01 / The mechanism and its boundary
What the technique establishes
EZKL is a library and command-line tool, developed by the company Zkonduit, for proving neural-network inference in zero knowledge. It compiles a model exported in the ONNX format into a halo2 circuit, quantizing its values, so a prover can show that a model produced an output without revealing whichever of the model or the data is private. Its source code is public. A Trail of Bits audit in 2025 found proof-forgery bugs in its circuits and smart contracts, and all the high-severity ones were fixed. Trail of Bits reports that other projects use its verifier contracts in production. Its main limit for AI verification is scale: the largest language model in South et al.'s published results is a 250,000-parameter nanoGPT, which took 46 minutes to prove with a 219 GB proving key. Quantization also leaves a gap between the proven circuit and the full-precision model.
- Threat model
- Adversarial prover
- Adversarial evaluation
- Independent red-team
- Hardware needed
- None
- Prover cooperation
- Required
- Confidentiality
- Partial
- Category
- Cryptography & computation
Claims and scope
A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.
The declared model is the one being served
Proves an output follows from a committed model. South et al.'s results reach about a million parameters (S-0024).
Readiness for a stated use
Assessed use: proving a language model's output follows from committed weights, against a cheating prover
medium confidence · current · assessed 2026-10-08 · rubric 1.1
This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.
Public, independently audited code proves small models against a cheating prover, but its published results stop far below the size of the language models that verification claims concern.
- R1 met: the claim is that a stated model produced an output from a stated input, with either kept private S-1806. South et al. set out its use for verifiable evaluations of models with private weights S-0024.
- R2 met: the code is public S-1806. The stated adversary is a prover who tries to convince a verifier of an incorrect result, and an independent audit tested for exactly that S-0070. South et al. report end-to-end proofs for models of up to about a million parameters S-0024.
- R3 not met for this use, which is checking that a served language model is the declared one. The library is public and versioned S-1806, and Trail of Bits reports that other projects use its attestation and verifier contracts in production S-0070. No source says what those projects prove, and no party is documented relying on EZKL to verify a language model's outputs. The largest language model South et al. prove with it has 250,000 parameters S-0024, far below the models that claims about served AI concern. This matches the assessment of Zero-knowledge proofs of inference.
- R4 not met, because R3 is not. Trail of Bits' 2025 audit would otherwise count: at its fix review no high-severity finding remained unresolved S-0070.
Evidence needed for the next level
A production-grade release that proves language models at the scale verification claims concern, or reliance by another party on such proofs for a verification decision.
Limitations, flaws, and blockers
These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.
critical / mitigated / demonstrated attack
Circuit and contract bugs allowed forged proofs
Trail of Bits found three high-severity soundness bugs in EZKL's circuits: an unsound shuffle argument for min, max and top-k, a decomposition that did not fix the sign of zero, and missing range checks for division and reciprocals. Each would let a malicious prover convince a verifier of incorrect calculations, for example that [1,1,1] is a valid permutation of [1,2,3]. It also found four ways to bypass the data attestation and KZG commitments in EZKL's smart contracts. All were resolved at the March 2025 fix review. Some fixes were first made in private repositories, to allow disclosure to projects using the contracts in production S-0070.
significant / open / demonstrated attack
Quantization can activate a backdoor dormant in the full-precision model
EZKL quantizes values to represent them in a finite field. Trail of Bits built a ResNet-18 whose backdoor is dormant at full precision and active after EZKL's quantization. Larger models and smaller quantization scales make the attack easier. Whether the backdoor persists through the witness and proof stages was left for further investigation. The fix was documentation of the risk S-0070.
What still blocks use or stronger assurance
- S-0024
Proving cost grows steeply with model size: a 250,000-parameter nanoGPT took 2,781 s to prove and needed a 219 GB proving key, which South et al. name as the main limit on model size.
Connections in the research map
Mechanisms implemented
Organizations and developers
Sources and provenance
- S-1806 / Tier B
zkonduit/ezkl (GitHub repository) ↗
Zkonduit Inc. · 2026 · GitHub
Supports: what EZKL proves, ONNX input, halo2 backend, quantization note, maintainer (provider-reported)
Locator: README
Version and catalogue details - S-0024 / Tier B
Verifiable evaluations of machine learning models using zkSNARKs ↗
T. South, A. Camuto, S. Jain, S. Nguyen, R. Mahari, C. Paquin, J. Morton, A. Pentland · 2024 · arXiv
Supports: verifiable evaluation attestations with EZKL; model sizes, proving and verification times, proving-key sizes; proving key as the main limit
Locator: abstract; §6.1 Table 1
Version and catalogue details - S-0070 / Tier B
Zkonduit EZKL Security Assessment ↗
F. Casal, T. Hess, L. Bourtoule, S. Hussain, G. Larregay · 2025 · Trail of Bits (prepared for Zkonduit Inc.)
Supports: independent audit: scope, soundness and contract findings, quantization backdoor, coverage limits, production use of the contracts, fix review
Locator: Executive Summary; Project Coverage; TOB-EZKL-4 to 6, 13 to 17, 34; App. D
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review