« All posts

Hollow-LLM Attack: Ghost Weights That Fool Zero-Knowledge LLM Verification

The Hollow-LLM attack examines the impact of ghost weights on zero-knowledge verification.

As large language models (LLMs) expand, verifying accurate inference execution becomes essential. Zero-knowledge (ZK) LLM inference offers public verifiability, ensuring outputs align with a public architecture under private weights. However, the Hollow-LLM Attack reveals a gap where dishonest providers can use ghost weights to misrepresent their model's effective computation. This allows them to claim larger models while operating on a smaller scale, thereby reducing costs without sacrificing output quality. These findings highlight the need for stronger protections to ensure that proof of correct inference correlates with actual computational work.