ZK-EdgeLoRA: Zero-Knowledge Proofs for LLM Plugins in Edge Computing
Abstract
Finetuning Large Language Models (LLMs) is a highly effective way to improve their performance on the specific domains that need expertise knowledge. However, fine-tuning very large models is prohibitively expensive. A trending solution is to train a much smaller adapter, dubbed LoRA, serving as a “plugin” to the model. However, in an untrusted distributed edge computing environment, when a user of an open-source base model wishes to utilize LoRA weights provided by external contributors, it is crucial to ensure that the LoRA weights are correctly matched with the intended base model and that the LoRA computation process is executed correctly. In this paper, we present ZK-EDGELORA, an efficient zero-knowledge (ZK) protocol that allows the LLM adapter (LoRA, the prover) to convince the base LLM model (the verifier) of its computing pro- cess, without revealing any information apart from the fact that the LoRA computing process is true. In particular, by leveraging VOLE-based “commit-and-prove” style ZK protocol, our solution enables efficient batch verification of matrix operations while preserving privacy. The proposed ZK-EDGELORA can safely and efficiently validate the correctness of each LoRA module within 0.1 to 2.8 seconds, depending on the weight size of the LoRA layer, when applied to real-world medical adapters from HuggingFace. The protocol establishes a scalable trust framework for distributed LLM deployments, bridging the gap between performance and security in modular AI ecosystems.
Community
0 commentsNo discussion yet
Be the first to share a question or observation.