01 / The mechanism and its boundary
What is being described
Zkonduit Inc. develops EZKL, which its documentation describes as "a developer-friendly system for verifiable AI and analytics" S-3561. Its verification work is EZKL:
- EZKL compiles a model exported in the ONNX format into a halo2 circuit, so a prover can show that a model produced an output while keeping either the model or the data private S-1806. See zero-knowledge proofs of inference.
- Two of the authors of South et al. are from EZKL. The paper uses EZKL to attest that a model with private weights reaches a stated score, with proofs for models of up to about a million parameters S-0024.
- Trail of Bits reviewed EZKL for Zkonduit in January 2025 and reported 34 findings, 8 of high severity. Its March fix review marked all eight high-severity findings resolved, three other findings partially resolved and two unresolved S-0070.
Connections in the research map
Related research
Sources and provenance
- S-3561 / Tier B
EZKL documentation (overview) ↗
Zkonduit Inc. · 2025 · EZKL documentation
Supports: self-description of EZKL; Zkonduit copyright
Locator: documentation home
Version and catalogue details - S-1806 / Tier B
zkonduit/ezkl (GitHub repository) ↗
Zkonduit Inc. · 2026 · GitHub
Supports: EZKL: ONNX models compiled to halo2 circuits; public or private model and data; Zkonduit Inc. as maintainer
Locator: README
Version and catalogue details - S-0024 / Tier B
Verifiable evaluations of machine learning models using zkSNARKs ↗
T. South, A. Camuto, S. Jain, S. Nguyen, R. Mahari, C. Paquin, J. Morton, A. Pentland · 2024 · arXiv
Supports: two EZKL authors; verifiable evaluations with EZKL; model sizes up to about a million parameters
Locator: author list; §6.1 Table 1
Version and catalogue details - S-0070 / Tier B
Zkonduit EZKL Security Assessment ↗
F. Casal, T. Hess, L. Bourtoule, S. Hussain, G. Larregay · 2025 · Trail of Bits (prepared for Zkonduit Inc.)
Supports: Trail of Bits audit and limited fix review: 34 findings, 8 high resolved, 3 other findings partially resolved, 2 unresolved
Version and catalogue details
- Source review date
- 2026-09-25
- Drafted by (source map)
- ai
- Review handles (source map)
- codex-review