Research · curated 4 Aug 2026
Hollow-LLM Attack: Computationally Trivial Weights in Zero-Knowledge Verification of LLM Inference
First reported arxiv.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
The Hollow-LLM Attack shows that ZK verification of remote LLM inference can be gamed by providers to silently downsize models while passing correctness proofs, undermining trust in verifiable AI-model supply chains.
A paper accepted to IEEE S&P 2026 introduces the Hollow-LLM Attack, in which a dishonest LLM provider embeds 'ghost weights' whose algebraic structure collapses effective computation while retaining the declared architecture and parameter count. Such witnesses satisfy zero-knowledge (ZK) inference verification circuits and yield valid proofs, letting a provider serve outputs at small-model cost while overclaiming model size, exposing an 'effort gap' where proof of correct inference is not proof of large-model execution.