Mechanism · Zero-knowledge proofs of inference

Sources

On this page
  1. AH. Sun et al. (2024). zkLLM: Zero Knowledge Proofs for Large Language Models. 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024). Source recordSupports: zkLLM design, threat model, security theorems, overheads, fixed-point effects · abstract; §3.6; §4–5; §7.2 Theorems 7.3–7.4; §8 Table 1; §9
  2. BH. Sun (2024). zkllm-ccs2024: code for zkLLM: Zero Knowledge Proofs for Large Language Models. GitHub; archived on Zenodo. Source recordSupports: zkLLM code availability, artifact badges and README caveats · README; Zenodo record
  3. AB.-J. Chen et al. (2024). ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs. 19th European Conference on Computer Systems (EuroSys 2024). Source recordSupports: ZKML design, halo2 backends, GPT-2 overheads, limitations · §3; §4.1; §4.4; §9 Tables 5–7
  4. AZ. Wang (2026). NanoZK: Privacy-Preserving Verifiable Inference for Large Language Models via Layerwise Zero-Knowledge Proofs. International Conference on Information and Communications Security (ICICS 2026). Source recordSupports: NanoZK layerwise proofs, threat model, proof sizes, partial audits · Definition 1; §5; §6; Table 8; App. A.4
  5. BT. South et al. (2024). Verifiable evaluations of machine learning models using zkSNARKs. arXiv. Source recordSupports: verifiable evaluation attestations with ezkl; public inputs and outputs; costs of small models · abstract; §5; §6.1 Table 1
  6. BF. Casal et al. (2025). Zkonduit EZKL Security Assessment. Trail of Bits (prepared for Zkonduit Inc.). Source recordSupports: independent audit of ezkl: circuit soundness findings, quantisation-activated backdoor, production use, fix review · Executive Summary; findings TOB-EZKL-4 to 6 and 17; App. D
  7. AZ. Peng et al. (2026). A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning. Artificial Intelligence Review, vol. 59, no. 7, article 157. Source recordSupports: definition and categorisation of ZKML; main implementation bottlenecks · abstract; §III; Table VI
  8. CAttestable (2026). Proving LLMs at Scale. Attestable blog. Source recordSupports: Attestable's reported prover, statement proven, performance and limits (provider-reported)
  9. CAttestable (2026). Pacing AI Requires Proof. Attestable blog. Source recordSupports: Attestable's coverage argument and pacing proposal (provider-reported)
  10. CAttestable (2026). From Verifiability to Model-Weight Security. Attestable blog. Source recordSupports: Attestable's proposal to prove randomly sampled outputs (provider-reported)
  11. BN. Cankaya (2026). A System Overview for Near-Term, Low-Trust AI Compute Verification. Machine Intelligence Research Institute. Source recordSupports: ZKPs as a 'tentative plan B' in a verification system; overhead assessment; floating-point gap · §5.2.4
  12. BC. Gong et al. (2026). Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference. arXiv. Source recordSupports: independent Hollow-LLM analysis: proofs do not bind computational effort; ghost-weight constructions; zkGPT-based experiment and cost results; countermeasures · Abstract; §I contributions; §V Table 2; §VI
  13. AW. Qu et al. (2025). zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM Inference. 34th USENIX Security Symposium (USENIX Security 25), pp. 2045–2063. Source recordSupports: zkGPT design, non-interactive proofs, GPT-2 proving and verification figures, public code · abstract; §3; §6 Table 3
  14. CLagrange Labs (2025). DeepProve-1: The First zkML System to Prove a Full LLM Inference. Lagrange blog. Source recordSupports: Lagrange's reported proof of full GPT-2 inference and 'production-ready' description (provider-reported)
  15. BLagrange Labs (2026). Lagrange-Labs/deep-prove (GitHub repository). GitHub. Source recordSupports: DeepProve public code, licence and reported GPT-2 proving figures (provider-reported) · README

Search

Full search page