zkAgent: Verifiable LLM Agent Execution via One-Shot Transcript Proofs
Lizheng Wang, Hancheng Lou, Chongrong Li, Yu Yu, Yuncong Hu
Abstract
LLM-based agents, which interleave large language model inference with external tool calls, are increasingly deployed in high-stakes settings. In real-world deployments, each model inference and provider-hosted tool execute behind the provider's API. Even when the agent loop runs on the user's device, these provider-executed steps still remain opaque to the user. This opacity creates an end-to-end integrity gap: a malicious provider may substitute the advertised model or fabricate tool observations to steer subsequent agent behavior. Existing zero-knowledge proof systems for LLMs prove only the Transformer computation of a single inference, leaving the rest of the inference pipeline, long-form autoregressive generation, and external tool interactions outside the proof.
We present zkAgent, the first SNARK system for verifiable agent execution. zkAgent proves the complete inference pipeline, from token-to-embedding lookup and positional encoding to Transformer computation and decoding. It further binds each tool observation to an authenticated execution via zkTLS or zkVM subproofs, yielding a single end-to-end proof. To scale beyond per-token proving, we introduce one-shot transcript proving: by exploiting the Transformer's causal attention mask, zkAgent proves an entire multi-step agent transcript in a single forward pass, avoiding the substantial overhead incurred by one-proof-per-token generation. We make this batched proof sound with a weight-dependent quantization scheme that is both input-independent and unconditionally complete.
On GPT-2 with a 512-token transcript, zkAgent achieves a prover speedup over the state of the art (zkGPT, USENIX Security'25), amortizing to s/token. On a real-world coding-assistant execution, zkAgent completes end-to-end proving in s with s verification, making verifiable agent execution practical.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get fe68b3ce-8c5b-4bb4-898a-b5d5e51f02b3Related papers
- DeepProve: Verifiable End-to-End Large Language Model InferenceNicolas Gailly, Ismael Hishon-Rezaizadeh, Tianyi Liu, Nicholas Mainardi et al.CCS 2026
- ZKML: An Optimizing System for ML Inference in Zero-Knowledge ProofsBing-Jyue Chen, Suppakit Waiwitlikhit, Ion Stoica, Daniel KangEuroSys 2024 · 65 citations
- zkGPT: An Efficient Non-interactive Zero-knowledge Proof Framework for LLM InferenceWenjie Qu, Yijun Sun, Xuanming Liu, Tao Lu et al.USENIX Security 2025
- BadAgent: Inserting and Activating Backdoor Attacks in LLM AgentsYifei Wang, Dizhan Xue, Shengjie Zhang, Shengsheng QianACL 2024
- Agentic Verification of Software SystemsHaoxin Tu, Huan Zhao, Yahui Song, Mehtab Zafar et al.FSE 2026 · 1 citation
