I-0005 / Cryptography & computation

Attestable zero-knowledge inference prover

Attestable's zero-knowledge prover, which the company reports proves large language model outputs came from committed weights at tens of tokens per second.

R1 ProposedSource reviewed 2026-09-25Provider-reported evidence

01 / The mechanism and its boundary

What the technique establishes

Attestable, a company, reports a zero-knowledge prover for transformer inference that would let an AI developer prove that an output came from a committed model, input and random seed without revealing the weights. On one NVIDIA H100 GPU, Attestable reports proving a 31-billion-parameter model at 53 tokens per second for one 16,000-token sequence, and 77 tokens per second across four 4,000-token sequences. It reports proofs of a few megabytes that a CPU verifies in under a second. It also proposes using such proofs to support verifiable limits on AI development. All evidence comes from the company's blog, and no paper, protocol specification or code is public, so the results cannot be independently checked. The company lists its own limits: a 16,000-token context, 8-bit integer matrix multiplications, and proofs that cover only the computation they are about.

Threat model
Adversarial prover
Adversarial evaluation
None
Hardware needed
None
Prover cooperation
Required
Confidentiality
Preserving
Category
Cryptography & computation

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R1 Proposed

Assessed use: proving an output came from committed weights

low confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

Attestable states the claim, its security basis and its limits, but has published no code, protocol description or artifact.

  • R1 met: Attestable publicly states the claim proven (an output y = F(W, x, r) for committed weights W, input x and seed r), its security basis (hash functions only, 100-bit security) and its limits S-1101. It also states the verification uses it proposes S-1102 S-1103.
  • R2 not met. The rubric excludes results that are claimed but not public or not reproducible, and Attestable's figures are published without code, a protocol description or an artifact S-1101.

Evidence needed for the next level

  • A public working implementation, or reproducible published end-to-end results, such as a paper with a protocol specification and benchmarks others can rerun.

  • Any independent security analysis of the proof system.

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / open / open question

Proves an 8-bit quantised variant of the model

Attestable reports that matrix multiplications are dynamically quantised to 8-bit integers, while non-linear operations are proven in floating point. It reports that its IFEval result "shows where the current quantization still needs improvement" S-1101. The proven model is therefore a quantised variant, which a verifier must accept as the declared model.

S-1101

significant / open / theoretical argument

A proof covers only the computation it is about

Attestable states that "a proof of some computation is not a proof of all computation" and that a proof "cannot discover a datacenter that was never declared" S-1102.

S-1102

What still blocks use or stronger assurance

  1. No paper, protocol specification or code is public, so the reported results cannot be reproduced.

    S-1101
  2. Attestable reports a context window limited to 16K tokens.

    S-1101
  3. Covering computation that is not proven relies on proof-of-work accounting, which Attestable has only proposed.

    Dependency: Proofs of useful work for capacity accounting

    S-1102

Connections in the research map

Mechanisms implemented

Concepts used

Organizations and developers

Sources and provenance

  1. S-1101 / Tier C

    Proving LLMs at Scale ↗

    Attestable · 2026 · Attestable blog

    Supports: statement proven, security basis, performance figures, limitations (provider-reported)

    Version and catalogue details
  2. S-1102 / Tier C

    Pacing AI Requires Proof ↗

    Attestable · 2026 · Attestable blog

    Supports: proposed verification uses and proof-of-work accounting; coverage argument (provider-reported)

    Version and catalogue details
  3. S-1103 / Tier C

    From Verifiability to Model-Weight Security ↗

    Attestable · 2026 · Attestable blog

    Supports: verification-firewall proposal with random sampling of outputs; stated threats (provider-reported)

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review