ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs
Bing-Jyue Chen, Suppakit Waiwitlikhit, Ion Stoica, Daniel Kang
Abstract
Machine learning (ML) is increasingly used behind closed systems and APIs to make important decisions. For example, social media uses ML-based recommendation algorithms to decide what to show users, and millions of people pay to use ChatGPT for information every day. Because ML is deployed behind these closed systems, there are increasing calls for transparency, such as releasing model weights. However, these service providers have legitimate reasons not to release this information, including for privacy and trade secrets. To bridge this gap, recent work has proposed using zeroknowledge proofs (specifically a form called ZK-SNARKs) for certifying computation with private models but has only been applied to unrealistically small models.
In this work, we present the first framework, ZKML, to produce ZK-SNARKs for realistic ML models, including stateof-the-art vision models, a distilled GPT-2, and the ML model powering Twitter's recommendations. We accomplish this by designing an optimizing compiler from TensorFlow to circuits in the halo2 ZK-SNARK proving system. There are many equivalent ways to implement the same operations within ZK-SNARK circuits, and these design choices can affect performance by 24×. To efficiently compile ML models, ZKML contains two parts: gadgets (efficient constraints for low-level operations) and an optimizer to decide how to lay out the gadgets within a circuit. Combined, these optimizations enable proving on a wider range of models, faster proving, faster verification, and smaller proofs compared to prior work.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f675dcb2-94fb-437b-a0a9-5c7e0b803462Cited by top-tier papers19
- Holding Secrets Accountable: Auditing Privacy-Preserving Machine LearningHidde Lycklama, Alexander Viand, Nicolas Küchler, Christian Knabenhans et al.USENIX Security 2024 · 11 citations
- Secure and Confidential Certificates of Online FairnessOlive Franzese, Ali Shahin Shamsabadi, Carter Luck, Hamed HaddadiNeurIPS 2025 · 10 citations
- Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM InferenceChen Gong, Beijie Liu, Mengyuan LiS&P 2026 · 2 citations
- LZKSA: Lattice-Based Special Zero-Knowledge Proofs for Secure Aggregation's Input VerificationZhi Lu, Songfeng LuCCS 2025 · 2 citations
- User-side Model Consistency Monitoring for Open Source Large Language Models Inference ServicesQijun Miao, Zhixuan FangACL 2025 · 1 citation
Builds on10
- Training language models to follow instructions with human feedbackLong Ouyang, Jeffrey Wu, Xu Jiang, Diogo Almeida et al.NeurIPS 2022 · 24,707 citations
- High-Resolution Image Synthesis with Latent Diffusion ModelsRobin Rombach, Andreas Blattmann, Dominik Lorenz, Patrick Esser et al.CVPR 2022 · 13,123 citations
- GAZELLE: A Low Latency Framework for Secure Neural Network InferenceChiraag Juvekar, Vinod Vaikuntanathan, Anantha P. ChandrakasanUSENIX Security 2018 · 1,075 citations
- CrypTen: Secure Multi-Party Computation Meets Machine LearningBrian Knott, Shobha Venkataraman, Awni Y. Hannun, Shubho Sengupta et al.NeurIPS 2021 · 573 citations
- MLPerf Inference BenchmarkVijay Janapa Reddi, Christine Cheng, David Kanter, Peter Mattson et al.ISCA 2020 · 517 citations
Related papers
- zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM InferenceWenjie Qu, Yijun Sun, Xuanming Liu, Tao Lu et al.USENIX Security 2025
- ZENO: A Type-based Optimization Framework for Zero Knowledge Neural Network InferenceBoyuan Feng, Zheng Wang, Yuke Wang, Shu Yang et al.ASPLOS 2024 · 13 citations
- Experimenting with Zero-Knowledge Proofs of TrainingSanjam Garg, Aarushi Goel, Somesh Jha, Saeed Mahloujifar et al.CCS 2023 · 31 citations
- zkAgent: Verifiable LLM Agent Execution via One-Shot Transcript ProofsLizheng Wang, Hancheng Lou, Chongrong Li, Yu Yu et al.CCS 2026
- ZKROWNN: Zero Knowledge Right of Ownership for Neural NetworksNojan Sheybani, Zahra Ghodsi, Ritvik Kapila, Farinaz KoushanfarDAC 2023 · 10 citations
