Model or dataset
Lagrange-Labs/deep-prove avatar
Lagrange-Labs/deep-prove

DeepProve: Zero-Knowledge Proof System for Neural Network Inference

Framework to prove inference of ML models blazingly fast

3,356 stars102 forksRustNOASSERTION

At a glance

What is it?
DeepProve is a Rust framework from Lagrange Labs that generates cryptographic proofs of neural network forward passes using sumchecks and logup GKR, with confirmed end-to-end support for GPT-2, Gemma 3, and Llama 2 on CPU hardware.
Who is it for?
DeepProve is the right tool for teams that need cryptographic attestation of specific neural network outputs, such as a smart contract that must verify an LLM prediction without running the model itself. It is the wrong tool for real-time inference pipelines: proving GPT-2 over 512 tokens takes 7.6 minutes on a 24-core server.
Can I use it commercially?
Check first. The repository uses a licence we do not classify automatically, so read its LICENSE file before any commercial use.
Is it still maintained?
Yes. The repository last received commits 123 days ago.
What is it written in?
Mainly Rust, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on October 1, 2026, and from our analysis. They are not legal advice.

Editorial analysis

The Problem DeepProve Solves: Verifiable ML Inference

Standard neural network inference produces an output but provides no proof that the model ran correctly or that a specific set of weights was used. Verifying a claim such as "this prediction came from GPT-2 running over this input" currently requires trusting the party who ran the model. DeepProve addresses this by generating a cryptographic proof that the forward pass actually happened with the exact model and input, and that the output is correct.

The project is aimed at developers who need to anchor AI outputs to blockchains, build trustless ML inference services, or audit model behavior in adversarial settings. The README describes it as the first end-to-end zero-knowledge proof system for full LLM inference, with confirmed support for transformer models including GPT-2, Gemma 3, and Llama 2, as well as MLP and CNN architectures.

The last push to the repository was on 2026-05-31.

The Sumcheck and logup GKR Proving Mechanism

DeepProve generates proofs using sumchecks and logup GKR rather than the circuit-based approach used by earlier ZK systems for ML. Circuit-based proving translates each arithmetic operation into a constraint system whose size grows proportionally with the number of operations. The sumcheck and GKR combination instead achieves sublinear proving time relative to model size, which is what makes proving transformer-scale models feasible on a single machine.

The core proving library is in the zkml crate. It handles model quantization, layer implementations for MLP, CNN, and transformer architectures, and the ZK proof generation and verification. The technique builds on sumcheck and GKR code from scroll-tech/ceno, which DeepProve's README acknowledges directly.

Accuracy is preserved through 12-bit quantization. The README reports a cosine similarity of at least 99.6% to the floating-point baseline for GPT-2 at that quantization level. This is a model-level figure; whether it holds for a specific downstream task on a specific prompt is not stated.

Benchmark Numbers and Hardware Requirements

The README provides proving times measured on a 24-core, 504 GB CPU server. For GPT-2 at 512 tokens, prove time is 7.6 minutes, verify time is 1.3 seconds, proof size is 10.7 MiB, and throughput is 1.12 tokens per second. For Gemma 3 at 512 tokens, prove time is 19 minutes, verify time is 4.3 seconds, proof size is 27 MiB, and throughput is 0.45 tokens per second.

The README states these numbers are 10 to 30 times faster than the previous published state of the art, citing zkGPT as achieving roughly 0.05 tokens per second on similar hardware. Verification is fast in both cases: under 5 seconds even for Gemma 3, which matters for on-chain verification where computation cost is metered.

Horizontal proof distribution and GPU acceleration are listed as supported. A cluster of GPU workers is described as on the roadmap, implying it is not yet available. The memory requirements implied by a 504 GB server mean that replicating these benchmarks on consumer hardware or standard cloud VM tiers is unlikely without adjusting sequence length or model size.

Repository Structure and the zkml Crate

DeepProve is a Rust workspace with six crates. The zkml crate is the core proving library and is the primary dependency for teams integrating ZK inference. The deep-prove crate provides the client stack: deep-prove-worker runs a proof generation server, and deep-prove-cli submits proving jobs locally or to a remote proving network.

The tenstore crate is a storage facade for persisting and retrieving tensor data, with support for both local storage and S3-compatible remote backends. The tenvis crate is an interactive CLI for inspecting and debugging proof data stored in tenstore. The telemetry crate provides shared OpenTelemetry tracing and logging setup across all crates. A utils crate provides shared helpers for CSV recording, memory tracking, and statistical summaries.

For anyone starting with the proving library, the README directs users to zkml/README.md for installation steps, model setup, GPU build instructions, and the bench-llm end-to-end tutorial. That document contains the practical onboarding path that the top-level README intentionally omits.

Installation Path and Build Configuration

The top-level README directs all installation and setup guidance to the zkml/README.md file within the repository. That document is described as holding the installation steps, model setup instructions, GPU build configuration, and the full bench-llm tutorial. The workspace Cargo.toml uses Rust edition 2024 and pins a nightly toolchain via rust-toolchain.toml.

The workspace depends on ark-bn254, ark-ff, and ark-serialize from the arkworks ecosystem for finite field arithmetic, and on dp-crypto from a Lagrange Labs private repository for GPU-accelerated polynomial operations. The dp-crypto crate is a git dependency pointing to a specific branch (feat/hkzg_gpu), which means a build will fetch it directly from GitHub. Teams who need reproducible builds in an air-gapped environment should plan for this dependency.

The Cargo.toml license field reads MIT OR Apache-2.0 but the repository LICENSE file is covered by the Lagrange License, a custom license named in the README. The README lists the license as NOASSERTION, which reflects this discrepancy. Before shipping a product that incorporates DeepProve, review the Lagrange License text in the LICENSE file directly.

Limitations: Proving Speed and Model Scope

The proving times, while significantly better than circuit-based alternatives, are still orders of magnitude slower than real-time inference. A 7.6-minute prove time for GPT-2 over 512 tokens means any application that needs to generate and verify a proof in the same request-response cycle faces a hard problem. DeepProve is suitable for workloads where proof generation can happen offline or asynchronously, such as batch attestation of historical inference runs.

Only three transformer models are confirmed to work end-to-end: GPT-2, Gemma 3, and Llama 2. MLP and CNN inference is also described as supported, but the boundary conditions for what transformer architectures are provable are not spelled out in the top-level README. Models with non-standard attention patterns, mixture-of-experts routing, or unusual activation functions may require additional work in the zkml layer.

The Lagrange License is a custom, non-standard license. Compared to permissive licenses like Apache-2.0 or MIT, a custom license introduces uncertainty about redistribution and modification rights. Teams in regulated industries or with strict open-source policies should obtain a legal review before building on DeepProve.

Alternative Approaches and Comparable Projects

The README names zkGPT as a prior system that achieves approximately 0.05 tokens per second on similar hardware. That 20-fold difference in throughput comes from the shift away from circuit-based proving. EZKL is another ZK inference framework that compiles neural networks to circuits for the Halo2 proving system. EZKL targets smaller models where circuit size is manageable; DeepProve's GKR-based approach targets transformer-scale models where circuit size becomes prohibitive.

For teams that do not need cryptographic proofs but need deterministic and auditable inference, approaches like running the model in a trusted execution environment (TEE) or using a verifiable compute network offer lower latency at the cost of different trust assumptions. The choice between ZK proofs and TEE-based attestation depends on whether the verifier needs to trust the hardware vendor.

Editorial conclusion

DeepProve is the right tool for teams that need cryptographic attestation of specific neural network outputs, such as a smart contract that must verify an LLM prediction without running the model itself. It is the wrong tool for real-time inference pipelines: proving GPT-2 over 512 tokens takes 7.6 minutes on a 24-core server. Before adopting it, confirm that the Lagrange License terms fit your use case and test whether your specific model architecture is supported, since only GPT-2, Gemma 3, and Llama 2 are listed as confirmed working.

Frequently asked questions

Which models has DeepProve confirmed working for end-to-end proof generation?

The README lists GPT-2, Gemma 3, and Llama 2 as confirmed working for all transformer layers including token embeddings through to next-token argmax. MLP and CNN inference is also described as supported.

How long does DeepProve take to generate a proof for GPT-2?

On a 24-core, 504 GB CPU server, proving GPT-2 over 512 tokens takes 7.6 minutes with a 1.3-second verification time. Verification time stays under 5 seconds even for Gemma 3.

What license does DeepProve use?

The repository uses the Lagrange License, a custom license whose text is in the LICENSE file. The Cargo.toml workspace metadata lists MIT OR Apache-2.0, but the README states NOASSERTION, reflecting that the governing terms are in the custom LICENSE file rather than the standard identifiers.

Official sources

  1. Issues
  2. Lagrange-Labs/deep-prove on GitHub
  3. Project website
  4. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/lagrange-labs-deep-prove.svg)](https://hysenlabs.com/projects/lagrange-labs-deep-prove)