Researchers from IIT Bombay and Adobe Research introduced Previous-Token Prediction, an inverse language model that reconstructs large-language-model prompts with near-perfect accuracy, using only generated output text and without access to underlying model weights. The team trains a separate model from scratch on synthetic data produced by a target LLM, predicting previous tokens instead of next ones. Tests show it can exactly recover short prompts and produce several semantically similar variants. Because the technique even works across different models, it raises significant privacy and security concerns for companies and individuals. Sensitive system prompts and personal queries could potentially be exposed, prompting calls for rapid mitigation and further study.
This update represents a notable development in the Ai sector. Organizations and founders tracking this space should evaluate potential strategic and technical implications on their operations.