01 / The mechanism and its boundary
What is being described
A zero-knowledge proof (ZKP) is a cryptographic protocol by which a prover convinces a verifier that a statement is true without revealing any more information than that fact S-1600.
It has three properties:
- Completeness. If the statement is true and both parties follow the protocol, the verifier accepts S-1606.
- Soundness. If the statement is false, a verifier that follows the protocol is not convinced S-1606.
- Zero knowledge. If the statement is true and the prover follows the protocol, the verifier learns no confidential information beyond the fact that the statement is true S-1606.
The statement combines a public instance, known to both parties, with a private witness known only to the prover S-1606. Strictly, a proof must be sound even against a computationally unbounded prover; an argument, such as a SNARK (succinct non-interactive argument of knowledge), need only be sound against bounded ones S-1606. In zero-knowledge proofs of inference the witness is the model's weights: the prover publishes a commitment to them once, then proves for each query that the output equals the committed model applied to the input S-0023. zkLLM proved one 2,048-token forward pass of LLaMa-2-13B in 803 seconds on one A100 GPU, producing a 188 kB proof of a fixed-point approximation of the model S-0023. For zero-knowledge proofs of training constraints, a 2026 proposal notes that governance analyses judge such proofs currently impractical at frontier scale, and argues that this limit is not fundamental S-0025.
Connections in the research map
Related research
Sources and provenance
- S-1600 / Tier A
NIST Computer Security Resource Center (CSRC) Glossary ↗
National Institute of Standards and Technology · 2026 · NIST Computer Security Resource Center
Supports: NIST definition of zero-knowledge proof
Locator: term: zero_knowledge_proof (NISTIR 8301)
Version and catalogue details - S-1606 / Tier B
ZKProof Community Reference ↗
D. Benarroch, L. Brandão, M. Maller, E. Tromer · 2022 · ZKProof
Supports: completeness, soundness and zero knowledge; instance and witness; proofs sound against unbounded provers vs arguments sound against bounded provers; SNARK as succinct non-interactive argument of knowledge
Locator: pp. 1–2; p. 21
Version and catalogue details - S-0023 / Tier A
zkLLM: Zero Knowledge Proofs for Large Language Models ↗
H. Sun, J. Li, H. Zhang · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024)
Supports: one-time weight commitment and per-query proof; LLaMa-2-13B forward pass of 2,048 tokens proved in 803 s on one A100 GPU with a 188 kB proof; fixed-point approximation
Locator: abstract; §3; §8, Table 1
Version and catalogue details - S-0025 / Tier B
Zero knowledge verification for frontier AI training is possible ↗
P. Peigné, K. Nguyen, P. Wang · 2026 · arXiv
Supports: recent analyses judge ZK verification of frontier training currently impractical; authors argue this is not fundamental and propose an architecture
Locator: abstract
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review