# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-08. Interactive version: https://trustbutveri.fyi/explorer/?mechanisms=M-0004,M-0002,M-0007&hide=weights

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's readiness and open flaws. Readiness levels R0 to R4 describe one record's public evidence for its assessed use and are never combined. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and flaws) and https://trustbutveri.fyi/about/readiness/ (readiness levels).

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

- **Keep hidden from the verifier: model weights.** Removes mechanisms that show the asset to the verifier. Conditional or unspecified exposure stays with a note and needs checking against the privacy requirement. Model weights: the checked model's parameters. Inputs and outputs: the requests a deployed model serves and its responses. Training data: what a model was trained on. Each mechanism's exposure is the editors' reading of its record: shown, depends on the design (kept, with a note), hidden, not involved, or unspecified for a selected implementation. Code and configuration are not covered yet.

24 of 25 mechanisms on the map pass these filters.

## Overview

One row per mechanism, read from its record. Open flaws: critical / significant / minor. The last three columns are the editors' reading of what the verifier sees.

| Mechanism | Readiness | Prover | Attack testing | Hardware | Open flaws | Weights | Inputs and outputs | Training data |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Zero-knowledge proofs of inference | R2 | Adversarial | Independent red-team | None | 0 / 3 / 1 | hidden | shown | not involved |
| Deterministic and bit-exact inference | R3 | Adversarial | Analysis | None | 0 / 1 / 1 | depends | depends | not involved |
| Proofs of useful work for capacity accounting | R1 | Adversarial | Analysis | None | 0 / 3 / 0 | depends | depends | not involved |

## Claims

No claims chosen.

## Mechanisms

### Zero-knowledge proofs of inference

A prover produces a cryptographic proof that an output came from running a committed model on a given input, without revealing the weights. ([Zero-knowledge proofs of inference](https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/))

- Assessment: mechanism family.
- Readiness: R2 Demonstrated, assessed for proving a language model's output follows from committed weights, against a cheating prover.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: required. Attack testing: independent red-team. Category: Cryptographic & computational.
- What the verifier sees: model weights hidden; inputs and outputs shown; training data not involved. The weights stay committed and hidden; the verifier knows each input and output it checks.

### Deterministic and bit-exact inference

Making model inference reproducible bit for bit, so that a verifier's re-run must match the provider's output exactly rather than approximately. ([Deterministic and bit-exact inference](https://trustbutveri.fyi/mechanisms/deterministic-inference/))

- Assessment: mechanism family.
- Readiness: R3 In production, assessed for reproducing open-model inference from receipts in Gensyn's information-market service.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: required. Attack testing: analysis. Category: Cryptographic & computational.
- What the verifier sees: model weights depends; inputs and outputs depends; training data not involved. Exact replay needs the weights, configuration and replayed requests inside the recomputation environment. What the verifier sees depends on whether that environment keeps them confidential.
- Filter note: May show model weights, depending on the design. Exact replay needs the weights, configuration and replayed requests inside the recomputation environment. What the verifier sees depends on whether that environment keeps them confidential.

### Proofs of useful work for capacity accounting

Cryptographic evidence that a given amount of matrix-multiplication work was completed, proposed as one input to accounting for spare capacity on declared hardware. ([Proofs of useful work for capacity accounting](https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/))

- Assessment: mechanism family.
- Readiness: R1 Proposed, assessed for bounding the spare capacity of declared hardware that could run training.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: required. Attack testing: analysis. Category: Cryptographic & computational.
- What the verifier sees: model weights depends; inputs and outputs depends; training data not involved. Checking a sampled tile of a matrix multiplication reveals that tile, which may hold model or input data; the authors suggest a zero-knowledge proof when the matrices must stay private.
- Filter note: May show model weights, depending on the design. Checking a sampled tile of a matrix multiplication reveals that tile, which may hold model or input data; the authors suggest a zero-knowledge proof when the matrices must stay private.


## Properties

**In production**

- Deterministic and bit-exact inference: R3 In production, assessed for reproducing open-model inference from receipts in Gensyn's information-market service

**Built for an adversarial prover**

- Zero-knowledge proofs of inference
- Deterministic and bit-exact inference
- Proofs of useful work for capacity accounting

**No new hardware needed**

- Zero-knowledge proofs of inference
- Deterministic and bit-exact inference
- Proofs of useful work for capacity accounting


## Attack testing

Published attempts to break a system, including those that found failures. Testing history does not establish that open flaws are resolved.

**Testing history**

- Zero-knowledge proofs of inference: Independent red-team
- Deterministic and bit-exact inference: Analysis
- Proofs of useful work for capacity accounting: Analysis


## Limits

**Open significant flaws**

- The proof covers a fixed-point approximation, not the floating-point model (open question, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-1) [1][5][7][11]. Current ZK inference systems prove a quantised version of the network. zkLLM scales values by 2^16 and reports small perplexity changes. Attestable reports quantising matrix multiplications to 8-bit integers while proving other operations in floating point. A verifier therefore learns about the proof-friendly variant, and must separately accept that this variant is the declared model. Trail of Bits built a ResNet-18 backdoor that is dormant in the full-precision model and active after ezkl's quantisation; whether it persists through proving was left for further investigation. A verification system design calls floating-point emulation in ZKPs an open problem.
- A proof speaks only for the computations that were proven (theoretical argument, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-2) [12]. Attestable writes that "a proof of some computation is not a proof of all computation", and that a proof cannot discover a datacenter that was never declared. Proofs of inference do not by themselves show that no other workload ran on the same or other hardware.

  Related mechanism: Proofs of useful work for capacity accounting (R1, in the proposal). The record names proof-of-work accounting as the kind of compute accounting needed to show that proven inference was the only work done.
- Proofs do not bind computational effort (Hollow-LLM) (demonstrated attack, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-4) [10]. Researchers at the University of Southern California show that a proof of inference certifies that an output is consistent with committed weights under the declared architecture, but not how much computation produced it. In their Hollow-LLM attack, a provider keeps the declared architecture and parameter count but commits to "ghost weights". Some layers pass their inputs through unchanged, and wide layers carry the signal in a small subspace, so a much smaller inner model does the real work. The ghost weights satisfy the verification circuit and yield valid proofs.

  The authors ran the attack with the proof procedure of zkGPT, a separate ZK inference system, on a 6-layer, 512-dimensional transformer declared as up to 12 layers and 1,024 dimensions. Outputs were identical to the inner model's, and serving cost stayed at the inner model's level. An honest model of the declared size cost 2.4 times as much to prefill and 3.1 times as much to decode. Proving cost still grew with the declared architecture.

  The authors note that results may be served before any proof, with the provider building the witness only when a call is selected for audit. They describe their constructions as "compatible with state-of-the-art zkLLM pipelines", and state that the attack does not imply a flaw in the proof system itself. They propose challenge-based audits and ablation tests, which raise the cost of cheating but give no guarantee.
- Cross-hardware replay relies on reverse-engineered, closed behaviour (open question, in Deterministic and bit-exact inference; https://trustbutveri.fyi/mechanisms/deterministic-inference/#flaw-2) [13][15]. Emulating one GPU's rounding on another requires reverse-engineering tensor-core arithmetic and modelling proprietary kernel choices. Hawkeye covers a subset of NVIDIA architectures and states that attention and other higher-level operations need further reverse engineering. For the bit-exact emulator, a proprietary Hopper kernel family is an open edge case.
- Proves that work was done, not that no capacity remains (theoretical argument, in Proofs of useful work for capacity accounting; https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/#flaw-1) [12]. Proof-of-work accounting bounds unmonitored compute only relative to an estimate of what the actor has. Attestable states that the verifier "needs a credible estimate of the compute available" to the actor, and that a proof "cannot discover a datacenter that was never declared".

  Related mechanism: Chip registries and manufacturing records (R1, not in the proposal). A registry of chips is one basis for the estimate of available compute that the flaw's source says the verifier needs.

  Related mechanism: Remote detection of data centres (R1, not in the proposal). Looks for data centres that were never declared, which a proof cannot discover.
- Security rests on new hardness assumptions (open question, in Proofs of useful work for capacity accounting; https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/#flaw-2) [24][25]. Komargodski and Weinstein base security on hardness assumptions about batches of low-rank random linear equations, and list PoUW "from more standard or well-studied assumptions" as an open problem. Pearl's floating-point variant introduces a further "quantized-subspace hardness" assumption.
- Known shortcuts let a miner claim somewhat more work than it did (theoretical argument, in Proofs of useful work for capacity accounting; https://trustbutveri.fyi/mechanisms/proofs-of-useful-work/#flaw-3) [25]. Pearl's specification lists known mining speedups: crafted inputs, precision shortcuts, seed grinding, work reuse, and faster kernels or hardware. A policy check caps the summands a miner may skip at one-sixteenth of those in a tile. For capacity bounding, any gap between work proven and work possible leaves spare capacity.

**Open minor flaws**

- The model architecture is disclosed (theoretical argument, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-3) [1][3]. ZKML "requires that the model architecture (but not weights) is revealed", and zkLLM assumes a publicly known model structure. Architecture can be commercially sensitive.
- Some kernels remain genuinely nondeterministic (open question, in Deterministic and bit-exact inference; https://trustbutveri.fyi/mechanisms/deterministic-inference/#flaw-1) [13]. The bit-exact work separates kernels that are deterministic but not batch-invariant from truly nondeterministic ones that use atomic functions. Some integer de-quantization kernels use atomic additions and remain nondeterministic, so exact replay needs backends that avoid them.

**Not yet demonstrated**

- Proofs of useful work for capacity accounting: R1 Proposed, assessed for bounding the spare capacity of declared hardware that could run training


## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open flaw or a dependency. Pointers, not recommendations: each brings its own readiness level and flaws, and none is claimed to close a flaw.

- **Chip registries and manufacturing records** (R1 Proposed, assessed for a checkable record of which chips were made and who declared owning them)
  - Bears on the open significant flaw "Proves that work was done, not that no capacity remains" in Proofs of useful work for capacity accounting. A registry of chips is one basis for the estimate of available compute that the flaw's source says the verifier needs.
- **Remote detection of data centres** (R1 Proposed, assessed for finding undeclared data centres above an agreed compute threshold)
  - Bears on the open significant flaw "Proves that work was done, not that no capacity remains" in Proofs of useful work for capacity accounting. Looks for data centres that were never declared, which a proof cannot discover.


## Dependencies

**Blockers**

- Zero-knowledge proofs of inference: Proving takes about 13 minutes (803 seconds) per 2,048-token forward pass of a 13B model on one A100, and a verification system design calls the overhead heavy. (performance & compatibility) [1][11]
- Zero-knowledge proofs of inference: ZKML and zkLLM prove fixed-point arithmetic, and floating-point emulation in ZKPs is described as an open problem. (performance & compatibility) [1][3][11]
- Zero-knowledge proofs of inference: zkLLM's code is unaudited, interactive and archived; the one audited ZK inference library, ezkl, had high-severity circuit soundness bugs before its fixes. (adversarial validation) [2][7]
- Zero-knowledge proofs of inference: Showing that proven inference was the only work done needs a compute-accounting mechanism such as proof-of-work accounting, which is only proposed. (coverage & hidden compute; waits on Proofs of useful work for capacity accounting) [12]
- Deterministic and bit-exact inference: Batch-invariant kernels cost throughput: in Thinking Machines' Qwen3-8B test, an improved deterministic build took 42 s against 26 s for vLLM's default, and SGLang reports an average 34.35% slowdown on its FlashInfer and FlashAttention 3 backends. (performance & compatibility) [14][16]
- Deterministic and bit-exact inference: Coverage is incomplete: the bit-exact emulator targets dense blocks on NVIDIA GPUs and excludes mixture-of-experts inference and training, and vLLM's batch-invariant mode is in beta, with open work on AMD hardware and speculative decoding. (performance & compatibility) [13][17][27]
- Deterministic and bit-exact inference: Amodo's status page for the AI 2040 verification plan rates a reproducible inference stack for that plan as 'not started'. (performance & compatibility) [28]
- Deterministic and bit-exact inference: Exact replay requires the prover to disclose weights, software versions, parallelism and batch sizes to whoever recomputes. (privacy & leakage) [11][13]
- Proofs of useful work for capacity accounting: Bounding spare capacity needs a credible estimate of the compute available to the actor, including third-party access. (capacity bounds) [12]
- Proofs of useful work for capacity accounting: Proofs of work cannot find facilities that were never declared. (coverage & hidden compute) [12]
- Proofs of useful work for capacity accounting: As of September 2026 no implementation, demonstration or independent evaluation of proofs of work for capacity bounding has been published. (adversarial validation)


## What the verifier sees

- Model weights: shown by none; depends on the design for Deterministic and bit-exact inference and Proofs of useful work for capacity accounting; hidden by Zero-knowledge proofs of inference; not involved in none; unspecified for none.
- Inputs and outputs: shown by Zero-knowledge proofs of inference; depends on the design for Deterministic and bit-exact inference and Proofs of useful work for capacity accounting; hidden by none; not involved in none; unspecified for none.
- Training data: shown by none; depends on the design for none; hidden by none; not involved in Zero-knowledge proofs of inference, Deterministic and bit-exact inference and Proofs of useful work for capacity accounting; unspecified for none.

## Implementations

- Zero-knowledge proofs of inference: [Attestable zero-knowledge inference prover](https://trustbutveri.fyi/implementations/attestable-zk-inference/) (R1, product); [EZKL](https://trustbutveri.fyi/implementations/ezkl/) (R2, product); [Low-trust AI compute verification system overview](https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/) (R1, proposed architecture); [zkLLM](https://trustbutveri.fyi/implementations/zkllm/) (R2, research prototype)
- Deterministic and bit-exact inference: [Batch-invariant inference kernels (Thinking Machines)](https://trustbutveri.fyi/implementations/batch-invariant-inference-kernels/) (R2, open-source project); [Verde and RepOps (Gensyn)](https://trustbutveri.fyi/implementations/gensyn-verde-repops/) (R3, product); [Low-trust AI compute verification system overview](https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/) (R1, proposed architecture)
- Proofs of useful work for capacity accounting: [Pearl proof-of-useful-work blockchain](https://trustbutveri.fyi/implementations/pearl-proof-of-useful-work/) (R3, open-source project)

## Sources

1. zkLLM: Zero Knowledge Proofs for Large Language Models, H. Sun et al. (2024). https://doi.org/10.1145/3658644.3670334
2. zkllm-ccs2024: code for zkLLM: Zero Knowledge Proofs for Large Language Models, H. Sun (2024). https://github.com/jvhs0706/zkllm-ccs2024
3. ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs, B.-J. Chen et al. (2024). https://doi.org/10.1145/3627703.3650088
4. NanoZK: Privacy-Preserving Verifiable Inference for Large Language Models via Layerwise Zero-Knowledge Proofs, Z. Wang (2026). https://arxiv.org/abs/2603.18046
5. Proving LLMs at Scale, Attestable (2026). https://attestable.com/blog/proving-llms-scale
6. Verifiable evaluations of machine learning models using zkSNARKs, T. South et al. (2024). https://arxiv.org/abs/2402.02675
7. Zkonduit EZKL Security Assessment, F. Casal et al. (2025). https://github.com/trailofbits/publications/blob/master/reviews/2025-03-zkonduit-ezkl-securityreview.pdf
8. DeepProve-1: The First zkML System to Prove a Full LLM Inference, Lagrange Labs (2025). https://lagrange.dev/blog/deepprove-1
9. Lagrange-Labs/deep-prove (GitHub repository), Lagrange Labs (2026). https://github.com/Lagrange-Labs/deep-prove
10. Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference, C. Gong et al. (2026). https://arxiv.org/abs/2607.28884
11. A System Overview for Near-Term, Low-Trust AI Compute Verification, N. Cankaya (2026). https://intelligence.org/wp-content/uploads/2026/06/A-system-overview-for-near-term-low-trust-AI-compute-verification.pdf
12. Pacing AI Requires Proof, Attestable (2026). https://attestable.com/blog/pacing-ai-requires-proof
13. Bit-Exact AI Inference Verification Without Performance Tradeoffs, N. Cankaya (2026). https://arxiv.org/abs/2606.00279
14. Defeating Nondeterminism in LLM Inference, H. He & Thinking Machines Lab (2025). https://thinkingmachines.ai/blog/defeating-nondeterminism-in-llm-inference/
15. Hawkeye: Reproducing GPU-Level Non-Determinism, E. Badash et al. (2026). https://proceedings.mlsys.org/paper_files/paper/2026/hash/e217c271a57c365a246b0ad39e668ba8-Abstract-Conference.html
16. Towards Deterministic Inference in SGLang and Reproducible RL Training, The SGLang Team (2025). https://www.lmsys.org/blog/2025-09-22-sglang-deterministic/
17. Batch Invariance (vLLM documentation), vLLM project (2026). https://github.com/vllm-project/vllm/blob/main/docs/features/batch_invariance.md
18. gensyn-ai/ree: Gensyn Reproducible Execution Environment (GitHub repository), Gensyn (2026). https://github.com/gensyn-ai/ree
19. EigenCloud Brings Verifiable AI to Mass Market with EigenAI and EigenCompute Launches, EigenCloud (2025). https://www.eigenlabs.org/blog/eigencloud-brings-verifiable-ai-to-mass-market-with-eigenai-and-eigencompute-launches/
20. Building Delphi: Pricing, Settlement, and Agentic Trading, D. Jedamski (2026). https://www.gensyn.ai/blog/building-delphi-pricing-settlement-and-agentic-trading
21. Reproducible Execution Environment (REE) (Gensyn documentation), Gensyn (2026). https://docs.gensyn.ai/tech
22. What is Delphi? (Delphi documentation), Gensyn (2026). https://docs.delphi.fyi/
23. Mechanisms to Verify International Agreements About AI Development, A. Scher & L. Thiergart (2025). https://arxiv.org/abs/2506.15867
24. Proofs of Useful Work from Arbitrary Matrix Multiplication, I. Komargodski & O. Weinstein (2025). https://arxiv.org/abs/2504.09971
25. Pearl Floating Point Scheme Specification, Pearl Research Team (2026). https://pearlresearch.ai/Pearl_Whitepaper.pdf
26. pearl: Monorepo for the Pearl network, Pearl Research Labs (2026). https://github.com/pearl-research-labs/pearl
27. [Feature]: Batch Invariant Feature and Performance Optimization (vLLM issue #27433), vLLM project contributors (2025). https://github.com/vllm-project/vllm/issues/27433
28. AI 2040 Plan A — Verification SITREP, Amodo Design (2026). https://amododesign.com/ai-verification/plan-a-sitrep/
