Lune

CCS2026Top-tier venue

zkAgent: Verifiable LLM Agent Execution via One-Shot Transcript Proofs

Lizheng Wang, Hancheng Lou, Chongrong Li, Yu Yu, Yuncong Hu

2026Year

Abstract

LLM-based agents, which interleave large language model inference with external tool calls, are increasingly deployed in high-stakes settings. In real-world deployments, each model inference and provider-hosted tool execute behind the provider's API. Even when the agent loop runs on the user's device, these provider-executed steps still remain opaque to the user. This opacity creates an end-to-end integrity gap: a malicious provider may substitute the advertised model or fabricate tool observations to steer subsequent agent behavior. Existing zero-knowledge proof systems for LLMs prove only the Transformer computation of a single inference, leaving the rest of the inference pipeline, long-form autoregressive generation, and external tool interactions outside the proof.

We present zkAgent, the first SNARK system for verifiable agent execution. zkAgent proves the complete inference pipeline, from token-to-embedding lookup and positional encoding to Transformer computation and decoding. It further binds each tool observation to an authenticated execution via zkTLS or zkVM subproofs, yielding a single end-to-end proof. To scale beyond per-token proving, we introduce one-shot transcript proving: by exploiting the Transformer's causal attention mask, zkAgent proves an entire multi-step agent transcript in a single forward pass, avoiding the substantial overhead incurred by one-proof-per-token generation. We make this batched proof sound with a weight-dependent quantization scheme that is both input-independent and unconditionally complete.

On GPT-2 with a 512-token transcript, zkAgent achieves a 1047.4×1047.4\times prover speedup over the state of the art (zkGPT, USENIX Security'25), amortizing to 0.300.30s/token. On a real-world coding-assistant execution, zkAgent completes end-to-end proving in 93.1893.18s with 1.631.63s verification, making verifiable agent execution practical.

Ask about this paper

Ask your agent about it.

Lune has read the top-tier papers around this one, so every answer names the papers it rests on.

Questions to start from

Your agent calls

Lunesearch_papers

Ask in Lune

Free to start. No credit card required.

lune papers get fe68b3ce-8c5b-4bb4-898a-b5d5e51f02b3

Related papers

Dusk over the sea between two cliffs drawn in fine vertical lines