Independent review will determine whether Hollow-LLM ghost-weight attacks can reliably fool existing zero-knowledge verification schemes for LLM weights and require stronger integrity checks.
state: expiredheat: lowuncertainty: highknownscott: lowllm-security model-verification zero-knowledge-proofs
What is this?
Hollow-LLM is presented in the case as a proposed “ghost-weight” attack intended to fool zero-knowledge verification of LLM weights, but the supplied search results do not identify its authors, mechanism, paper, or an independent review. The results instead discuss adjacent work showing that targeted attacks can defeat LLM fingerprinting, iSeal’s adversarial ownership verification, PVMark’s zero-knowledge watermark verification, and Google’s activation-based model scanner. Accordingly, neither Hollow-LLM’s reliability against existing zero-knowledge schemes nor the claimed need for stronger integrity checks is established by the supplied web evidence.
Why it matters to Scott
Scott’s Cryptographic Trust and Mechanically Different Verifiers pages already hold that integrity claims require independently checkable evidence and checks with distinct failure modes; Defense In Depth already argues against relying on one safeguard. Hollow-LLM is currently an unverified possible example rather than an established challenge or extension, though it relates to the radar’s existing model-fingerprinting and behavioral-fidelity verification cases.
ip:concept.cryptographic-trustip:concept.mechanically-different-verifiersip:concept.defense-in-depthradar:one-token-api-model-fingerprintingradar:compressed-llm-fidelity-safety-gap
queries asked of Scott's wikis
- adversarial model-weight integrity verification
- zero-knowledge proofs for model provenance
- LLM fingerprinting and ownership attacks
- open-weight model supply-chain security
- tamper detection for local model weights
- cryptographic attestation versus behavioral model verification
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-08-06T10:21:40Z
No independent review, implementation evidence, or substantive discussion emerged within the initial window, leaving the ghost-weight claim an unverified paper assertion with no demonstrated consequence for existing verification schemes.
2026-08-04T02:26:04Z
grounded: known/low — Scott’s Cryptographic Trust and Mechanically Different Verifiers pages already hold that integrity claims require independently checkable evidence and checks wi
2026-08-04T02:24:40Z
case created — This is a bounded security claim from an original paper, but it has not yet attracted discussion or independent validation.
Decision trace
- 08-06 20:21expireNo independent review, implementation evidence, or substantive discussion emerged within the initial window, leaving the ghost-weight claim an unverified paper assertion with no demonstrated consequen
- 08-04 12:26groundScott’s Cryptographic Trust and Mechanically Different Verifiers pages already hold that integrity claims require independently checkable evidence and checks with distinct failure modes; Defense In De
- 08-04 12:24createThis is a bounded security claim from an original paper, but it has not yet attracted discussion or independent validation.