dot product
How does zkVM proving cost scale with a large dot product, 10^3 to 10^6 elements — and what is the marginal cost of one proved multiply-accumulate?
Overview
README.md ↗Checkpoint: CP-002 Status: QUEUED — not yet run. No results exist for this experiment.
Question
How does zkVM proving cost scale with a large dot product, 10^3 to 10^6 elements — and what is the marginal cost of one proved multiply-accumulate?
Why it matters
Experiment 001 showed the cost is dominated by a fixed charge at small sizes. CP-002 measures the slope — the number that lets us extrapolate proving cost to any model size without running the model. It is also the first head-to-head between a general zkVM and a specialised argument (H3).
Gate
Ready to start. Depends only on E001, which is complete.
This is a stub. It exists so the roadmap's structure is visible, not to imply
work has been done. Nothing in ../../benchmarks/results/ refers to it yet.
Hypothesis
hypothesis.md ↗Research question (CP-002)
How does zkVM proving cost scale with the size of a dot product, and what is the marginal cost of one proved multiply-accumulate?
y = Σ xᵢ·wᵢ for n = 10^3, 10^4, 10^5, 10^6.
Why this specific shape
E001 established that SP1's cost at small sizes is a fixed per-proof charge. The number that actually lets us predict anything about neural inference is the marginal cost per proved arithmetic operation, because a forward pass is, to first order, a very large number of multiply-accumulates. Once we have seconds-per-MAC we can extrapolate to any model size without running it, and that extrapolation is the input to every economic decision downstream.
A dot product is the right vehicle: it is one MAC repeated, it is the inner loop of matrix multiplication, and it has no non-linearity to confound the measurement.
Hypotheses
H2a. Above the fixed-cost knee identified in E001, proving time is linear in n with a stable slope over at least three decades.
H2b. The zkVM charges many RISC-V cycles per useful MAC — the ratio of proved cycles to useful arithmetic operations is ≥ 5×, because loads, index arithmetic and loop control are all proved alongside the arithmetic that matters. This "cycle tax" is the core inefficiency of the general-zkVM approach and quantifying it is the main deliverable.
H2c (tests H3). A specialised argument for the same statement — a sumcheck or inner-product argument over the same vectors — beats the zkVM by ≥ 100× in prover time, because it charges for the arithmetic relation rather than for a RISC-V execution trace.
H2d. Verification cost stays roughly flat in n for compressed proofs, so
R_verify improves with problem size. If so, the general-zkVM approach is
economically hopeless for small jobs and merely very expensive for large ones —
which is a different and more actionable conclusion than "ZK is expensive".
Predictions (record before running)
| quantity | prediction |
|---|---|
| cycles per MAC (u64) | 5–20 |
| prove time at n = 10^6 | 60–600 s |
| slope stability across 10^3→10^6 | within 2× |
| specialised vs zkVM gap | 10^2–10^4 × |
R_verify at n = 10^6 |
still ≫ 1 |
Measurement additions over E001
- Integer and fixed-point variants. Real inference is not
u64. A fixed-point variant with an explicit rescale per MAC measures what quantisation costs inside a zkVM. - Compressed mode throughout, since E001 suggests core proofs are the wrong product for a coordinator verifying every job.
- Prover memory as a first-class result. E001 hit 8.3 GB peak RSS at 5M cycles. If memory scales with cycles, the binding constraint on provable job size is RAM, not time — which changes what hardware a Nodus prover needs and therefore what it costs.
- A second zkVM (RISC Zero) so that the slope is not an SP1 artefact.
What would falsify the whole general-zkVM branch
If cycles-per-MAC is ≥ 10 and the marginal proving rate stays near E001's measured rate, then proving a single 0.5B-parameter forward pass lands in the range of years of CPU time. If that extrapolation holds, general zkVMs are removed from the Nodus candidate set for inference (they may survive for small control-plane statements), and the programme's ZK effort moves entirely to specialised arguments. Making that call on measured evidence is the point of E002.