فا
← BACK TO THE WIRE
N°0270ZK Tech2 MIN2 SOURCES

The Proof Is Fast; the Trust Boundary Is Still the Story: Attestable’s ZK Inference Benchmarks

Attestable reports production-scale zero-knowledge proofs for Gemma 4 31B, but its alpha benchmarks should be read as an engineering milestone—not yet as an independently verified security result.

SHARE
ZK Tech
The Proof Is Fast; the Trust Boundary Is Still the Story: Attestable’s ZK Inference Benchmarks
IMAGE: AI-GENERATED

Attestable has published benchmark results for zero-knowledge proofs over production-scale language-model inference, shifting the conversation from whether ZKML can handle toy networks to what a verifier can check for a real transformer workload.

The company says its prover can bind an output to a committed model, input, decoding configuration, random seed, and execution policy. A verifier can then check the proof without receiving the model weights or rerunning inference. Attestable describes the result as a computational signature: changing the model, input, output, or policy should invalidate verification.

The headline case study is Gemma 4 31B. On one NVIDIA H100, Attestable reports 53 tokens per second for a batch-one sequence with a 16K-token context, and 77 tokens per second across four 4K sequences. The resulting proofs reportedly range from 4.35 MiB to 7.92 MiB, while verification takes 157–648 milliseconds on the company’s reference CPU verifier.

That matters because proof generation—not verification—has traditionally been the practical bottleneck in ZKML. A fast verifier is useful only if producing the proof is affordable enough to run alongside inference. Attestable’s published architecture therefore targets a valuable division of labor: a GPU performs inference and proving, while an ordinary CPU can independently validate the result.

The engineering boundary is important. Attestable says its current system supports contexts up to 16K tokens and quantizes matrix multiplications to integers, while proving nonlinear operations in floating point. It also says its results are alpha benchmarks with substantial optimization still ahead. The company reports that its current quantization preserves difficult-reasoning performance better than a standard INT8 baseline on GPQA Diamond, while IFEval exposes areas that still need improvement.

There is also a verification boundary for readers. Attestable’s numbers are self-reported alpha results from one H100, and independent reproduction is not currently available. The company does not publish enough proof-system detail—such as the concrete field, query parameters, or a complete soundness analysis—for outsiders to independently assess every cryptographic claim. A contemporaneous technical analysis also notes that the published benchmark conditions are not directly comparable with older ZKML results using different models, hardware, and workloads.

The practical takeaway is narrower but meaningful: ZK inference is beginning to look like an infrastructure problem rather than only a research demo. For AI providers, the attractive promise is a portable proof that an approved model produced a particular output without disclosing proprietary weights. For auditors and integrators, the next questions are reproducibility, model-commitment formats, proof-system documentation, and whether the quantization boundary changes the computation being attested.

Attestable has not eliminated those questions. It has made them measurable. That is the timely development: a public benchmark suggests that verifiable inference can operate in a production-shaped regime, while the remaining trust boundary has moved from “can a proof exist?” to “can independent developers reproduce and audit it?”

TAGSZK TechZKMLZero-Knowledge ProofsVerifiable AI
Grounded sources2 REFS
  1. [01]Proving LLMs at Scaleattestable.com
  2. [02]Zero-knowledge proofs over inference: the Attestable launch and the published numbersnoze.it
Read next

Get the wire in your inbox

Every new signal, straight from the generator. No noise, unsubscribe anytime.

RSS AVAILABLE · NO SPAM