Pascal Berrang

AI Safety · Zero-Knowledge Proofs · Cryptography

profile.jpg
Birmingham, UK and Munich, Germany

My research applies cryptography and zero-knowledge proofs to problems in AI security, privacy, and safety. I build tools that let us verify properties of AI systems — without revealing the models or data behind them. I’m currently focused on moving this work from research into practice, and on AI safety and technical AI governance more broadly.

I am an Associate Professor in Computer Security at the University of Birmingham, UK and Co-Founder & CTO of Zeroth Research, a non-profit making intelligent systems safe, with mathematical certainty.

I currently lead an ARIA-funded project on privacy-preserving AI safety verification (with Mirco Giacobbe and Yang Zhang), developing foundations for verifying AI safety guarantees without revealing sensitive model or data details. I also lead a Foresight Institute-funded project on ZK attestation for AI security (with Luca Arnaboldi), and an InnovateUK CyberASAP-funded project on identifying money laundering on the blockchain.

I am a SPAR mentor for two Spring 2026 projects bridging AI safety and zero-knowledge proofs: Proving Model Equality in Zero-Knowledge and Proving Safety Properties of Guardrail Models (with Luca Arnaboldi).

Previously, I completed my PhD in the Information Security and Cryptography Group at Saarland University under supervision of Michael Backes. My thesis, Quantifying and Mitigating Privacy Risks in Biomedical Data, received the Dr. Eduard-Martin Award 2019 for the best PhD thesis in mathematics and computer science.

research areas

Verifiable AI Safety Zero-Knowledge Proofs for AI & Blockchain Security & Privacy of Machine Learning Blockchain Security & Compliance

news

Feb 01, 2026 Mentoring two SPAR Spring 2026 projects: Proving Model Equality in Zero-Knowledge and Proving Safety Properties of Guardrail Models.
Jan 15, 2026 Paper accepted at WWW 2026: Evasion Under Blockchain Sanctions.
Jan 01, 2026 Awarded a Foresight Institute grant for ZK attestation for AI security (with Luca Arnaboldi).
Jul 01, 2025 Launched Zeroth Research, a non-profit making intelligent systems safe, with mathematical certainty.
Apr 01, 2025 Awarded ARIA funding for our project on privacy-preserving AI safety verification using zero-knowledge proofs (with Mirco Giacobbe and Yang Zhang).

selected publications

  1. arXiv
    Zero-Knowledge Model Checking
    Pascal Berrang, Mirco Giacobbe, Jacob Swales, and 1 more author
    2026
  2. arXiv
    Beyond Red-Teaming: Formal Guarantees of LLM Guardrail Classifiers
    Nikita Kezins, Urbas Ekka, Pascal Berrang, and 1 more author
    2026
  3. PoPETs
    Revisiting Assumptions for Membership Inference on Summary Statistics
    Pascal Berrang, Mark Ryan, and Kiera Wooldridge
    Proceedings on Privacy Enhancing Technologies (PoPETs), 2026
  4. PoPETs
    SoK: Descriptive Statistics Under Local Differential Privacy
    René Raab, Pascal Berrang, Paul Gerhart, and 1 more author
    Proceedings on Privacy Enhancing Technologies (PoPETs), 2025
  5. USENIX
    Quantifying Privacy Risks of Prompts in Visual Prompt Learning
    Yixin Wu, Rui Wen, Michael Backes, and 4 more authors
    In Proceedings of the 33rd USENIX Security Symposium (Security), 2024