Background
A deployed large language model can continue to perform normally on routine benchmarks while changing in ways that matter. Fine-tuning, adapters, model editing, poisoning, backdoors, or a compromised software supply chain can alter targeted behavior without producing an obvious decline in average performance. That creates a governance problem: an organization may approve one model, then have limited visibility into whether the system serving users remains behaviorally consistent with it.
The risk includes more than model weights. The supplied OWASP LLM supply-chain guidance describes threats affecting training data, models, adapters, dependencies, and deployment platforms. It recommends provenance controls, inventories, signing, hashes, red-teaming, anomaly detection, monitoring, and related safeguards. Those measures help establish what entered a system and how it is operated, but they do not directly test whether a deployed model still behaves like an approved reference.
Zero-knowledge proofs provide a different kind of evidence. As NIST explains, they allow one party to prove that a mathematical statement is true without revealing additional information about the secret witness behind it. That property is useful when model behavior, audit inputs, and operational details are commercially or security sensitive.