Implementation · Attestable zero-knowledge inference prover

Evidence & limits

On this page

R1Proposed for proving an output came from committed weights

Attestable states the claim, its security basis and its limits, but has published no code, protocol description or artifact.

Assessed use: proving an output came from committed weights

Rubric assessment

  • R1 met: Attestable publicly states the claim proven (an output y = F(W, x, r) for committed weights W, input x and seed r), its security basis (hash functions only, 100-bit security) and its limits 1. It also states the verification uses it proposes 2 3.
  • R2 not met. The rubric excludes results that are claimed but not public or not reproducible, and Attestable's figures are published without code, a protocol description or an artifact 1.
Gaps to the next level
  • A public working implementation, or reproducible published end-to-end results, such as a paper with a protocol specification and benchmarks others can rerun.
  • Any independent security analysis of the proof system.

Assessed 2026-09-25 against rubric v1.1.

Evidence

All results come from Attestable's own blog. Attestable reports these figures on a single NVIDIA H100 GPU:

  • Proofs. Proof sizes range from 4.35 to 7.92 MiB, and CPU verification takes 157 to 648 milliseconds 1.
  • Throughput. For a 31-billion-parameter Gemma model, it reports proving 53 tokens per second for one 16K-token sequence, and 77 tokens per second across four 4K-token sequences 1.
  • Accuracy. It reports that its quantisation preserved performance on the GPQA Diamond reasoning benchmark better than a standard INT8 baseline 1.
  • Comparison. It sets these figures against an ezkl result from the end of 2023: 16 minutes to prove a 1-million-parameter model on a CPU 1.

As of September 2026 no independent reproduction of these results has been published.

Limitations

Attestable lists its current limits:

  • a context window of up to 16K tokens;
  • matrix multiplications quantised to 8-bit integers 1.

It reports that its IFEval result "shows where the current quantization still needs improvement" 1.

On coverage, Attestable writes that "a proof of some computation is not a proof of all computation" 2. It proposes pairing inference proofs with proof-of-work accounting, which would need "a credible estimate of the compute available" to the actor 2.

For the firewall proposal, Attestable lists threats that the proofs do not address:

  • physical attacks, such as probing memory buses;
  • leakage through timing, packet sizes, power and proof-generation latency 3.

As of September 2026 the protocol is unpublished, and no attack on it or security analysis of it has been published.

Known flaws

Blockers

Search

Full search page