# AI verification proposal

A proposal built with the Proposal Explorer of the AI Verification Tech Map (https://trustbutveri.fyi/), from its records of 2026-10-08. Interactive version: https://trustbutveri.fyi/explorer/?mechanisms=M-0004,M-0017&implementations=M-0004:I-0005

How to read it: a claim is something one party wants to verify about another's AI hardware or software. A mechanism is a general technique for verifying claims; it is "aimed at" a claim when that is its direct purpose, and "supporting" when it contributes without being aimed at it. A claim is addressed when a mechanism in the proposal is aimed at it and is not excluded by the filters; addressed does not mean verified, so check that mechanism's readiness and open flaws. Readiness levels R0 to R4 describe one record's public evidence for its assessed use and are never combined. Definitions: https://trustbutveri.fyi/about/methodology/ (roles, properties and flaws) and https://trustbutveri.fyi/about/readiness/ (readiness levels).

## Filters

Filters apply to mechanisms only and describe the setting the proposal is for.

None set. Every mechanism on the map was available.

## Overview

One row per mechanism, read from its record. Open flaws: critical / significant / minor. The last three columns are the editors' reading of what the verifier sees.

| Mechanism | Readiness | Prover | Attack testing | Hardware | Open flaws | Weights | Inputs and outputs | Training data |
| --- | --- | --- | --- | --- | --- | --- | --- | --- |
| Zero-knowledge proofs of inference / Attestable zero-knowledge inference prover | R1 | Adversarial | None | None | 0 / 2 / 0 | unspecified | unspecified | unspecified |
| Tamper evidence for verifier devices | R2 | Adversarial | Analysis | Retrofit device | 0 / 3 / 0 | not involved | not involved | not involved |

## Claims

No claims chosen.

## Mechanisms

### Zero-knowledge proofs of inference

Attestable's zero-knowledge prover, which the company reports proves large language model outputs came from committed weights at tens of tokens per second. ([Zero-knowledge proofs of inference](https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/))

- Assessment: selected implementation [Attestable zero-knowledge inference prover](https://trustbutveri.fyi/implementations/attestable-zk-inference/).
- Readiness: R1 Proposed, assessed for proving an output came from committed weights.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: none. Prover cooperation: required. Attack testing: none. Category: Cryptographic & computational.
- What the verifier sees: model weights unspecified; inputs and outputs unspecified; training data unspecified. This Explorer has no asset-specific exposure assessment for this implementation. Check its source and deployment assumptions.

### Tamper evidence for verifier devices

Enclosures, seals and sensors that make physical interference with verification hardware either visible or self-defeating. ([Tamper evidence for verifier devices](https://trustbutveri.fyi/mechanisms/tamper-evidence-for-verifier-devices/))

- Assessment: mechanism family.
- Readiness: R2 Demonstrated, assessed for detecting probing of proposed verifier hardware, using server and electronics prototypes as evidence.
- Claims in this proposal: none of them.
- Threat model: adversarial prover. Hardware: retrofit device. Prover cooperation: partial. Attack testing: analysis. Category: Off-chip devices & sensors.
- What the verifier sees: model weights not involved; inputs and outputs not involved; training data not involved. Protects verifier devices; it does not handle model data.


## Properties

**Built for an adversarial prover**

- Zero-knowledge proofs of inference
- Tamper evidence for verifier devices

**No new hardware needed**

- Zero-knowledge proofs of inference


## Attack testing

Published attempts to break a system, including those that found failures. Testing history does not establish that open flaws are resolved.

**Testing history**

- Tamper evidence for verifier devices: Analysis


## Limits

**Open significant flaws**

- Proves an 8-bit quantised variant of the model (open question, in Attestable zero-knowledge inference prover; https://trustbutveri.fyi/implementations/attestable-zk-inference/#flaw-1) [1]. Attestable reports that matrix multiplications are dynamically quantised to 8-bit integers, while non-linear operations are proven in floating point. It reports that its IFEval result "shows where the current quantization still needs improvement". The proven model is therefore a quantised variant, which a verifier must accept as the declared model.
- A proof covers only the computation it is about (theoretical argument, in Attestable zero-knowledge inference prover; https://trustbutveri.fyi/implementations/attestable-zk-inference/#flaw-2) [2]. Attestable states that "a proof of some computation is not a proof of all computation" and that a proof "cannot discover a datacenter that was never declared".
- Seals are often defeated with simple methods (demonstrated attack, in Tamper evidence for verifier devices; https://trustbutveri.fyi/mechanisms/tamper-evidence-for-verifier-devices/#flaw-1) [15][16]. Mechanism-class evidence. Published defeats of general security seals. They warn about proposed verifier-device seals, but do not demonstrate defeat of an AI verification enclosure or sensor. In 1996 a Los Alamos vulnerability assessment defeated all 94 security seals it examined, with 132 defeats in total, using rapid, inexpensive, low-tech methods. It found that seal cost did not predict security. In 2001 Johnston reported that high-tech seals are often easier to defeat than low-tech ones.
- Security depends on inspection protocols (theoretical argument, in Tamper evidence for verifier devices; https://trustbutveri.fyi/mechanisms/tamper-evidence-for-verifier-devices/#flaw-2) [14][16]. Mechanism-class evidence. An inspection and protocol requirement drawn from safeguards and enclosure studies, not a reported break of a deployed AI verifier. Johnston argues that a seal is no better than the protocols for using it, and that inspectors are usually given little useful information on how to detect tampering. The Sandia survey notes that larger enclosures are hard to inspect fully and that sensor data must be authenticated.
- Attack classes outside published models (open question, in Tamper evidence for verifier devices; https://trustbutveri.fyi/mechanisms/tamper-evidence-for-verifier-devices/#flaw-3) [9][10][17]. Mechanism-class evidence. The radio compensation result is emulated using measured channel data under a known-reference attacker model. It is not a physical bypass demonstration against an AI verifier enclosure. The authors of the batteryless cover say they cannot assess chemical-solvent attacks, which exceed their expertise, and deem cover removal impractical. Anti-Tamper Radio's reference can drift as the environment or measurement system ages; the authors suggest gradually renewing the reference. A 2025 follow-up by some of the same authors shows, by emulation on measured channel data, that an attacker who knows the reference channel and the needle's effect on it could inject a signal that cancels the change caused by a needle insertion. It proposes a reconfigurable intelligent surface that randomizes the channel as a countermeasure.

**Family finding context**

- Context for Attestable zero-knowledge inference prover; applicability depends on the finding's scope. The proof covers a fixed-point approximation, not the floating-point model (open question, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-1) [1][4][5][6]. Current ZK inference systems prove a quantised version of the network. zkLLM scales values by 2^16 and reports small perplexity changes. Attestable reports quantising matrix multiplications to 8-bit integers while proving other operations in floating point. A verifier therefore learns about the proof-friendly variant, and must separately accept that this variant is the declared model. Trail of Bits built a ResNet-18 backdoor that is dormant in the full-precision model and active after ezkl's quantisation; whether it persists through proving was left for further investigation. A verification system design calls floating-point emulation in ZKPs an open problem.
- Context for Attestable zero-knowledge inference prover; applicability depends on the finding's scope. A proof speaks only for the computations that were proven (theoretical argument, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-2) [2]. Attestable writes that "a proof of some computation is not a proof of all computation", and that a proof cannot discover a datacenter that was never declared. Proofs of inference do not by themselves show that no other workload ran on the same or other hardware.

  Related mechanism: Proofs of useful work for capacity accounting (R1, not in the proposal). The record names proof-of-work accounting as the kind of compute accounting needed to show that proven inference was the only work done.
- Context for Attestable zero-knowledge inference prover; applicability depends on the finding's scope. The model architecture is disclosed (theoretical argument, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-3) [4][7]. ZKML "requires that the model architecture (but not weights) is revealed", and zkLLM assumes a publicly known model structure. Architecture can be commercially sensitive.
- Context for Attestable zero-knowledge inference prover; applicability depends on the finding's scope. Proofs do not bind computational effort (Hollow-LLM) (demonstrated attack, in Zero-knowledge proofs of inference; https://trustbutveri.fyi/mechanisms/zk-proofs-of-inference/#flaw-4) [8]. Researchers at the University of Southern California show that a proof of inference certifies that an output is consistent with committed weights under the declared architecture, but not how much computation produced it. In their Hollow-LLM attack, a provider keeps the declared architecture and parameter count but commits to "ghost weights". Some layers pass their inputs through unchanged, and wide layers carry the signal in a small subspace, so a much smaller inner model does the real work. The ghost weights satisfy the verification circuit and yield valid proofs.

  The authors ran the attack with the proof procedure of zkGPT, a separate ZK inference system, on a 6-layer, 512-dimensional transformer declared as up to 12 layers and 1,024 dimensions. Outputs were identical to the inner model's, and serving cost stayed at the inner model's level. An honest model of the declared size cost 2.4 times as much to prefill and 3.1 times as much to decode. Proving cost still grew with the declared architecture.

  The authors note that results may be served before any proof, with the provider building the witness only when a call is selected for audit. They describe their constructions as "compatible with state-of-the-art zkLLM pipelines", and state that the attack does not imply a flaw in the proof system itself. They propose challenge-based audits and ablation tests, which raise the cost of cheating but give no guarantee.

**Not yet demonstrated**

- Zero-knowledge proofs of inference: R1 Proposed, assessed for proving an output came from committed weights


## Possible additions

Mechanisms on the map, not in the proposal, that the records connect to an unaddressed or partly addressed claim, an open flaw or a dependency. Pointers, not recommendations: each brings its own readiness level and flaws, and none is claimed to close a flaw.

- **Proofs of useful work for capacity accounting** (R1 Proposed, assessed for bounding the spare capacity of declared hardware that could run training)
  - Zero-knowledge proofs of inference waits on it: Covering computation that is not proven relies on proof-of-work accounting, which Attestable has only proposed.


## Dependencies

**Blockers**

- Zero-knowledge proofs of inference: No paper, protocol specification or code is public, so the reported results cannot be reproduced. (adversarial validation) [1]
- Zero-knowledge proofs of inference: Attestable reports a context window limited to 16K tokens. (performance & compatibility) [1]
- Zero-knowledge proofs of inference: Covering computation that is not proven relies on proof-of-work accounting, which Attestable has only proposed. (coverage & hidden compute; waits on Proofs of useful work for capacity accounting) [2]
- Tamper evidence for verifier devices: No tamper-evident enclosure has been designed for AI verifier hardware at retrofit scale. (hardware trust) [6]
- Tamper evidence for verifier devices: Battery-backed designs add bulk, limit operating temperature (+10 °C to +35 °C for the IBM 4765) and complicate transport. (performance & compatibility) [10]
- Tamper evidence for verifier devices: Active monitoring needs power, and visual inspection of large enclosures faces access limits. (access & governance) [14]
- Tamper evidence for verifier devices: No evaluation has been published in the AI verification setting. (adversarial validation) [6]


## What the verifier sees

- Model weights: shown by none; depends on the design for none; hidden by none; not involved in Tamper evidence for verifier devices; unspecified for Zero-knowledge proofs of inference.
- Inputs and outputs: shown by none; depends on the design for none; hidden by none; not involved in Tamper evidence for verifier devices; unspecified for Zero-knowledge proofs of inference.
- Training data: shown by none; depends on the design for none; hidden by none; not involved in Tamper evidence for verifier devices; unspecified for Zero-knowledge proofs of inference.

## Implementations

- Zero-knowledge proofs of inference: [Attestable zero-knowledge inference prover](https://trustbutveri.fyi/implementations/attestable-zk-inference/) (R1, product); [EZKL](https://trustbutveri.fyi/implementations/ezkl/) (R2, product); [Low-trust AI compute verification system overview](https://trustbutveri.fyi/implementations/low-trust-compute-verification-system-overview/) (R1, proposed architecture); [zkLLM](https://trustbutveri.fyi/implementations/zkllm/) (R2, research prototype)
- Tamper evidence for verifier devices: [AI 2040 inference-only verification stack](https://trustbutveri.fyi/implementations/ai-2040-inference-only-verification-plan/) (R1, proposed architecture)

## Sources

1. Proving LLMs at Scale, Attestable (2026). https://attestable.com/blog/proving-llms-scale
2. Pacing AI Requires Proof, Attestable (2026). https://attestable.com/blog/pacing-ai-requires-proof
3. From Verifiability to Model-Weight Security, Attestable (2026). https://attestable.com/blog/model-weights-security
4. zkLLM: Zero Knowledge Proofs for Large Language Models, H. Sun et al. (2024). https://doi.org/10.1145/3658644.3670334
5. Zkonduit EZKL Security Assessment, F. Casal et al. (2025). https://github.com/trailofbits/publications/blob/master/reviews/2025-03-zkonduit-ezkl-securityreview.pdf
6. A System Overview for Near-Term, Low-Trust AI Compute Verification, N. Cankaya (2026). https://intelligence.org/wp-content/uploads/2026/06/A-system-overview-for-near-term-low-trust-AI-compute-verification.pdf
7. ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs, B.-J. Chen et al. (2024). https://doi.org/10.1145/3627703.3650088
8. Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference, C. Gong et al. (2026). https://arxiv.org/abs/2607.28884
9. Anti-Tamper Radio: System-Level Tamper Detection for Computing Systems, P. Staat et al. (2022). https://ieeexplore.ieee.org/document/9833631/
10. Secure Physical Enclosures from Covers with Tamper-Resistance, V. Immler et al. (2019). https://tches.iacr.org/index.php/TCHES/article/view/7334
11. ImpedanceVerif: On-Chip Impedance Sensing for System-Level Tampering Detection, T. Mosavirik et al. (2023). https://eprint.iacr.org/2022/946
12. IBM 4765 Cryptographic Coprocessor Security Module: Security Policy, IBM Corporation (2012). https://csrc.nist.gov/csrc/media/projects/cryptographic-module-validation-program/documents/security-policies/140sp1505.pdf
13. PHYSEC SEAL: Change detection for maximum safety, PHYSEC GmbH (2026). https://www.physec.de/en/solutions/physec-seal/
14. Tamper-Indicating Enclosures, A Current Survey, H. A. Smartt & Z. N. Gastelum (2015). https://www.osti.gov/servlets/purl/1256541
15. Physical Security and Tamper-Indicating Devices, R. G. Johnston & A. R. E. Garcia (1996). https://www.osti.gov/servlets/purl/459707
16. Tamper Detection for Safeguards and Treaty Monitoring: Fantasies, Realities, and Potentials, R. G. Johnston (2001). https://www.nonproliferation.org/wp-content/uploads/npr/81john.pdf
17. Anti-Tamper Radio Meets Reconfigurable Intelligent Surface for System-Level Tamper Detection, M. S. Tabar et al. (2025). https://arxiv.org/abs/2503.14279
