PulseAugur
EN
LIVE 23:55:07
Français(FR) Un system prompt se reconstitue à partir d'une seule réponse

New method reconstructs LLM prompts from output alone

Researchers from IIT Bombay and Adobe Research have developed a method called Previous-Token Prediction (PTP) that can reconstruct a model's original prompt from its generated text alone. This technique trains an inverse model to predict preceding tokens instead of the next one. A PTP model trained on a small open-source model like Qwen-3-0.6B can accurately infer the intent and meaning of prompts sent to larger, proprietary models such as GPT-4o, even without knowing which model produced the output. While the current demonstration is limited to short prompts, it raises concerns about the security of proprietary system prompts used by companies. AI

IMPACT Raises concerns about the security of proprietary system prompts and could impact how companies protect their AI instructions.

RANK_REASON Research paper detailing a new method for prompt reconstruction. [lever_c_demoted from research: ic=1 ai=1.0]

Read on dev.to — LLM tag →

AI-generated summary · Google Gemini · from 1 sources. How we write summaries →

New method reconstructs LLM prompts from output alone

How we ranked this

Signal score
0 / 100
Composite score across the factors below. Higher = stronger signal that this story matters right now.
Newsworthiness bucket
Tool
Research paper detailing a new method for prompt reconstruction. [lever_c_demoted from research: ic=1 ai=1.0]
Source corroboration
Single-source cluster
Only one publisher covered this so far. Single-source stories can still rank when the publisher is high-authority, but they lack cross-source corroboration.
Topics
paper, safety
Editorial topic classification. Feeds into how the story surfaces on /topic/<slug> hub pages and into the per-entity coverage mix.
AI-industry relevance
High
Clearly on-topic for AI-industry coverage.
Story freshness
45 days old
Aged out of breaking-news scoring windows; ranking reflects the durable signal from the full source set.

Full methodology in our editorial standards.

COVERAGE [1]

  1. dev.to — LLM tag TIER_1 Français(FR) · Thibault Monteiro ·

    A system prompt is reconstructed from a single response

    <p>L'essentiel</p> <ul> <li> Des chercheurs de l'IIT Bombay et d'Adobe Research reconstituent le prompt d'origine à partir du seul texte produit par un modèle, sans accès à ses poids.</li> <li> Leur méthode, baptisée « Previous-Token Prediction », entraîne un modèle inverse qui p…