I-0003 / Cryptography & computation

zkLLM

zkLLM is a GPU-accelerated zero-knowledge proof system that proves a large language model's output came from committed weights without revealing those weights.

R2 DemonstratedSource reviewed 2026-09-25Provider-reported evidence

01 / The mechanism and its boundary

What the technique establishes

zkLLM is an academic zero-knowledge proof system for large language models, published at ACM CCS 2024. It lets a model's owner prove that its committed model computed an output, without revealing the weights. The verifier supplies the prompt and sees the output. On one NVIDIA A100 GPU, zkLLM proved one 2,048-token forward pass of LLaMa-2-13B in about 13 minutes. The 188 kB proof verifies in about four seconds. The code is public and passed the conference's artifact evaluation. The main obstacles to real use are cost and engineering maturity. Its authors state the code is unaudited, not ready for industrial use and no longer maintained. For verification, the main weakness is that it proves a fixed-point approximation of a model whose architecture must be public. Its zero-knowledge guarantee also assumes a verifier that follows the protocol.

Threat model
Adversarial prover
Adversarial evaluation
Published analysis
Hardware needed
None
Prover cooperation
Required
Confidentiality
Partial
Category
Cryptography & computation
Technical detail and cited results

The design has four parts S-0023:

  • tlookup is a parallel lookup argument for non-arithmetic tensor operations. The authors state it adds no asymptotic overhead in memory or running time (§4).
  • zkAttn proves softmax attention by splitting the exponentiation into K segments, each checked with tlookup (§5).
  • The commitments use Hyrax, a Pedersen variant, over BLS12-381 under discrete-log hardness (§3).
  • Tensors are scaled by 2^16 and rounded into the field. The resulting total L1 error on the output is about 10^-2 (§7–8).

The paper's security analysis is in §7.2 S-0023:

  • Theorems 7.2 and 7.3 give tlookup a completeness error of O(N/|F|). They show that a cheating probabilistic polynomial-time prover succeeds only with negligible probability. The rest of the protocol applies the sumcheck protocol and proofs of opening for committed tensors.
  • Theorem 7.4 covers zero knowledge. It states that a simulator with only oracle access to the output produces a view indistinguishable from the real one. The theorem assumes zero-knowledge variants of sumcheck and Pedersen commitments. The threat model assumes a semi-honest verifier (§3.6).

Table 1 reports these costs on an A100 40 GB GPU at sequence length 2,048 S-0023:

  • OPT-13B took 1,270 s to commit and 713 s to prove. The proof was 160 kB, verified in 3.71 s and used 22.9 GB of memory.
  • LLaMa-2-13B took 986 s to commit and 803 s to prove. The proof was 188 kB, verified in 3.95 s and used 23.1 GB of memory.

The public code covers LLaMa-2 7B and 13B, runs prover and verifier side by side, and is interactive S-1108.

Claims and scope

A direct link identifies the intended claim. A supporting link supplies part of the evidence. Neither establishes that a complete verification system has been demonstrated.

Readiness for a stated use

R2 Demonstrated

Assessed use: proving an output came from committed weights, against a prover who cheats

medium confidence · current · assessed 2026-09-25 · rubric 1.1

This is the source map’s editorial assessment. Production use is not evidence of resistance to every adversary.

Public, artifact-evaluated code proves 13-billion-parameter models in peer-reviewed tests, but its authors say it is unaudited and not ready for production.

  • R1 met: the paper states the claim, the threat model and the security theorems S-0023.
  • R2 met: the code is public, tagged and archived on Zenodo. It received the CCS 2024 badges "Artifacts Available" and "Artifacts Evaluated--Functional" S-1108. The published end-to-end results use 13-billion-parameter models on a data-centre GPU S-0023. The stated adversary is a cheating polynomial-time prover S-0023.
  • R3 not met: the README says the code "is NOT ready for industrial applications" and is no longer maintained S-1108. As of September 2026 no third party is known to rely on it.
  • R4 not met: the README says the code "has NOT undergone security auditing" S-1108, and as of September 2026 no independent security evaluation of it has been published.

Evidence needed for the next level

  • A production-grade implementation, with prover and verifier separated and non-interactive proofs, or reliance by a third party for a verification decision.

  • An independent public security evaluation (audit, red-team or third-party peer-reviewed analysis).

Limitations, flaws, and blockers

These are attributed assessments from the source map. Absence of a listed flaw is not a security guarantee.

significant / open / open question

Reference code is interactive and runs prover and verifier together

The README states that prover and verifier work "are implemented side-by-side", and that intermediate values written to files are for the prover's reference only. It says an industrial deployment would need to separate the two and apply Fiat–Shamir to make proofs non-interactive S-1108. The released code gives a verifier no standalone check.

S-1108

minor / open / theoretical argument

Proves a fixed-point approximation of a publicly known architecture

The prover's model must have a "publicly known structure". Tensors are discretised by scaling and rounding S-0023. The authors report perplexity changes of 0.008 to 0.09 on C4 S-0023. The proof covers the quantised computation.

S-0023

What still blocks use or stronger assurance

  1. Proving takes about 13 minutes (803 seconds) of A100 time per 2,048-token forward pass at 13B parameters, plus a one-time weight commitment of 16 to 21 minutes.

    S-0023
  2. The repository was archived on 10 July 2025 and the author states there is no plan for upgrades or maintenance.

    S-1108
  3. No security audit of the code has been carried out.

    S-1108

Connections in the research map

Mechanisms implemented

Concepts used

Organizations and developers

Sources and provenance

  1. S-0023 / Tier A

    zkLLM: Zero Knowledge Proofs for Large Language Models ↗

    H. Sun, J. Li, H. Zhang · 2024 · 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS 2024)

    Supports: design, threat model, security theorems, overheads, accuracy, comparison with zkML

    Locator: abstract; §3.6; §4; §5; §7; §8 Table 1 and Fig. 4; §9

    Version and catalogue details
  2. S-1108 / Tier B

    zkllm-ccs2024: code for zkLLM: Zero Knowledge Proofs for Large Language Models ↗

    H. Sun · 2024 · GitHub; archived on Zenodo

    Supports: public code, artifact badges, supported models, README caveats, archive status

    Locator: README; Zenodo record 13621754

    Version and catalogue details
  3. S-0018 / Tier B

    A System Overview for Near-Term, Low-Trust AI Compute Verification ↗

    N. Cankaya · 2026 · Machine Intelligence Research Institute

    Supports: use of zkLLM's figures in a verification system design

    Locator: §5.2.4

    Version and catalogue details
  4. S-1112 / Tier B

    Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference ↗

    C. Gong, B. Liu, M. Li · 2026 · arXiv

    Supports: independent Hollow-LLM analysis: valid proofs in zkLLM-style deployments do not bind computational effort; demonstrated with zkGPT

    Locator: Abstract; threat model; §V

    Version and catalogue details
Source review date
2026-09-25
Drafted by (source map)
ai
Review handles (source map)
codex-review