Mechanism · Zero-knowledge proofs of inference
The proof covers a fixed-point approximation, not the floating-point model
On this page
SignificantOpen questionOpen
Current ZK inference systems prove a quantised version of the network. zkLLM scales values by 2^16 and reports small perplexity changes 1. Attestable reports quantising matrix multiplications to 8-bit integers while proving other operations in floating point 8. A verifier therefore learns about the proof-friendly variant, and must separately accept that this variant is the declared model. Trail of Bits built a ResNet-18 backdoor that is dormant in the full-precision model and active after ezkl's quantisation; whether it persists through proving was left for further investigation 6. A verification system design calls floating-point emulation in ZKPs an open problem 11.