ZK-Receipt: Privacy-Preserving Verifiable Provenance for Intermediated AI Services
Abstract
AI services are increasingly accessed through APIs, gateways, and third-party intermediaries, creating a gap between the service requested by a user and the provenance evidence available for the delivered response. We introduce ZK-Receipt, a framework for privacy-preserving verifiable provenance of provider-attested AI interactions. A provider issues a signed credential binding a prompt commitment, response digest, recipient-generated service commitment, and authenticated registry state. ZK-Receipt supports selective disclosure of provenance claims: a zero-knowledge presentation proves that the interaction was signed under an authorized provider/model entry and that the same hidden provider/model pair is bound to the recipient’s requested service, without revealing transcript plaintext or credential information to a public verifier. The recipient additionally checks consistency with its retained request state and delivered response. Under explicit cryptographic and trust assumptions, ZK-Receipt provides authorization soundness, recipient-detectable end-to-end integrity, and provider and model presentation privacy. It does not prove model execution or response correctness. A Circom/Groth16 prototype achieves median proving times below 1.5,s across three registry depths, with nearly constant verification gas on a local EVM.