Implementation · Attestable zero-knowledge inference prover
Evidence & limits
On this page
R1Proposed for proving an output came from committed weights
Attestable states the claim, its security basis and its limits, but has published no code, protocol description or artifact.
Assessed use: proving an output came from committed weights
Rubric assessment
- R1 met: Attestable publicly states the claim proven (an output y = F(W, x, r) for committed weights W, input x and seed r), its security basis (hash functions only, 100-bit security) and its limits 1. It also states the verification uses it proposes 2 3.
- R2 not met. The rubric excludes results that are claimed but not public or not reproducible, and Attestable's figures are published without code, a protocol description or an artifact 1.
- A public working implementation, or reproducible published end-to-end results, such as a paper with a protocol specification and benchmarks others can rerun.
- Any independent security analysis of the proof system.
Assessed 2026-09-25 against rubric v1.1.
Evidence
All results come from Attestable's own blog. Attestable reports these figures on a single NVIDIA H100 GPU:
- Proofs. Proof sizes range from 4.35 to 7.92 MiB, and CPU verification takes 157 to 648 milliseconds 1.
- Throughput. For a 31-billion-parameter Gemma model, it reports proving 53 tokens per second for one 16K-token sequence, and 77 tokens per second across four 4K-token sequences 1.
- Accuracy. It reports that its quantisation preserved performance on the GPQA Diamond reasoning benchmark better than a standard INT8 baseline 1.
- Comparison. It sets these figures against an ezkl result from the end of 2023: 16 minutes to prove a 1-million-parameter model on a CPU 1.
As of September 2026 no independent reproduction of these results has been published.
Limitations
Attestable lists its current limits:
- a context window of up to 16K tokens;
- matrix multiplications quantised to 8-bit integers 1.
It reports that its IFEval result "shows where the current quantization still needs improvement" 1.
On coverage, Attestable writes that "a proof of some computation is not a proof of all computation" 2. It proposes pairing inference proofs with proof-of-work accounting, which would need "a credible estimate of the compute available" to the actor 2.
For the firewall proposal, Attestable lists threats that the proofs do not address:
- physical attacks, such as probing memory buses;
- leakage through timing, packet sizes, power and proof-generation latency 3.
As of September 2026 the protocol is unpublished, and no attack on it or security analysis of it has been published.
Known flaws
Blockers
No paper, protocol specification or code is public, so the reported results cannot be reproduced.
Attestable reports a context window limited to 16K tokens.
Covering computation that is not proven relies on proof-of-work accounting, which Attestable has only proposed.