Delta$ is the error in the prover's initial claim, then the soundness error of our protocols degrades gracefully with $\delta/\Delta$. In other words, if the initial error $\Delta$ is large relative to $\delta$, then the soundness error is small, meaning the verifier is very likely to reject. Unlike the classical sum-check protocol, which is fundamentally algebraic, our generalization exploits the metric structure of low-degree polynomials. The protocol can be instantiated over various domains, but is most natural over the complex numbers, where the analysis draws on the behavior of polynomials over the unit circle. We also analyze the protocol under the Fiat-Shamir transform, revealing a new intermediate security phenomenon that appears intrinsic to approximation. Prior work on verifiable computing for numerical tasks typically verifies that a prover exactly executed a computation that only approximates the desired function. In contrast, our protocols treat approximation as a first-class citizen: the verifier's checks are relaxed to accept prover messages that are only approximately consistent with the claimed result. This establishes the first black-box feasibility result for approximate arithmetic proof systems: the protocol compiler is independent of how arithmetic operations are implemented, requiring only that they satisfy error bounds. This opens a path to verifying approximate computations while sidestepping much of the prover overhead imposed by existing techniques that require encoding real-valued data into finite field arithmetic.
Metadata
- Available format(s)
-
PDF
- Category
- Cryptographic protocols
- Publication info
- A major revision of an IACR publication in EUROCRYPT 2026
- Keywords
- sum-check protocolinteractive proofsprobabilistic proofsverifiable computationapproximation
- Contact author(s)
-
dorbi @ post bgu ac il
zd @ nyu edu
shafi goldwasser @ gmail com
yuval ishai @ gmail com
yaelism @ gmail com
justin r thaler @ gmail com - History
- 2026-03-16: last of 2 revisions
- 2025-11-25: received
- See all versions
- Short URL
- https://ia.cr/2025/2152
- License
-
CC BY
BibTeX
@misc{cryptoeprint:2025/2152,
author = {Dor Bitan and Zachary DeStefano and Shafi Goldwasser and Yuval Ishai and Yael Tauman Kalai and Justin Thaler},
title = {Sum-check protocol for approximate computations},
howpublished = {Cryptology {ePrint} Archive, Paper 2025/2152},
year = {2025},
url = {https://eprint.iacr.org/2025/2152}
}