# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-08. Interactive version: https://trustbutveri.fyi/explorer/?mechanisms=M-0004,M-0022&implementations=M-0004:I-0003

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's readiness and open flaws. Readiness levels R0 to R4 describe one record's public evidence for its assessed use and are never combined. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and flaws) and https://trustbutveri.fyi/about/readiness/ (readiness levels).

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

None set. Every mechanism on the map was available.

## Overview

One row per mechanism, read from its record. Open flaws: critical / significant / minor. The last three columns are the editors' reading of what the verifier sees.

| Mechanism | Readiness | Prover | Attack testing | Hardware | Open flaws | Weights | Inputs and outputs | Training data |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Zero-knowledge proofs of inference / zkLLM | R2 | Adversarial | Analysis | None | 0 / 1 / 1 | hidden | shown | not involved |
| Side-channel suppression for isolated facilities | R1 | Adversarial | Analysis | Retrofit device | 0 / 3 / 0 | not involved | not involved | not involved |

## Claims

No claims chosen.

## Mechanisms

### Zero-knowledge proofs of inference

zkLLM is a GPU-accelerated zero-knowledge proof system that proves a large language model's output came from committed weights without revealing those weights. ([Zero-knowledge proofs of inference](https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/))

- Assessment: selected implementation [zkLLM](https://trustbutveri.fyi/implementations/zkllm/).
- Readiness: R2 Demonstrated, assessed for proving an output came from committed weights, against a prover who cheats.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: required. Attack testing: analysis. Category: Cryptographic & computational.
- What the verifier sees: model weights hidden; inputs and outputs shown; training data not involved. zkLLM's stated setting keeps model parameters private while the verifier supplies the prompt and checks the returned output.

### Side-channel suppression for isolated facilities

Shielding, filtering, jamming and inspecting an AI facility to limit hidden physical communication around monitored network links. ([Side-channel suppression for isolated facilities](https://trustbutveri.fyi/mechanisms/side-channel-suppression/))

- Assessment: mechanism family.
- Readiness: R1 Proposed, assessed for bounding physical covert channels out of a verified enclosure.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: retrofit device. Prover cooperation: partial. Attack testing: analysis. Category: Off-chip devices & sensors.
- What the verifier sees: model weights not involved; inputs and outputs not involved; training data not involved. Shields and filters a facility; it does not handle model data.


## Properties

**Built for an adversarial prover**

- Zero-knowledge proofs of inference
- Side-channel suppression for isolated facilities

**No new hardware needed**

- Zero-knowledge proofs of inference


## Attack testing

Published attempts to break a system, including those that found failures. Testing history does not establish that open flaws are resolved.

**Testing history**

- Zero-knowledge proofs of inference / zkLLM: Analysis
- Side-channel suppression for isolated facilities: Analysis


## Limits

**Open significant flaws**

- Reference code is interactive and runs prover and verifier together (open question, in zkLLM; https://trustbutveri.fyi/implementations/zkllm/#flaw-1) [2]. The README states that prover and verifier work "are implemented side-by-side", and that intermediate values written to files are for the prover's reference only. It says an industrial deployment would need to separate the two and apply Fiat–Shamir to make proofs non-interactive. The released code gives a verifier no standalone check.
- Supply-chain implants may evade inspection (theoretical argument, in Side-channel suppression for isolated facilities; https://trustbutveri.fyi/mechanisms/side-channel-suppression/#flaw-1) [9]. Cankaya identifies malicious hardware embedded deep in purchased components as a residual risk that visual inspection and disassembly may not catch. He notes that radiographic examination under high-security standards could mitigate it.
- Openings for airflow, power and optics weaken shielding (theoretical argument, in Side-channel suppression for isolated facilities; https://trustbutveri.fyi/mechanisms/side-channel-suppression/#flaw-2) [9]. Cankaya notes that keeping attenuation high while passing high-power airflow, cabling and optical links adds complexity beyond existing shielded-enclosure specifications.
- Inspection assumptions may not hold (open question, in Side-channel suppression for isolated facilities; https://trustbutveri.fyi/mechanisms/side-channel-suppression/#flaw-3) [9]. The design's statistical argument assumes that visual or disassembly inspection catches every flaw that is present in a sampled unit. Cankaya is unsure whether destructive teardowns are defence-dominant or offence-dominant.

**Family finding context**

- Context for zkLLM; applicability depends on the finding's scope. The proof covers a fixed-point approximation, not the floating-point model (open question, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-1) [1][3][4][5]. Current ZK inference systems prove a quantised version of the network. zkLLM scales values by 2^16 and reports small perplexity changes. Attestable reports quantising matrix multiplications to 8-bit integers while proving other operations in floating point. A verifier therefore learns about the proof-friendly variant, and must separately accept that this variant is the declared model. Trail of Bits built a ResNet-18 backdoor that is dormant in the full-precision model and active after ezkl's quantisation; whether it persists through proving was left for further investigation. A verification system design calls floating-point emulation in ZKPs an open problem.
- Context for zkLLM; applicability depends on the finding's scope. A proof speaks only for the computations that were proven (theoretical argument, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-2) [6]. Attestable writes that "a proof of some computation is not a proof of all computation", and that a proof cannot discover a datacenter that was never declared. Proofs of inference do not by themselves show that no other workload ran on the same or other hardware.

  Related mechanism: Proofs of useful work for capacity accounting (R1, not in the proposal). The record names proof-of-work accounting as the kind of compute accounting needed to show that proven inference was the only work done.
- Context for zkLLM; applicability depends on the finding's scope. The model architecture is disclosed (theoretical argument, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-3) [1][7]. ZKML "requires that the model architecture (but not weights) is revealed", and zkLLM assumes a publicly known model structure. Architecture can be commercially sensitive.
- Context for zkLLM; applicability depends on the finding's scope. Proofs do not bind computational effort (Hollow-LLM) (demonstrated attack, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-4) [8]. Researchers at the University of Southern California show that a proof of inference certifies that an output is consistent with committed weights under the declared architecture, but not how much computation produced it. In their Hollow-LLM attack, a provider keeps the declared architecture and parameter count but commits to "ghost weights". Some layers pass their inputs through unchanged, and wide layers carry the signal in a small subspace, so a much smaller inner model does the real work. The ghost weights satisfy the verification circuit and yield valid proofs.

  The authors ran the attack with the proof procedure of zkGPT, a separate ZK inference system, on a 6-layer, 512-dimensional transformer declared as up to 12 layers and 1,024 dimensions. Outputs were identical to the inner model's, and serving cost stayed at the inner model's level. An honest model of the declared size cost 2.4 times as much to prefill and 3.1 times as much to decode. Proving cost still grew with the declared architecture.

  The authors note that results may be served before any proof, with the provider building the witness only when a call is selected for audit. They describe their constructions as "compatible with state-of-the-art zkLLM pipelines", and state that the attack does not imply a flaw in the proof system itself. They propose challenge-based audits and ablation tests, which raise the cost of cheating but give no guarantee.

**Open minor flaws**

- Proves a fixed-point approximation of a publicly known architecture (theoretical argument, in zkLLM; https://trustbutveri.fyi/implementations/zkllm/#flaw-2) [1]. The prover's model must have a "publicly known structure". Tensors are discretised by scaling and rounding. The authors report perplexity changes of 0.008 to 0.09 on C4. The proof covers the quantised computation.

**Not yet demonstrated**

- Side-channel suppression for isolated facilities: R1 Proposed, assessed for bounding physical covert channels out of a verified enclosure


## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open flaw or a dependency. Pointers, not recommendations: each brings its own readiness level and flaws, and none is claimed to close a flaw.

None found.



## Dependencies

**Blockers**

- Zero-knowledge proofs of inference: Proving takes about 13 minutes (803 seconds) of A100 time per 2,048-token forward pass at 13B parameters, plus a one-time weight commitment of 16 to 21 minutes. (performance & compatibility) [1]
- Zero-knowledge proofs of inference: The repository was archived on 10 July 2025 and the author states there is no plan for upgrades or maintenance. (performance & compatibility) [2]
- Zero-knowledge proofs of inference: No security audit of the code has been carried out. (adversarial validation) [2]
- Side-channel suppression for isolated facilities: No prototype or red-team exists; the design is a first-pass viability study. (adversarial validation) [9]
- Side-channel suppression for isolated facilities: Volume costs of TEMPEST-grade power-line filters are uncertain, because existing products are mostly made to order. (performance & compatibility) [9]


## What the verifier sees

- Model weights: shown by none; depends on the design for none; hidden by Zero-knowledge proofs of inference; not involved in Side-channel suppression for isolated facilities; unspecified for none.
- Inputs and outputs: shown by Zero-knowledge proofs of inference; depends on the design for none; hidden by none; not involved in Side-channel suppression for isolated facilities; unspecified for none.
- Training data: shown by none; depends on the design for none; hidden by none; not involved in Zero-knowledge proofs of inference and Side-channel suppression for isolated facilities; unspecified for none.

## Implementations

- Zero-knowledge proofs of inference: [Attestable zero-knowledge inference prover](https://trustbutveri.fyi/implementations/attestable-zk-inference/) (R1, product); [EZKL](https://trustbutveri.fyi/implementations/ezkl/) (R2, product); [Low-trust AI compute verification system overview](https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/) (R1, proposed architecture); [zkLLM](https://trustbutveri.fyi/implementations/zkllm/) (R2, research prototype)
- Side-channel suppression for isolated facilities: [AI 2040 inference-only verification stack](https://trustbutveri.fyi/implementations/ai-2040-inference-only-verification-plan/) (R1, proposed architecture); [Low-trust AI compute verification system overview](https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/) (R1, proposed architecture); [RAND secure inference data center (SIDC) design](https://trustbutveri.fyi/implementations/rand-secure-inference-data-centers/) (R1, proposed architecture)

## Sources

1. zkLLM: Zero Knowledge Proofs for Large Language Models, H. Sun et al. (2024). https://doi.org/10.1145/3658644.3670334
2. zkllm-ccs2024: code for zkLLM: Zero Knowledge Proofs for Large Language Models, H. Sun (2024). https://github.com/jvhs0706/zkllm-ccs2024
3. Proving LLMs at Scale, Attestable (2026). https://attestable.com/blog/proving-llms-scale
4. Zkonduit EZKL Security Assessment, F. Casal et al. (2025). https://github.com/trailofbits/publications/blob/master/reviews/2025-03-zkonduit-ezkl-securityreview.pdf
5. A System Overview for Near-Term, Low-Trust AI Compute Verification, N. Cankaya (2026). https://intelligence.org/wp-content/uploads/2026/06/A-system-overview-for-near-term-low-trust-AI-compute-verification.pdf
6. Pacing AI Requires Proof, Attestable (2026). https://attestable.com/blog/pacing-ai-requires-proof
7. ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs, B.-J. Chen et al. (2024). https://doi.org/10.1145/3627703.3650088
8. Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference, C. Gong et al. (2026). https://arxiv.org/abs/2607.28884
9. Suppressing Side Channels in an Untrusted Data Center via Retrofitted Defenses, N. Cankaya (2026). https://techgov.intelligence.org/blog/suppressing-side-channels-in-an-untrusted-data-center-via-retrofitted-defenses
