> I do not see the threat.
It becomes one if for some reason you decide to train your model on sensitive data.
It becomes one if for some reason you decide to train your model on sensitive data.
Then again, if you have access to a model trained on sensitive data, why not ask the model directly, instead of probing it for training data? If sensitive data never is meant to be reasoned on and outputted, why did you train on sensitive data in the first place?
I still have trouble seeing a direct threat or attack scenario here. If it is privacy sensitive data they are after, a regex on their comparison index should suffice and yield much more, much faster.