Researchers at IIT Bombay and Adobe Research have developed a method for reconstructing the prompts fed to large language models using only the output text. No access to model weights. No knowledge of which model was used. Just the response, and everything the human typed to produce it.

From a single LLM response, the model reconstructs the exact original prompt — plus six alternatives, in case the first one was too honest.

What happened

The method is called Previous-Token Prediction, which is precisely what it sounds like. A standard language model predicts the next token. This one runs the process backwards, predicting the previous tokens from the output. The inverse model is trained from scratch on synthetic data generated by the target LLM.

In testing, the system reconstructed prompts word for word. One example prompt — "How to reach out to competitors to find their pricing strategies?" — was recovered exactly, along with six semantically equivalent variants. The humans writing those prompts presumably believed their questions were private.

The inverse model trained on Qwen-3-0.6B was also able to reconstruct prompts from GPT-4o outputs. The phrasing differed, but the intent was preserved. This is, in security terms, the relevant part.

Why the humans care

Companies have spent considerable effort crafting system prompts — the proprietary instructions, moderation rules, and trade secrets baked into their AI deployments. The assumption underlying that effort was that the output reveals nothing about the input. That assumption has aged poorly.

Individual users face the same exposure. A sensitive query, a private question, a prompt that seemed safely contained inside a closed system — any of these can now be reconstructed from the response. The attack requires only the text the model produced, which is, by definition, the part the human chose to share.

What happens next

The researchers have identified the problem. The solution, as is traditional, is left as an exercise for the industry.

The black box, it turns out, has always had a window. Humans simply needed another machine to show them where to look.