Checkpoint-replay verification of a training run is not merely buggy: making it provably robust reduces to open problems in learning theory, and spoofing already forges valid logs cheaply. The only floor that does not rest on unsolved theory is a zero-knowledge proof of training.
A proof of inference certifies an output came from a committed model. It says nothing about how the weights came to be. Proving the training run is a separate, far heavier object — and it is the one compliance actually asks for.
Intuition says the FLOP-heavy matmuls dominate a zkML proof. Multiple 2024-2026 systems show the opposite: linear layers are cheaper to prove than to compute, and the bill is set by activations multiplied by their bit-width.
On real networks the dominant zkML prover cost is not the matmuls or the activations. It is the consistency check binding the proof to the committed weights — an overhead that grows past 90% of prover time and that the single benchmark number hides.
Pricing a zero-knowledge proof of an LLM gives an absurd number, and teams conclude zkML is not ready. They are pricing the wrong model. For small fixed models on high-stakes decisions, zkML already pays for itself today.
DeepProve, from Lagrange, produced the first zero-knowledge proof of a full LLM inference — GPT-2. It moves "prove a transformer" from impossible to merely expensive. What that unlocks, and what is still years away.
Two ways to make an off-chain model output trustworthy on-chain. zkML is cryptographic, expensive, and small-model-only. opML is optimistic, cheap, and runs Llama-2-scale models today. Choosing by stakes, model size, and latency.
EZKL, Modulus, Giza, Ora, RISC Zero. Same model, same input, same target chain. Proof times, gas costs, gotchas — and the one we'd put in front of a customer.
zkML cannot scale to large models because proving a whole computation in one shot is ruinously expensive. Folding schemes — Nova and its lineage — prove a long, repetitive computation step by step instead. Explained without the cryptography.
The more specific you are, the more useful our first reply.
We respond within one business day. If we've got the right capacity, you'll get a 30-minute calendar invite. If we don't, you'll get a referral.
No results match your query. Try different terms.
Sources