ZKML (ddkang)
Daniel KangZKML (ddkang) compiles a TensorFlow Lite model into a Halo2 zero-knowledge circuit and proves that an inference ran on that model, so a verifier can check the output without re-running the model or trusting whoever ran it. It is a Rust library with Python converters for models and inputs, and proves with either KZG or IPA commitments. Daniel Kang publishes it from a personal GitHub account, with the paper that describes the method.
Tagged independently verifiable. The only zero-knowledge inference prover on the map under an OSI license, and dormant: no tagged release, and the repository was last pushed in May 2024, so the entry is read against the repository head.
Openness
5 high confidence- license
- Apache-2.0(OSI)
- source
- public
- core features withheld
- no
Daniel Kang publishes the prover and its converters under Apache-2.0, with no paid edition or withheld component, so anyone may run, modify and redistribute it. The placeholder crate on crates.io declares AGPL-3.0-or-later instead; it carries none of the prover, so the repository's license governs.
- https://crates.io/api/v1/crates/zkml/0.0.1 recorded 2026-09-27
zkml 0.0.1, created 2023-02-27: license AGPL-3.0-or-later, has_lib false, bin_names [main], one Rust file, crate_size 15,542 bytes
- https://raw.githubusercontent.com/ddkang/zkml/main/Cargo.toml recorded 2026-09-27
Package zkml 0.0.1, "Zero-knowledge machine learning", license = "LICENSE" (the file name put in the SPDX field), homepage github.com/ddkang/zkml, repository github.com/ddkang/zkml-public.git; depends on the PSE halo2, halo2_gadgets and halo2_proofs crates
- https://raw.githubusercontent.com/ddkang/zkml/main/LICENSE recorded 2026-09-27
Apache License, Version 2.0, full text; the appendix copyright line is left as the unfilled template
- https://ungh.cc/repos/ddkang/zkml/files/main recorded 2026-09-27
Full file listing of ddkang/zkml main at 4378958, 125 paths: src/, python/ converters, examples/, testing/; no ee/, enterprise/, commercial/ or proprietary/ directory
- https://ungh.cc/repos/ddkang/zkml/releases recorded 2026-09-27
No releases published for ddkang/zkml
Adoption
1 low confidenceGitHub stars are the only signal: the prover is installed by building the repository, and the zkml crate is a placeholder that does not contain it. A star is not a use.
- https://crates.io/api/v1/crates/zkml/0.0.1 recorded 2026-09-27
zkml 0.0.1, created 2023-02-27: license AGPL-3.0-or-later, has_lib false, bin_names [main], one Rust file, crate_size 15,542 bytes
- https://ungh.cc/repos/ddkang/zkml recorded 2026-09-27
ddkang/zkml: 379 stars, 42 forks, default branch main, pushed 2024-05-17
Capability
5 medium confidenceA proof lets anyone confirm that a specific model computed a specific output without trusting the party that ran it, which puts ZKML beside NVIDIA's hardware attestation at the top of the category. It accepts only TensorFlow Lite models.
- https://arxiv.org/abs/2210.08674 recorded 2026-09-27
"Scaling up Trustless DNN Inference with Zero-Knowledge Proofs", the paper the README cites for implementation details
- https://raw.githubusercontent.com/ddkang/zkml/main/Cargo.toml recorded 2026-09-27
Package zkml 0.0.1, "Zero-knowledge machine learning", license = "LICENSE" (the file name put in the SPDX field), homepage github.com/ddkang/zkml, repository github.com/ddkang/zkml-public.git; depends on the PSE halo2, halo2_gadgets and halo2_proofs crates
- https://raw.githubusercontent.com/ddkang/zkml/main/README.md recorded 2026-09-27
"zkml is a framework for constructing proofs of ML model execution in ZK-SNARKs"; "Currently, we accept TFLite models"; the quickstart creates params_kzg and params_ipa and proves an MNIST circuit with kzg
Verified 2026-09-27