Verifiable AI Inference
The Trust Problem
A remote inference response does not by itself prove which model, inputs, or execution environment produced it. Verification methods aim to provide evidence about some or all of those details.
The required evidence depends on how the result is used. A result that can authorize a financial action needs different controls from a draft summary that a person will review.
Verifiable inference solves this: it creates a cryptographic proof that a specific model produced a specific output from a specific input.
Why This Matters for Smart Contracts
Smart contracts are deterministic - given the same inputs, they always produce the same outputs. AI models are not deterministic in the same way. This creates a fundamental tension:
- A DeFi protocol wants to use AI to assess loan risk.
- An NFT marketplace wants AI to detect fake art.
- A DAO wants AI to summarize proposals.
In each case, a smart contract needs to consume an AI output. But how does the contract know the AI output is legitimate?
Approaches to Verification
Zero-Knowledge Machine Learning (zkML)
A proof system can establish that a specified computation produced an output. The guarantee depends on the circuit, model representation, verifier, and cryptographic assumptions. It does not prove that the model's answer is factually correct.
Pros: A verifier can check the encoded computation without repeating all of it. Cons: Extremely computationally expensive. Generating ZK proofs for large neural networks can take hours and cost more than the inference itself.
Projects: EZKL, Modulus Labs, Giza.
Optimistic Machine Learning (opML)
Similar to optimistic rollups. Assume the AI output is correct, but allow a dispute window where anyone can challenge it by re-running the inference.
Pros: Much cheaper than zkML. Only expensive when disputes happen. Cons: Requires a dispute period (latency). Security depends on having honest challengers.
Projects: ORA Protocol.
Trusted Execution Environments (TEEs)
Run the AI model inside a hardware enclave (Intel SGX, AMD SEV, ARM TrustZone) that produces an attestation proving the code ran untampered.
Pros: Fast, practical, works with any model size. Cons: Depends on the hardware, firmware, attestation service, and protection against relevant attacks.
Projects: Phala Network, Marlin.
The Spectrum of Trust
| Method | Trust Assumption | Speed | Cost | Best For |
|---|---|---|---|---|
| zkML | Proof system, circuit, verifier, and input commitments | Workload-dependent | Workload-dependent | Checking specified computations |
| opML | Honest challengers | Medium | Low | General use |
| TEE | Hardware vendor | Fast | Low | Real-time apps |
Compare these methods for the particular workload. Proof generation, dispute periods, hardware trust, privacy requirements, and recovery from failure can lead to different choices.
Real-World Applications
- AI Oracles: Protocols like ORA bring AI model outputs on-chain with verification, enabling smart contracts to use GPT-level intelligence.
- Content Authentication: Proving that a piece of content was generated by a specific model (useful for deepfake detection).
- Autonomous Trading: DeFi protocols that use AI for trading strategies need verifiable execution to prevent operators from front-running.
State precisely what the verification establishes, and keep that separate from claims about model quality or the truth of its output.
Quiz: Verifiable AI Inference
1 / 5What is verifiable inference?