Hollow-LLM攻击:LLM推理零知识验证中的计算上微不足道的权重
Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference
AI总结:
该研究提出Hollow-LLM攻击,利用LLM零知识验证的工作量缺口,通过嵌入幽灵权重使不诚实提供者以小模型成本生成有效证明,需额外措施绑定正确性与计算工作。
AI中文摘要:
随着大型语言模型(LLMs)规模不断扩大且主要由远程平台提供服务,验证推理执行的真实性变得至关重要(即确保提供者实际执行的是所声明的模型和计算工作量,而非经过篡改或缩小的变体)。零知识(ZK)LLM推理提供了一种颇具吸引力的方法,它承诺具备公开可验证性,并通过证明输出与在承诺的私有权重下执行的公开架构一致,为每个实例提供等式正确性保证。不过,我们发现该方法并未将生成输出所付出的工作量绑定起来。在本文中,我们将这一被忽视的工作量缺口形式化,并提出Hollow-LLM攻击:不诚实的提供者保留声明的架构和参数数量,但嵌入幽灵权重,其代数结构会使有效计算崩溃。这些见证满足验证电路并生成有效证明,尽管作为证明者的不诚实模型所有者执行的计算量远小于声明的公开架构对应的计算量。这形成了一种有利可图的平衡:提供者以小模型成本提供可证明正确的输出,同时夸大模型规模。因此,我们表征了与标准Transformer模块兼容的具体幽灵权重族,并表明在相同验证电路下,此类Hollow部署会大幅降低服务成本且质量无损失。这些发现强调,正确推理的证明并非大模型执行的证明,需要额外的保护措施将正确性与可验证的计算工作绑定。
英文摘要:
As large language models (LLMs) grow in scale and are predominantly served from remote platforms, verifying faithful inference execution becomes critical (i.e., ensuring that a provider actually executes the advertised model and computational workload rather than a tampered or downsized variant). Zero-knowledge (ZK) LLM inference offers an appealing approach. It promises public verifiability and delivers per-instance guarantees of equational correctness by proving that an output is consistent with executing a public architecture under committed, private weights. Though, we show that it does not bind the effort expended to produce the output. In this paper, we formalize this overlooked effort gap and introduce the Hollow-LLM Attack, in which a dishonest provider retains the declared architecture and parameter count but embeds ghost weights whose algebraic structure collapses effective computation. These witnesses satisfy the verification circuit and yield valid proofs, even though the dishonest model owner, who serves as the prover, performs computation commensurate with a much smaller model than the declared public architecture. This creates a profitable equilibrium in which providers deliver provably correct outputs at small-model cost while overclaiming model size. Accordingly, we characterize concrete families of ghost weights that compose with standard transformer blocks and show that such hollow deployments substantially reduce serving cost with zero quality loss under the same verification circuit. These findings underscore that proof of correct inference is not proof of large-model execution and necessitate additional protections to bind correctness to verifiable computational work.