ZK/SEC Research notes from zkSecurity
All posts
Proof is in the Pudding · Part 11 of 11

Archetype x zkSecurity - Proof is in the Pudding: zkML

For the 11th session of Proof is in the Pudding, we teamed up with Archetype to talk about zkML. Running an LLM is already expensive. How much harder is it to prove that you ran it?

We start with what a proof of model inference actually guarantees, how inference differs from training, and the alternatives to using ZK. Then we open up a transformer and look at the computation we would have to prove.

From there, we discuss sumcheck, GKR, lookup arguments, and provers specialized for particular models. If you'd like to work through one of those building blocks yourself, our sumcheck tutorial includes code and exercises. We also covered GKR from a security angle in Session 3.

The second half looks at quantization, models designed to be easier to prove, and opportunities around KV caching. We finish with scaling, where verifiable ML might be useful, and a more speculative possibility: agents agreeing on circuits and exchanging proofs as they interact.

Jump to a topic

You can catch up on our previous session on Groth16 or browse the full series. Have a topic you'd like us to cover next? Let us know on Twitter/X!

Keep reading
Recommended

Learn Sumcheck, MLE, and HyperPlonk: An Interactive Tutorial with SageMath

A new interactive tutorial on Sumcheck, Multilinear Extensions, and HyperPlonk with complete SageMath implementations and exercises. Go beyond the theory and understand how these protocols actually work by implementing them yourself.

Marco Gaglianese · November 22, 2025

Archetype x zkSecurity - Proof is in the Pudding: Groth16

In Session 10 of "Proof is in the Pudding," we work backward from Groth16's famously compact verifier equation to explain why the protocol is shaped the way it is. We cover how R1CS constraints become polynomial identities, why pairings are needed to multiply hidden commitments, how random linear combinations and the Schwartz-Zippel lemma enforce witness consistency, and how the separating factors gamma and delta restrict which pieces of the CRS a prover can use.

ZK/SEC · July 23, 2026

Archetype x zkSecurity (Whiteboard Session) - Proof is in the Pudding: GKR and How to Prove False Statements

In our third whiteboard session with Archetype, we dive into the fascinating world of cryptographic protocols by breaking down the intricacies of the Fiat-Shamir security model and the GKR protocol. Whether you're a cryptography enthusiast or just curious about how these complex mechanisms enhance security, this is a chance to explore the theories with us in a friendly and digestible way. Don't miss the opportunity to expand your understanding of this cutting-edge topic!

ZK/SEC · February 25, 2025
More to explore

Sum-Check as an Algebraic Tensor Reduction: Part I

This post introduces algebraic tensor reductions as a unifying framework for understanding recursive proof protocols, using sum-check as the main motivating example. It walks through one recursive step of sum-check, showing how the prover sends a univariate summary, the verifier checks sum consistency, and the original claim is reduced to a smaller claim with one fewer variable. A small bivariate example illustrates how this “peel off one variable, check, then fold with randomness” pattern works concretely. The post sets up the rest of the series, which will introduce the tensor language needed to recover classical sum-check as an algebraic tensor reduction.

Marco Besier · April 27, 2026

Introducing bugs.zksecurity.xyz a knowledge base for ZK bugs

We're thrilled to introduce our new site, [bugs.zksecurity.xyz](https://bugs.zksecurity.xyz/), a hub for exploring past vulnerabilities in ZK circuits. Dive into our growing catalog of documented bugs and learn how we've reproduced some with comprehensive scripts. Discover evaluations of prominent security tools like Circomspect and Picus, and see where they shine or stumble. We're calling on the community to join us in expanding this invaluable resource, whether by adding bugs, reproducing them, or improving our platform. Let's collaborate to elevate ZK security together!

Stefanos Chaliasos · February 17, 2025

Looking for an internship in 2025?

Thinking about diving into the world of cryptography and cutting-edge tech? We're on the lookout for bright minds to join us for internships in areas like ZK, MPC, and post-quantum cryptography. Our past interns have tackled exciting projects like exploring ZK circuit vulnerabilities and delving into RISC-V zkVMs. If you want a fast track to an interview, try out the zkBank challenge, or simply send us your resume. Come join us and see where the journey takes you!

ZK/SEC · February 25, 2025