Spaces:
Running
Running
chore(sync): mirror backend .py + Dockerfile to Space (hf-sync-backend)
Browse filesAutomated backend sync from szl-holdings/a11oy main via hf-sync-backend.
Updated (differed from the Space): Dockerfile, serve.py, szl3d_holographic.py, szl_frontier_zkinfer.py
Deleted (gone from the repo + Dockerfile COPY set): (none)
Keeps the Space-built backend (serve.py + the Dockerfile-COPY'd .py
modules) identical to GitHub main so the Space never rebuilds from a
stale backend, new endpoints don't 404 there, and orphaned modules
removed from the repo don't linger in the Space tree.
- Dockerfile +1 -1
- serve.py +15 -0
- szl3d_holographic.py +1 -0
- szl_frontier_zkinfer.py +535 -0
Dockerfile
CHANGED
|
@@ -649,7 +649,7 @@ COPY web/formulas.html web/v4_fleet_panel.html web/operator.html web/fleet-c2.ht
|
|
| 649 |
# physical-bounds) and szl_governed_api.py (govern/infer energy reference). Per-file
|
| 650 |
# COPY (this Dockerfile uses no `COPY . .`) or the guarded import falls back and the
|
| 651 |
# endpoint 404s / the govern receipt cannot cite the MEASURED reference.
|
| 652 |
-
COPY knowledge.json szl_parity_gaps.py compliance_crosswalk.py szl_compliance_mesh.py a11oy_warhacker_obs.py serve.py szl_governed_api.py szl_demo_tier1.py szl_assurance.py govern_showcase.html a11oy_wireA_metrics.py cathedral.html a11oy_operator_organ.py a11oy_hf_assets.py szl_b2_secdata.py gates_manifest.json a11oy_code_orchestrator.py a11oy_agent_loop.py a11oy_org_rag.py a11oy_mcp_client.py szl_rag.py a11oy_code_ide.html wayra_serve.py wayra_snapshot.json wayra_digests_7d.json szl_khipu_os_routes.py szl_spaces_proxy.py szl_spaces_surface.py szl_khipu_consensus.py szl_puriq_formulas.py ayni_os_serve.py szl_live_wires.py live_wires.html live_wires_3d.js szl_intoto.py szl_intoto_routes.py szl_scitt.py szl_dsse.py szl_provenance.py szl_be_hardening.py szl_unay.py szl_khipu_lmdb.py szl_khipu_replicate.py szl_unay_routes.py szl_warhacker_aliases.py a11oy_v4_hickok.py szl_khipu.py szl_formulas.py a11oy_v4_formulas.py szl_anatomy_3d.py szl_anatomy_routes.py _vendor_blobs.py szl_v4_fleet.py operator_shell_v4.py szl_bridge.py szl_bridge_schemas.py agent.html a11oy_bridge_cli.py szl_ken.py a11oy_formula_endpoints.py a11oy_formula_registry_guard.py a11oy_formulas_page.py a11oy_frontier_patch.py a11oy_v4_agent.py szl_brain.py szl_wire.py szl_hub.py szl_rosie_companion.py szl_receipt_substrate.py szl_alloy_embed_fabric.py szl_ayni_quorum.py szl_agentic_loop.py szl_ltc_dynamics.py szl_sgh_scheduler.py szl_formula_wiring.py szl_formula_surfaces.py a11oy_code_engine.py a11oy_code.py a11oy_seismic.py szl_warhacker_real.py szl_warhacker_demos.py NOTICE_warhacker_demos.txt szl_llm_registry.py szl_elite_console.py szl_alloy_models.py szl_scaling.py szl_allodial.py szl_entanglement.py szl_neuroplasticity.py szl_neuromorphic.py szl_chain_of_title.py szl_sovereign_compute.py a11oy_active_flux_router.py szl_energy_budget.py szl_energy_sovereign.py szl_energy_provenance.py szl_heart_blood.py szl_engine_status.py szl_backend_hardening.py revenue_endpoints.py a11oy_harvest_endpoints.py joule_billing.py szl_energy_ledger.py szl_energy_operator.py szl_energy_projection.py szl_cheapest_watt.py szl_energy_live.py szl_orbital_topology.py szl_orbital_projection.py a11oy_orbital_page.py a11oy_frontier_page.py szl_frontier_manifest.py a11oy_code_as_action.py a11oy_governed_kernel.py szl_lambda_tripwire.py szl_provenance_receipt.py szl_khipu_verify.py szl_attest_stack.py szl_demo_sign.py szl_sda.py szl_fabric_surface.py szl_nemo_agents.py szl_kverify.py szl_specdec.py szl_immune.py szl_quant_qbio_holo.py szl_materials.py szl_materials_predict.py a11oy_factory.py a11oy_constitution.py a11oy_nav_wireup.py szl_mbse_cosim.py szl_mbse_nav.py szl_mbse.py szl_factory.py szl_willay_gateway.py a11oy_willay_nav.py szl_waqay.py a11oy_waqay_nav.py szl_yupay.py a11oy_yupay_nav.py a11oy_uds_portability_nav.py szl_pinn_bounds.py physical_bounds_certificate.json agentic_decision_trail.json physical_bounds_certificate.dsse.json szl_pinn_inverse.py szl_governed_ipinn.py szl_calphad_inverse.py szl_pnt_mesh.py quantum_sensing_limits.py pnt_resilience.py nav_coasting.py fundamental_limits.py szl_counter_uas_proxy.py szl_gpu_quant.py szl_joules_truth.py revenue_model.py szl_prod_hardening.py szl_resilience.py szl_observability.py szl_corpus_publish.py szl_lake_store.py szl_lake_ingest.py szl_e8.py szl_trajectory_sign.py szl_nemotron_ingest.py szl_nemotron_corpus.py szl_nemo_verify.py a11oy_nemo_core.py szl_restraint.py szl_sapa.py szl_sapa_patch.py szl_restraint_energy.py a11oy_react_core.py szl_org_lambda.py a11oy_canonical_domain.py a11oy_formula_tiers.py szl_physical_bounds.py ./
|
| 653 |
|
| 654 |
# DEV2 Build 1: TEE/TDX attestation hook (2026-06-30) — imported by serve.py (guarded);
|
| 655 |
# MUST be per-file COPY'd or /api/a11oy/v1/tee/status + tee_attestation receipt field
|
|
|
|
| 649 |
# physical-bounds) and szl_governed_api.py (govern/infer energy reference). Per-file
|
| 650 |
# COPY (this Dockerfile uses no `COPY . .`) or the guarded import falls back and the
|
| 651 |
# endpoint 404s / the govern receipt cannot cite the MEASURED reference.
|
| 652 |
+
COPY knowledge.json szl_parity_gaps.py compliance_crosswalk.py szl_compliance_mesh.py a11oy_warhacker_obs.py serve.py szl_governed_api.py szl_demo_tier1.py szl_assurance.py govern_showcase.html a11oy_wireA_metrics.py cathedral.html a11oy_operator_organ.py a11oy_hf_assets.py szl_b2_secdata.py gates_manifest.json a11oy_code_orchestrator.py a11oy_agent_loop.py a11oy_org_rag.py a11oy_mcp_client.py szl_rag.py a11oy_code_ide.html wayra_serve.py wayra_snapshot.json wayra_digests_7d.json szl_khipu_os_routes.py szl_spaces_proxy.py szl_spaces_surface.py szl_khipu_consensus.py szl_puriq_formulas.py ayni_os_serve.py szl_live_wires.py live_wires.html live_wires_3d.js szl_intoto.py szl_intoto_routes.py szl_scitt.py szl_dsse.py szl_provenance.py szl_be_hardening.py szl_unay.py szl_khipu_lmdb.py szl_khipu_replicate.py szl_unay_routes.py szl_warhacker_aliases.py a11oy_v4_hickok.py szl_khipu.py szl_formulas.py a11oy_v4_formulas.py szl_anatomy_3d.py szl_anatomy_routes.py _vendor_blobs.py szl_v4_fleet.py operator_shell_v4.py szl_bridge.py szl_bridge_schemas.py agent.html a11oy_bridge_cli.py szl_ken.py a11oy_formula_endpoints.py a11oy_formula_registry_guard.py a11oy_formulas_page.py a11oy_frontier_patch.py a11oy_v4_agent.py szl_brain.py szl_wire.py szl_hub.py szl_rosie_companion.py szl_receipt_substrate.py szl_alloy_embed_fabric.py szl_ayni_quorum.py szl_agentic_loop.py szl_ltc_dynamics.py szl_sgh_scheduler.py szl_formula_wiring.py szl_formula_surfaces.py a11oy_code_engine.py a11oy_code.py a11oy_seismic.py szl_warhacker_real.py szl_warhacker_demos.py NOTICE_warhacker_demos.txt szl_llm_registry.py szl_elite_console.py szl_alloy_models.py szl_scaling.py szl_allodial.py szl_entanglement.py szl_neuroplasticity.py szl_neuromorphic.py szl_chain_of_title.py szl_sovereign_compute.py a11oy_active_flux_router.py szl_energy_budget.py szl_energy_sovereign.py szl_energy_provenance.py szl_heart_blood.py szl_engine_status.py szl_backend_hardening.py revenue_endpoints.py a11oy_harvest_endpoints.py joule_billing.py szl_energy_ledger.py szl_energy_operator.py szl_energy_projection.py szl_cheapest_watt.py szl_energy_live.py szl_orbital_topology.py szl_orbital_projection.py a11oy_orbital_page.py a11oy_frontier_page.py szl_frontier_manifest.py szl_frontier_zkinfer.py a11oy_code_as_action.py a11oy_governed_kernel.py szl_lambda_tripwire.py szl_provenance_receipt.py szl_khipu_verify.py szl_attest_stack.py szl_demo_sign.py szl_sda.py szl_fabric_surface.py szl_nemo_agents.py szl_kverify.py szl_specdec.py szl_immune.py szl_quant_qbio_holo.py szl_materials.py szl_materials_predict.py a11oy_factory.py a11oy_constitution.py a11oy_nav_wireup.py szl_mbse_cosim.py szl_mbse_nav.py szl_mbse.py szl_factory.py szl_willay_gateway.py a11oy_willay_nav.py szl_waqay.py a11oy_waqay_nav.py szl_yupay.py a11oy_yupay_nav.py a11oy_uds_portability_nav.py szl_pinn_bounds.py physical_bounds_certificate.json agentic_decision_trail.json physical_bounds_certificate.dsse.json szl_pinn_inverse.py szl_governed_ipinn.py szl_calphad_inverse.py szl_pnt_mesh.py quantum_sensing_limits.py pnt_resilience.py nav_coasting.py fundamental_limits.py szl_counter_uas_proxy.py szl_gpu_quant.py szl_joules_truth.py revenue_model.py szl_prod_hardening.py szl_resilience.py szl_observability.py szl_corpus_publish.py szl_lake_store.py szl_lake_ingest.py szl_e8.py szl_trajectory_sign.py szl_nemotron_ingest.py szl_nemotron_corpus.py szl_nemo_verify.py a11oy_nemo_core.py szl_restraint.py szl_sapa.py szl_sapa_patch.py szl_restraint_energy.py a11oy_react_core.py szl_org_lambda.py a11oy_canonical_domain.py a11oy_formula_tiers.py szl_physical_bounds.py ./
|
| 653 |
|
| 654 |
# DEV2 Build 1: TEE/TDX attestation hook (2026-06-30) — imported by serve.py (guarded);
|
| 655 |
# MUST be per-file COPY'd or /api/a11oy/v1/tee/status + tee_attestation receipt field
|
serve.py
CHANGED
|
@@ -625,6 +625,21 @@ try:
|
|
| 625 |
except Exception as _szl_fm_e: # pragma: no cover
|
| 626 |
print(f"[a11oy] Frontier manifest NOT registered: {_szl_fm_e!r}", file=__import__("sys").stderr)
|
| 627 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 628 |
# Composite inference-provenance receipt (THE CAPSTONE) — POST /api/a11oy/v1/provenance/
|
| 629 |
# receipt composes, by CALLING the already-live surfaces IN-PROCESS, ONE signed Khipu
|
| 630 |
# envelope binding every guarantee for a single governed action: the REAL immune verdict
|
|
|
|
| 625 |
except Exception as _szl_fm_e: # pragma: no cover
|
| 626 |
print(f"[a11oy] Frontier manifest NOT registered: {_szl_fm_e!r}", file=__import__("sys").stderr)
|
| 627 |
|
| 628 |
+
# zkML Proof-of-Inference ("Cryptographic Receipts") — GET /api/a11oy/v1/frontier/zkinfer
|
| 629 |
+
# returns the CRYPTOGRAPHIC-PROOF trust branch of verifiable inference (counterpart to the
|
| 630 |
+
# TEE branch, ccattest): literature-parameterized zkML proof-cost models (prover time / proof
|
| 631 |
+
# size / verify time vs model size × seq length, every value citing its arXiv ID / DOI), a
|
| 632 |
+
# cryptographic-vs-TEE trust-model matrix, and ONE real commit→prove→verify micro-artifact
|
| 633 |
+
# computed in-process (MEASURED for that narrow claim only; HONEST-STUB on failure). Top label
|
| 634 |
+
# MODELED (explicitly NOT VERIFIED). Adds NOTHING to the locked-8; Λ stays Conjecture 1; trust
|
| 635 |
+
# ceiling 0.97, never 100%. Additive, try/except-guarded, same register() pattern.
|
| 636 |
+
try:
|
| 637 |
+
import szl_frontier_zkinfer as _szl_frontier_zkinfer
|
| 638 |
+
_szl_frontier_zkinfer.register(app, ns="a11oy")
|
| 639 |
+
print("[a11oy] Frontier zkinfer registered: /api/a11oy/v1/frontier/zkinfer (MODELED zkML proof-of-inference)", file=__import__("sys").stderr)
|
| 640 |
+
except Exception as _szl_zk_e: # pragma: no cover
|
| 641 |
+
print(f"[a11oy] Frontier zkinfer NOT registered: {_szl_zk_e!r}", file=__import__("sys").stderr)
|
| 642 |
+
|
| 643 |
# Composite inference-provenance receipt (THE CAPSTONE) — POST /api/a11oy/v1/provenance/
|
| 644 |
# receipt composes, by CALLING the already-live surfaces IN-PROCESS, ONE signed Khipu
|
| 645 |
# envelope binding every guarantee for a single governed action: the REAL immune verdict
|
szl3d_holographic.py
CHANGED
|
@@ -94,6 +94,7 @@ SURFACES: List[Dict[str, str]] = [
|
|
| 94 |
{"id": "ctxready", "title": "Context-Ready Transformer", "owner": "Wave15"},
|
| 95 |
{"id": "opera", "title": "OPERA Perplexity-Reward Alignment", "owner": "Wave15"},
|
| 96 |
{"id": "brain", "title": "Formula-Graph Brain", "owner": "Wave15"},
|
|
|
|
| 97 |
]
|
| 98 |
|
| 99 |
# Content-type by extension (the only extensions we serve from the 3d tree).
|
|
|
|
| 94 |
{"id": "ctxready", "title": "Context-Ready Transformer", "owner": "Wave15"},
|
| 95 |
{"id": "opera", "title": "OPERA Perplexity-Reward Alignment", "owner": "Wave15"},
|
| 96 |
{"id": "brain", "title": "Formula-Graph Brain", "owner": "Wave15"},
|
| 97 |
+
{"id": "zkinfer", "title": "zkML Proof-of-Inference (Cryptographic Receipts)", "owner": "Wave18"},
|
| 98 |
]
|
| 99 |
|
| 100 |
# Content-type by extension (the only extensions we serve from the 3d tree).
|
szl_frontier_zkinfer.py
ADDED
|
@@ -0,0 +1,535 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
#!/usr/bin/env python3
|
| 2 |
+
# SPDX-License-Identifier: Apache-2.0
|
| 3 |
+
# © 2026 Lutar, Stephen P. Jr. — SZL Holdings · ORCID 0009-0001-0110-4173
|
| 4 |
+
# Doctrine v11 LOCKED · Λ = Conjecture 1
|
| 5 |
+
# Sign-off: Stephen P. Lutar <stephenlutar2@gmail.com>
|
| 6 |
+
"""szl_frontier_zkinfer.py — zkML Proof-of-Inference ("Cryptographic Receipts").
|
| 7 |
+
|
| 8 |
+
GET /api/a11oy/v1/frontier/zkinfer returns the cryptographic-proof trust branch of
|
| 9 |
+
verifiable inference — the counterpart to the estate's TEE/hardware branch
|
| 10 |
+
(`ccattest`). A prover (model host) emits a succinct zero-knowledge argument that a
|
| 11 |
+
COMMITTED model produced a specific output, checkable by anyone against only a public
|
| 12 |
+
weight commitment — no trusted hardware, no vendor in the trust base.
|
| 13 |
+
|
| 14 |
+
TOP-LEVEL HONESTY LABEL: MODELED (explicitly NOT VERIFIED). The estate is NOT running a
|
| 15 |
+
production zk-SNARK prover over a live LLM forward pass (that costs minutes + specialized
|
| 16 |
+
CUDA per the zkLLM result). The endpoint therefore returns:
|
| 17 |
+
|
| 18 |
+
1. proof_cost_model (MODELED) — prover time / proof size / verify time as functions of
|
| 19 |
+
model size × sequence length × proof system, PARAMETERIZED from the five literature
|
| 20 |
+
sources below. EVERY numeric value carries its citing arXiv ID / DOI in-band.
|
| 21 |
+
2. trust_model_matrix (STRUCTURAL) — cryptographic branch (standard hardness assumptions,
|
| 22 |
+
no trusted hardware) vs. the estate's TEE branch (`ccattest`). Definitional only.
|
| 23 |
+
3. micro_artifact (MEASURED for its OWN narrow claim only) — a genuine Fiat–Shamir-style
|
| 24 |
+
commit → prove → verify roundtrip over a tiny toy linear circuit, computed IN-PROCESS
|
| 25 |
+
at request time (Merkle commitment over a small weight vector + a transcript hash the
|
| 26 |
+
client can independently recompute + a real verify check). MEASURED means "this
|
| 27 |
+
roundtrip really executed in-process now", NOT a hardware/joule measurement and NOT a
|
| 28 |
+
claim that it scales to an LLM. If the roundtrip cannot run honestly, it downgrades to
|
| 29 |
+
HONEST-STUB — never a fabricated passing proof.
|
| 30 |
+
|
| 31 |
+
PRIMARY SOURCES (all verified to resolve 2026-07-06):
|
| 32 |
+
* zkLLM: Zero Knowledge Proofs for Large Language Models — Sun, Li, Zhang (2024),
|
| 33 |
+
arXiv:2404.16109 (ACM CCS 2024). 13B-param full-inference proof < 15 min; proof < 200 kB;
|
| 34 |
+
hides parameters. Introduces tlookup + zkAttn.
|
| 35 |
+
* Scaling up Trustless DNN Inference with Zero-Knowledge Proofs — Kang, Hashimoto, Stoica,
|
| 36 |
+
Sun (2022), arXiv:2210.08674. First ImageNet-scale non-interactive ZK-SNARK proof of
|
| 37 |
+
valid inference (79% top-5); MLaaS verification protocols.
|
| 38 |
+
* ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs — EuroSys 2024,
|
| 39 |
+
DOI 10.1145/3627703.3650088. TensorFlow→halo2 compiler; up to 5× larger provable models,
|
| 40 |
+
5× faster verify, 22× smaller proofs vs prior work (EZKL / ddkang line).
|
| 41 |
+
* Verifiable evaluations of machine learning models using zkSNARKs — South, Camuto, Jain,
|
| 42 |
+
et al. (2024), arXiv:2402.02675. ZK inference proofs packaged as verifiable evaluation
|
| 43 |
+
attestations (a model with fixed private weights provably hits a stated benchmark).
|
| 44 |
+
* A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning — Peng, Wang, Zhao,
|
| 45 |
+
et al. (2025), arXiv:2502.18535. Documents the three honest bottlenecks: limited circuit
|
| 46 |
+
expressiveness, high proving cost, deployment complexity.
|
| 47 |
+
|
| 48 |
+
DOCTRINE v11:
|
| 49 |
+
- Adds NOTHING to the locked-8 {F1,F4,F7,F11,F12,F18,F19,F22} @ kernel c7c0ba17; touches
|
| 50 |
+
no locked formula and no kernel.
|
| 51 |
+
- Λ stays Conjecture 1 (advisory); introduces no theorem, no green/1.0, no proof of Λ.
|
| 52 |
+
BFT remains Conjecture 2. Trust ceiling 0.97, never 100%.
|
| 53 |
+
- No label is ever upgraded. MODELED stays MODELED; the micro-artifact tile is MEASURED
|
| 54 |
+
ONLY for the narrow "roundtrip really ran" claim, or an honest HONEST-STUB otherwise.
|
| 55 |
+
- Additive route; canonical domain a-11-oy.com; 0 runtime CDN on the surface; no
|
| 56 |
+
user-visible codenames.
|
| 57 |
+
"""
|
| 58 |
+
from __future__ import annotations
|
| 59 |
+
|
| 60 |
+
import datetime
|
| 61 |
+
import hashlib
|
| 62 |
+
from typing import Any
|
| 63 |
+
|
| 64 |
+
# Honesty-label vocabulary (doctrine v11) — tests grep these exact strings.
|
| 65 |
+
MODELED = "MODELED"
|
| 66 |
+
MEASURED = "MEASURED"
|
| 67 |
+
HONEST_STUB = "HONEST-STUB"
|
| 68 |
+
STRUCTURAL = "STRUCTURAL-ONLY"
|
| 69 |
+
|
| 70 |
+
# Trust ceiling — advisory, never 100% (doctrine v11).
|
| 71 |
+
TRUST_CEILING = 0.97
|
| 72 |
+
|
| 73 |
+
# Primary sources, keyed by the short id each numeric value cites in-band.
|
| 74 |
+
SOURCES: dict[str, dict[str, str]] = {
|
| 75 |
+
"2404.16109": {
|
| 76 |
+
"id": "arXiv:2404.16109",
|
| 77 |
+
"title": "zkLLM: Zero Knowledge Proofs for Large Language Models",
|
| 78 |
+
"venue": "ACM CCS 2024",
|
| 79 |
+
"url": "https://arxiv.org/abs/2404.16109",
|
| 80 |
+
},
|
| 81 |
+
"2210.08674": {
|
| 82 |
+
"id": "arXiv:2210.08674",
|
| 83 |
+
"title": "Scaling up Trustless DNN Inference with Zero-Knowledge Proofs",
|
| 84 |
+
"venue": "arXiv 2022 (DOI 10.48550/arXiv.2210.08674)",
|
| 85 |
+
"url": "https://arxiv.org/abs/2210.08674",
|
| 86 |
+
},
|
| 87 |
+
"10.1145/3627703.3650088": {
|
| 88 |
+
"id": "DOI 10.1145/3627703.3650088",
|
| 89 |
+
"title": "ZKML: An Optimizing System for ML Inference in Zero-Knowledge Proofs",
|
| 90 |
+
"venue": "EuroSys 2024",
|
| 91 |
+
"url": "https://dl.acm.org/doi/10.1145/3627703.3650088",
|
| 92 |
+
},
|
| 93 |
+
"2402.02675": {
|
| 94 |
+
"id": "arXiv:2402.02675",
|
| 95 |
+
"title": "Verifiable evaluations of machine learning models using zkSNARKs",
|
| 96 |
+
"venue": "arXiv 2024 (DOI 10.48550/arXiv.2402.02675)",
|
| 97 |
+
"url": "https://arxiv.org/abs/2402.02675",
|
| 98 |
+
},
|
| 99 |
+
"2502.18535": {
|
| 100 |
+
"id": "arXiv:2502.18535",
|
| 101 |
+
"title": "A Survey of Zero-Knowledge Proof Based Verifiable Machine Learning",
|
| 102 |
+
"venue": "arXiv 2025 (DOI 10.48550/arXiv.2502.18535)",
|
| 103 |
+
"url": "https://arxiv.org/abs/2502.18535",
|
| 104 |
+
},
|
| 105 |
+
}
|
| 106 |
+
|
| 107 |
+
|
| 108 |
+
def _now_iso() -> str:
|
| 109 |
+
return datetime.datetime.now(datetime.timezone.utc).isoformat()
|
| 110 |
+
|
| 111 |
+
|
| 112 |
+
def _sha256_hex(*parts: bytes) -> str:
|
| 113 |
+
h = hashlib.sha256()
|
| 114 |
+
for p in parts:
|
| 115 |
+
h.update(p)
|
| 116 |
+
return h.hexdigest()
|
| 117 |
+
|
| 118 |
+
|
| 119 |
+
# ---------------------------------------------------------------------------
|
| 120 |
+
# 1. Proof-cost model (MODELED) — literature anchor points + a MODELED scaling grid.
|
| 121 |
+
# Every numeric value carries the citing source id.
|
| 122 |
+
# ---------------------------------------------------------------------------
|
| 123 |
+
|
| 124 |
+
def _anchor_points() -> list[dict[str, Any]]:
|
| 125 |
+
"""Literature HEADLINE figures only — no field is invented. Where a paper does not
|
| 126 |
+
headline a number we leave it null rather than fabricate one."""
|
| 127 |
+
return [
|
| 128 |
+
{
|
| 129 |
+
"system": "zkLLM",
|
| 130 |
+
"model": "LLaMa-2 13B (full inference)",
|
| 131 |
+
"params": 13_000_000_000,
|
| 132 |
+
"prover_time_s": {"value": 900, "relation": "<", "note": "under 15 minutes",
|
| 133 |
+
"source": "2404.16109"},
|
| 134 |
+
"proof_size_kb": {"value": 200, "relation": "<", "note": "succinct proof",
|
| 135 |
+
"source": "2404.16109"},
|
| 136 |
+
"verify_time_s": {"value": None, "note": "not headlined as a single figure by the paper",
|
| 137 |
+
"source": "2404.16109"},
|
| 138 |
+
"hides_parameters": True,
|
| 139 |
+
"label": MODELED,
|
| 140 |
+
},
|
| 141 |
+
{
|
| 142 |
+
"system": "Kang et al. (halo2 zk-SNARK)",
|
| 143 |
+
"model": "ImageNet-scale DNN (MobileNet-class)",
|
| 144 |
+
"params": None,
|
| 145 |
+
"prover_time_s": {"value": None, "note": "reported minutes-scale; no single headline value used",
|
| 146 |
+
"source": "2210.08674"},
|
| 147 |
+
"proof_size_kb": {"value": None, "note": "tens-of-kB order; exact value not reproduced here",
|
| 148 |
+
"source": "2210.08674"},
|
| 149 |
+
"verify_time_s": {"value": None, "note": "sub-second order; exact value not reproduced here",
|
| 150 |
+
"source": "2210.08674"},
|
| 151 |
+
"accuracy_top5": {"value": 0.79,
|
| 152 |
+
"note": "first ImageNet-scale non-interactive ZK-SNARK proof of valid inference",
|
| 153 |
+
"source": "2210.08674"},
|
| 154 |
+
"label": MODELED,
|
| 155 |
+
},
|
| 156 |
+
{
|
| 157 |
+
"system": "ZKML / EZKL (TensorFlow→halo2)",
|
| 158 |
+
"model": "relative to prior zkML toolchains",
|
| 159 |
+
"params": None,
|
| 160 |
+
"provable_model_size_gain_x": {"value": 5, "relation": "up to",
|
| 161 |
+
"source": "10.1145/3627703.3650088"},
|
| 162 |
+
"verify_speedup_x": {"value": 5, "source": "10.1145/3627703.3650088"},
|
| 163 |
+
"proof_size_reduction_x": {"value": 22, "source": "10.1145/3627703.3650088"},
|
| 164 |
+
"label": MODELED,
|
| 165 |
+
},
|
| 166 |
+
]
|
| 167 |
+
|
| 168 |
+
|
| 169 |
+
def _cost_grid() -> dict[str, Any]:
|
| 170 |
+
"""A MODELED prover-time surface over (model size × sequence length), anchored to the
|
| 171 |
+
zkLLM headline point (13B params → ~900 s). This is an EXTRAPOLATION, not a measurement:
|
| 172 |
+
prover_time_s ≈ k · (params/1e9)^a · (seq_len/1024)^b, with k fixed so the anchor
|
| 173 |
+
reproduces. Labeled MODELED; the anchor's source is cited. NOT VERIFIED."""
|
| 174 |
+
# Anchor: 13e9 params, 1024-token seq -> 900 s (zkLLM headline "< 15 min").
|
| 175 |
+
a, b = 1.0, 0.5 # near-linear in params, sublinear in seq (MODELED assumption).
|
| 176 |
+
anchor_params_b = 13.0
|
| 177 |
+
anchor_seq = 1024.0
|
| 178 |
+
anchor_time = 900.0
|
| 179 |
+
k = anchor_time / ((anchor_params_b ** a) * ((anchor_seq / 1024.0) ** b))
|
| 180 |
+
|
| 181 |
+
params_axis_b = [0.13, 0.5, 1.3, 7.0, 13.0, 70.0] # billions of params
|
| 182 |
+
seq_axis = [512, 1024, 2048, 4096, 8192] # tokens
|
| 183 |
+
|
| 184 |
+
def prover_time(params_b: float, seq: int) -> float:
|
| 185 |
+
return round(k * (params_b ** a) * ((seq / 1024.0) ** b), 2)
|
| 186 |
+
|
| 187 |
+
# Proof size stays roughly succinct/near-constant (zkLLM: < 200 kB; NANOZK-style
|
| 188 |
+
# layerwise proofs are near constant-size). MODELED: hold at the zkLLM ceiling.
|
| 189 |
+
proof_size_kb = 200.0
|
| 190 |
+
|
| 191 |
+
rows = []
|
| 192 |
+
for pb in params_axis_b:
|
| 193 |
+
rows.append({
|
| 194 |
+
"params_b": pb,
|
| 195 |
+
"prover_time_s": [prover_time(pb, s) for s in seq_axis],
|
| 196 |
+
})
|
| 197 |
+
|
| 198 |
+
return {
|
| 199 |
+
"label": MODELED,
|
| 200 |
+
"not_verified": True,
|
| 201 |
+
"formula": "prover_time_s = k · (params_b)^a · (seq_len/1024)^b",
|
| 202 |
+
"coefficients": {"k": round(k, 4), "a": a, "b": b},
|
| 203 |
+
"anchor": {"params_b": anchor_params_b, "seq_len": int(anchor_seq),
|
| 204 |
+
"prover_time_s": anchor_time, "source": "2404.16109",
|
| 205 |
+
"note": "zkLLM headline: 13B full inference proved in under 15 minutes"},
|
| 206 |
+
"axes": {"params_b": params_axis_b, "seq_len": seq_axis},
|
| 207 |
+
"prover_time_grid_s": rows,
|
| 208 |
+
"proof_size_kb_modeled": {"value": proof_size_kb, "source": "2404.16109",
|
| 209 |
+
"note": "held near the zkLLM succinct-proof ceiling; "
|
| 210 |
+
"layerwise systems target near-constant size"},
|
| 211 |
+
"honest_note": ("EXTRAPOLATED from a single literature anchor — a design surface, not "
|
| 212 |
+
"a benchmark. Real prover cost is proof-system, hardware and circuit "
|
| 213 |
+
"dependent; treat every off-anchor cell as MODELED, never MEASURED."),
|
| 214 |
+
}
|
| 215 |
+
|
| 216 |
+
|
| 217 |
+
# ---------------------------------------------------------------------------
|
| 218 |
+
# 2. Trust-model matrix (STRUCTURAL) — cryptographic branch vs. the TEE branch.
|
| 219 |
+
# ---------------------------------------------------------------------------
|
| 220 |
+
|
| 221 |
+
def _trust_matrix() -> dict[str, Any]:
|
| 222 |
+
return {
|
| 223 |
+
"label": STRUCTURAL,
|
| 224 |
+
"note": ("definitional contrast only — no measurement. This surface is the "
|
| 225 |
+
"cryptographic branch; `ccattest` is the estate's TEE/hardware branch."),
|
| 226 |
+
"axes": [
|
| 227 |
+
"trust_base", "trusted_hardware_in_TCB", "vendor_in_trust_base",
|
| 228 |
+
"verifier_re_runs_model", "hides_model_parameters", "assumption",
|
| 229 |
+
],
|
| 230 |
+
"branches": {
|
| 231 |
+
"cryptographic_zkml (this surface)": {
|
| 232 |
+
"trust_base": "standard cryptographic hardness assumptions only",
|
| 233 |
+
"trusted_hardware_in_TCB": False,
|
| 234 |
+
"vendor_in_trust_base": False,
|
| 235 |
+
"verifier_re_runs_model": False,
|
| 236 |
+
"hides_model_parameters": True,
|
| 237 |
+
"assumption": "soundness of the ZK argument (e.g. discrete-log / lattice / hash)",
|
| 238 |
+
"source": "2404.16109",
|
| 239 |
+
},
|
| 240 |
+
"tee_attestation (ccattest)": {
|
| 241 |
+
"trust_base": "hardware root of trust (SGX / SEV-SNP / H100 CC quote)",
|
| 242 |
+
"trusted_hardware_in_TCB": True,
|
| 243 |
+
"vendor_in_trust_base": True,
|
| 244 |
+
"verifier_re_runs_model": False,
|
| 245 |
+
"hides_model_parameters": True,
|
| 246 |
+
"assumption": "enclave + silicon vendor attestation service are honest/uncompromised",
|
| 247 |
+
"source": None,
|
| 248 |
+
"cross_surface": "/api/a11oy/v1/frontier/manifest (ccattest tile)",
|
| 249 |
+
},
|
| 250 |
+
},
|
| 251 |
+
"bottlenecks_honest": {
|
| 252 |
+
"source": "2502.18535",
|
| 253 |
+
"items": [
|
| 254 |
+
"limited circuit expressiveness (non-arithmetic ops need lookup arguments)",
|
| 255 |
+
"high proving cost (minutes + specialized compute at LLM scale)",
|
| 256 |
+
"deployment complexity (toolchain, circuit compilation, key management)",
|
| 257 |
+
],
|
| 258 |
+
},
|
| 259 |
+
"receipt_thesis": {
|
| 260 |
+
"source": "2402.02675",
|
| 261 |
+
"note": ("zk inference proofs package into verifiable evaluation attestations — a "
|
| 262 |
+
"model with fixed private weights provably achieves a stated benchmark; "
|
| 263 |
+
"the cryptographic counterpart to the estate's receipt/attestation thesis."),
|
| 264 |
+
},
|
| 265 |
+
}
|
| 266 |
+
|
| 267 |
+
|
| 268 |
+
# ---------------------------------------------------------------------------
|
| 269 |
+
# 3. Real, honest micro-artifact — commit → prove → verify roundtrip IN-PROCESS.
|
| 270 |
+
# MEASURED ONLY for the narrow "this roundtrip really ran now" claim.
|
| 271 |
+
# ---------------------------------------------------------------------------
|
| 272 |
+
|
| 273 |
+
def _merkle_root(leaves: list[bytes]) -> tuple[str, list[str]]:
|
| 274 |
+
"""Compute a plain SHA-256 Merkle root over `leaves` (duplicate-last padding). Returns
|
| 275 |
+
(root_hex, level0_leaf_hashes_hex). Real, deterministic, client-recomputable."""
|
| 276 |
+
level = [hashlib.sha256(b"leaf:" + lf).digest() for lf in leaves]
|
| 277 |
+
leaf_hex = [d.hex() for d in level]
|
| 278 |
+
if not level:
|
| 279 |
+
return hashlib.sha256(b"empty").hexdigest(), []
|
| 280 |
+
while len(level) > 1:
|
| 281 |
+
if len(level) % 2 == 1:
|
| 282 |
+
level.append(level[-1]) # duplicate-last padding
|
| 283 |
+
level = [hashlib.sha256(b"node:" + level[i] + level[i + 1]).digest()
|
| 284 |
+
for i in range(0, len(level), 2)]
|
| 285 |
+
return level[0].hex(), leaf_hex
|
| 286 |
+
|
| 287 |
+
|
| 288 |
+
def _micro_artifact() -> dict[str, Any]:
|
| 289 |
+
"""A genuine Fiat–Shamir-style commit-and-check over a tiny toy linear circuit y = w·x.
|
| 290 |
+
|
| 291 |
+
The whole roundtrip runs at request time; every value is client-recomputable:
|
| 292 |
+
commit : Merkle root over the committed weight vector w
|
| 293 |
+
challenge : r = SHA256(root || x) (Fiat–Shamir, non-interactive)
|
| 294 |
+
output : y = Σ w_i · x_i (the toy "inference")
|
| 295 |
+
transcript : SHA256(root || x || y || r)
|
| 296 |
+
verify : recompute root from w, recompute r, recompute y, recompute transcript, compare
|
| 297 |
+
|
| 298 |
+
HONESTY: this proves the commit→prove→verify PLUMBING is real; it is NOT a zk-SNARK,
|
| 299 |
+
reveals w (no zero-knowledge here), and does NOT scale to an LLM. Labeled MEASURED ONLY
|
| 300 |
+
for the narrow claim "this roundtrip executed in-process now"; on any failure it is
|
| 301 |
+
reported HONEST-STUB, never a fabricated pass."""
|
| 302 |
+
try:
|
| 303 |
+
# Tiny committed "weight vector" and public input (toy circuit).
|
| 304 |
+
w = [3, 1, 4, 1, 5, 9, 2, 6]
|
| 305 |
+
x = [1, 0, 1, 1, 0, 1, 0, 1]
|
| 306 |
+
|
| 307 |
+
w_leaves = [str(v).encode() for v in w]
|
| 308 |
+
root, leaf_hashes = _merkle_root(w_leaves)
|
| 309 |
+
|
| 310 |
+
x_bytes = (",".join(str(v) for v in x)).encode()
|
| 311 |
+
challenge = _sha256_hex(bytes.fromhex(root), x_bytes)
|
| 312 |
+
|
| 313 |
+
y = sum(wi * xi for wi, xi in zip(w, x)) # the toy inference output
|
| 314 |
+
transcript = _sha256_hex(bytes.fromhex(root), x_bytes, str(y).encode(),
|
| 315 |
+
bytes.fromhex(challenge))
|
| 316 |
+
|
| 317 |
+
# Independent verify: recompute EVERYTHING from the committed inputs.
|
| 318 |
+
root2, _ = _merkle_root(w_leaves)
|
| 319 |
+
challenge2 = _sha256_hex(bytes.fromhex(root2), x_bytes)
|
| 320 |
+
y2 = sum(wi * xi for wi, xi in zip(w, x))
|
| 321 |
+
transcript2 = _sha256_hex(bytes.fromhex(root2), x_bytes, str(y2).encode(),
|
| 322 |
+
bytes.fromhex(challenge2))
|
| 323 |
+
verify_ok = (root2 == root and challenge2 == challenge
|
| 324 |
+
and y2 == y and transcript2 == transcript)
|
| 325 |
+
|
| 326 |
+
if not verify_ok: # pragma: no cover — deterministic; would indicate a real fault
|
| 327 |
+
return {
|
| 328 |
+
"label": HONEST_STUB,
|
| 329 |
+
"verify_ok": False,
|
| 330 |
+
"note": ("commit-verify roundtrip did NOT reconcile in-process; reported "
|
| 331 |
+
"honestly as HONEST-STUB, not faked."),
|
| 332 |
+
}
|
| 333 |
+
|
| 334 |
+
return {
|
| 335 |
+
"label": MEASURED,
|
| 336 |
+
"measured_claim": ("ONLY that this commit→prove→verify roundtrip executed "
|
| 337 |
+
"in-process at request time and reconciled; NOT a joule/hardware "
|
| 338 |
+
"measurement, NOT zero-knowledge (w is revealed), NOT LLM-scale."),
|
| 339 |
+
"scheme": "SHA-256 Merkle commitment + Fiat–Shamir transcript over a toy linear circuit",
|
| 340 |
+
"commit": {"weight_vector": w, "merkle_root": root, "leaf_hashes": leaf_hashes},
|
| 341 |
+
"public_input": x,
|
| 342 |
+
"challenge_fiat_shamir": challenge,
|
| 343 |
+
"output_y": y,
|
| 344 |
+
"transcript_hash": transcript,
|
| 345 |
+
"verify_ok": True,
|
| 346 |
+
"client_recompute": {
|
| 347 |
+
"root": "SHA256('node:'||L||R) over SHA256('leaf:'||str(w_i)), duplicate-last pad",
|
| 348 |
+
"challenge": "SHA256(root_bytes || b'x0,x1,...')",
|
| 349 |
+
"output": "y = sum(w_i * x_i)",
|
| 350 |
+
"transcript": "SHA256(root_bytes || x_bytes || str(y) || challenge_bytes)",
|
| 351 |
+
},
|
| 352 |
+
"honest_note": ("real plumbing, deliberately tiny. Scaling this to a hiding, "
|
| 353 |
+
"succinct LLM proof is exactly the MODELED cost above and the "
|
| 354 |
+
"three bottlenecks in arXiv:2502.18535."),
|
| 355 |
+
}
|
| 356 |
+
except Exception as exc: # noqa: BLE001 — degrade honestly, never fabricate a pass
|
| 357 |
+
return {
|
| 358 |
+
"label": HONEST_STUB,
|
| 359 |
+
"verify_ok": False,
|
| 360 |
+
"note": f"micro-artifact could not run honestly in-process: {exc}",
|
| 361 |
+
}
|
| 362 |
+
|
| 363 |
+
|
| 364 |
+
# ---------------------------------------------------------------------------
|
| 365 |
+
# Payload assembly
|
| 366 |
+
# ---------------------------------------------------------------------------
|
| 367 |
+
|
| 368 |
+
def build_payload() -> dict[str, Any]:
|
| 369 |
+
"""Compose the zkinfer surface payload. Pure read; mints/ signs nothing (receipts
|
| 370 |
+
belong on writes, never on GETs)."""
|
| 371 |
+
micro = _micro_artifact()
|
| 372 |
+
return {
|
| 373 |
+
"ok": True,
|
| 374 |
+
"endpoint": "frontier/zkinfer",
|
| 375 |
+
"service": "a11oy.frontier.zkinfer",
|
| 376 |
+
"title": "zkML Proof-of-Inference (Cryptographic Receipts)",
|
| 377 |
+
# TOP-LEVEL honesty banner — VERBATIM, explicitly NOT VERIFIED.
|
| 378 |
+
"label": MODELED,
|
| 379 |
+
"claim": MODELED,
|
| 380 |
+
"not_verified": True,
|
| 381 |
+
"no_trusted_hardware_in_TCB": True,
|
| 382 |
+
"what": ("the cryptographic-proof trust branch of verifiable inference: a succinct "
|
| 383 |
+
"zero-knowledge argument that a COMMITTED model produced a specific output, "
|
| 384 |
+
"checkable against only a public weight commitment — no trusted hardware, no "
|
| 385 |
+
"vendor in the trust base. Orthogonal to the estate's TEE branch (ccattest)."),
|
| 386 |
+
"doctrine": {
|
| 387 |
+
"label_top": MODELED,
|
| 388 |
+
"not_verified": True,
|
| 389 |
+
"locked_proven": 8,
|
| 390 |
+
"locked_set": ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"],
|
| 391 |
+
"kernel_commit": "c7c0ba17",
|
| 392 |
+
"adds_to_locked_8": 0,
|
| 393 |
+
"lambda": "Conjecture 1",
|
| 394 |
+
"khipu_bft": "Conjecture 2",
|
| 395 |
+
"trust_ceiling": TRUST_CEILING,
|
| 396 |
+
"trust_100_percent": False,
|
| 397 |
+
"runtime_cdn": 0,
|
| 398 |
+
"note": ("additive MODELED surface; touches no locked formula and no kernel; "
|
| 399 |
+
"introduces no theorem, no green/1.0, no proof of Λ."),
|
| 400 |
+
},
|
| 401 |
+
"proof_cost_model": {
|
| 402 |
+
"label": MODELED,
|
| 403 |
+
"not_verified": True,
|
| 404 |
+
"anchor_points": _anchor_points(),
|
| 405 |
+
"cost_frontier": _cost_grid(),
|
| 406 |
+
},
|
| 407 |
+
"trust_model_matrix": _trust_matrix(),
|
| 408 |
+
"micro_artifact": micro,
|
| 409 |
+
"sources": SOURCES,
|
| 410 |
+
"labels_legend": {
|
| 411 |
+
MODELED: "design/parametric quantity derived from the literature — NOT verified",
|
| 412 |
+
MEASURED: "the micro-artifact roundtrip really executed in-process now (narrow claim only)",
|
| 413 |
+
HONEST_STUB: "an honest placeholder — the roundtrip could not run; never a faked pass",
|
| 414 |
+
STRUCTURAL: "definitional/structural contrast only — no measurement",
|
| 415 |
+
},
|
| 416 |
+
"timestamp_utc": _now_iso(),
|
| 417 |
+
}
|
| 418 |
+
|
| 419 |
+
|
| 420 |
+
def handle() -> dict[str, Any]:
|
| 421 |
+
"""GET /frontier/zkinfer handler used by FastAPI and __main__."""
|
| 422 |
+
try:
|
| 423 |
+
return build_payload()
|
| 424 |
+
except Exception as exc: # never 500: honest degraded response
|
| 425 |
+
return {
|
| 426 |
+
"ok": False,
|
| 427 |
+
"endpoint": "frontier/zkinfer",
|
| 428 |
+
"label": MODELED,
|
| 429 |
+
"error": str(exc),
|
| 430 |
+
"doctrine": "v11: surface unavailable; no fabricated proof/cost emitted.",
|
| 431 |
+
"timestamp_utc": _now_iso(),
|
| 432 |
+
}
|
| 433 |
+
|
| 434 |
+
|
| 435 |
+
# ---------------------------------------------------------------------------
|
| 436 |
+
# FastAPI router registration — mirrors szl_frontier_manifest.register() exactly.
|
| 437 |
+
# ---------------------------------------------------------------------------
|
| 438 |
+
|
| 439 |
+
def register(app, ns: str = "a11oy") -> str:
|
| 440 |
+
"""Mount the zkinfer surface endpoint on the FastAPI ``app``. Returns a status string."""
|
| 441 |
+
from fastapi.responses import JSONResponse
|
| 442 |
+
|
| 443 |
+
base = f"/api/{ns}/v1/frontier"
|
| 444 |
+
|
| 445 |
+
@app.get(f"{base}/zkinfer")
|
| 446 |
+
async def _frontier_zkinfer():
|
| 447 |
+
"""zkML proof-of-inference cost model + trust matrix + a real commit-verify micro-artifact."""
|
| 448 |
+
return JSONResponse(handle())
|
| 449 |
+
|
| 450 |
+
return "frontier-zkinfer-wired:1"
|
| 451 |
+
|
| 452 |
+
|
| 453 |
+
# ---------------------------------------------------------------------------
|
| 454 |
+
# Self-test — honest labels, no upgrade, real roundtrip, sources cited.
|
| 455 |
+
# ---------------------------------------------------------------------------
|
| 456 |
+
|
| 457 |
+
if __name__ == "__main__":
|
| 458 |
+
import json as _json
|
| 459 |
+
import sys as _sys
|
| 460 |
+
|
| 461 |
+
print("=" * 72)
|
| 462 |
+
print("szl_frontier_zkinfer — self-test (MODELED surface, honest labels)")
|
| 463 |
+
print("=" * 72)
|
| 464 |
+
|
| 465 |
+
p = build_payload()
|
| 466 |
+
blob = _json.dumps(p)
|
| 467 |
+
|
| 468 |
+
# 1) top-level MODELED, explicitly NOT VERIFIED, no trusted hardware in TCB.
|
| 469 |
+
assert p["ok"] is True
|
| 470 |
+
assert p["label"] == MODELED and p["claim"] == MODELED
|
| 471 |
+
assert p["not_verified"] is True
|
| 472 |
+
assert p["no_trusted_hardware_in_TCB"] is True
|
| 473 |
+
assert "VERIFIED" not in {p["label"], p["claim"]}
|
| 474 |
+
print("[1] top-level MODELED / not_verified / no trusted hardware OK")
|
| 475 |
+
|
| 476 |
+
# 2) doctrine: locked-8 exact, adds nothing, Λ Conjecture 1, trust ceiling 0.97 not 100%.
|
| 477 |
+
d = p["doctrine"]
|
| 478 |
+
assert d["locked_proven"] == 8
|
| 479 |
+
assert d["locked_set"] == ["F1", "F4", "F7", "F11", "F12", "F18", "F19", "F22"]
|
| 480 |
+
assert d["adds_to_locked_8"] == 0
|
| 481 |
+
assert d["lambda"] == "Conjecture 1" and d["khipu_bft"] == "Conjecture 2"
|
| 482 |
+
assert d["trust_ceiling"] == 0.97 and d["trust_100_percent"] is False
|
| 483 |
+
assert d["runtime_cdn"] == 0
|
| 484 |
+
print("[2] doctrine: locked-8 exact, +0, Λ=Conjecture 1, trust 0.97 (not 100%) OK")
|
| 485 |
+
|
| 486 |
+
# 3) every numeric cost value carries a citing source.
|
| 487 |
+
def _walk_sources(node):
|
| 488 |
+
found = []
|
| 489 |
+
if isinstance(node, dict):
|
| 490 |
+
if "source" in node and node["source"] is not None:
|
| 491 |
+
found.append(node["source"])
|
| 492 |
+
for v in node.values():
|
| 493 |
+
found += _walk_sources(v)
|
| 494 |
+
elif isinstance(node, list):
|
| 495 |
+
for v in node:
|
| 496 |
+
found += _walk_sources(v)
|
| 497 |
+
return found
|
| 498 |
+
|
| 499 |
+
cited = set(_walk_sources(p["proof_cost_model"]))
|
| 500 |
+
assert cited, "no source citations found in proof_cost_model"
|
| 501 |
+
assert cited <= set(SOURCES), f"cost model cites an unknown source: {cited - set(SOURCES)}"
|
| 502 |
+
# all five primary sources present in the payload.
|
| 503 |
+
for sid in ("2404.16109", "2210.08674", "10.1145/3627703.3650088",
|
| 504 |
+
"2402.02675", "2502.18535"):
|
| 505 |
+
assert sid in blob, f"missing primary source {sid}"
|
| 506 |
+
print(f"[3] cost values cite sources {sorted(cited)}; all 5 primary sources present OK")
|
| 507 |
+
|
| 508 |
+
# 4) the real micro-artifact roundtrip ran + reconciled (MEASURED narrow claim) and is
|
| 509 |
+
# independently recomputable; verify_ok is COMPUTED, never asserted true blindly.
|
| 510 |
+
m = p["micro_artifact"]
|
| 511 |
+
assert m["label"] in (MEASURED, HONEST_STUB)
|
| 512 |
+
if m["label"] == MEASURED:
|
| 513 |
+
assert m["verify_ok"] is True
|
| 514 |
+
# recompute the whole roundtrip independently here to prove it is honest.
|
| 515 |
+
w = m["commit"]["weight_vector"]
|
| 516 |
+
x = m["public_input"]
|
| 517 |
+
root2, _ = _merkle_root([str(v).encode() for v in w])
|
| 518 |
+
assert root2 == m["commit"]["merkle_root"], "Merkle root not client-recomputable"
|
| 519 |
+
xb = (",".join(str(v) for v in x)).encode()
|
| 520 |
+
ch2 = _sha256_hex(bytes.fromhex(root2), xb)
|
| 521 |
+
assert ch2 == m["challenge_fiat_shamir"], "Fiat–Shamir challenge not recomputable"
|
| 522 |
+
assert sum(wi * xi for wi, xi in zip(w, x)) == m["output_y"], "output y not recomputable"
|
| 523 |
+
print(f"[4] micro-artifact label={m['label']}, verify_ok={m.get('verify_ok')}, "
|
| 524 |
+
"independently recomputed OK")
|
| 525 |
+
|
| 526 |
+
# 5) no green/1.0 verified state; trust ceiling never 100%.
|
| 527 |
+
assert d["trust_100_percent"] is False and d["trust_ceiling"] < 1.0
|
| 528 |
+
assert "VERIFIED" not in p["label"]
|
| 529 |
+
print("[5] no VERIFIED/green-1.0 top state; trust never 100% OK")
|
| 530 |
+
|
| 531 |
+
print("\n--- payload keys ---")
|
| 532 |
+
for k in p:
|
| 533 |
+
print(f" - {k}")
|
| 534 |
+
print("\nok:true checks:5")
|
| 535 |
+
_sys.exit(0)
|