acceptodds
Under review as a conference paper at ICLR 2027

From Registered Models to Authorized Actions: Zero-Knowledge LLM Agents with Model Binding and Private Tool-Call Authorization

Abstract

An LLM inference proof establishes computational correctness, but does not by itself establish use of an approved model or authorization of generated actions. We present an interactive zero-knowledge prototype for Q12 fixed-point GPT-2 Small that addresses both gaps with public prompts and private weights. Intermediate generation and denied-call contents remain hidden from the verifier; final answers and accepted calls reach their authorized recipients. First, a streamed Reed–Solomon check links every private weight label consumed by inference to an approved registration. Starting from those labels, a shared lookup interface over information-theoretically authenticated values supports both generation and authorization. It supports private embedding reads, online secret-logit lookup, and fixed-round parsing while keeping token IDs authenticated; its range-aware fused Q12 lookup evaluation (the fused Q12 path) reuses evidence across nonlinear computation. Our contribution lies in composing these relations rather than in introducing a new lookup argument. One-shot verification proves the exact top- set under Q12 logits with canonical tie-breaking; the verifier-provided seed and proved sampling rule, rather than prover discretion, fix each next token. Private parsing then extracts call identifiers from verified hidden tokens, and public-policy checks determine authorization. For gateway-controlled resources, an accepted call is bound to a one-time capability. The trusted gateway learns the accepted call and executes a registered adapter: authorization is verified, but tool execution itself is not ZK-proved. Evaluation covers eight inference shapes. At , matched ablations show that the fused Q12 path reduces full verification time per evaluated row by 78.2–79.4%, while secret-logit lookup makes softmax top- sampling faster than selector sampling. For 124.4 million weights, the streamed link reduces online model-binding time by a factor of relative to a per-weight LowMC masking/recovery comparator implemented in the same codebase. Across seven bounded agent tasks in each of three independent 12-round trials, the system executes authorized calls and rejects the tested unauthorized transfer and forged administrator claims before execution.

Then back it, or bet against it.

Related papers

Open the market on this paper to see 7 more related papers.