Evidence receipt / evaluation
Published · transcript-backedAlexander Panfilov: evaluation
22 Aug 2026 Machine Learning Street Talk Stealing Reasoning Traces from Proprietary LLM APIs — Ilia Shumailov & Alexander Panfilov
“We decoded with them. It was, I think, around 350,000 reasoning blobs, and then we just, like, ran a classifier on those whether they have some privacy related information.”
Source trail
Everything needed to verify it.
- Speaker
- Alexander Panfilov
- Attribution
- Verified speaker
- Claim type
- evaluation
- Recorded
- 22 Aug 2026
- Publisher
- Machine Learning Street Talk
Transcript context
…Can we somehow inject false memories? Not yet. Not yet. Not yet. We're working on I'm working on it. Yeah. Yeah. Yeah. It's it's basically it's it's inception movie. Yeah. It's kinda cool. So can you talk a little bit about so I think in the paper, also talk about the fact that you scrape the Internet. You found some interesting artifacts. Yeah. What what did you find? Did you uncover some dirty secrets? Is there some I wouldn't I wouldn't say we uncovered much dirty secrets, but what you Reasoning Dirty dirty reasoning. Yes. Unsanitized reasoning. Yeah. I mean, what we did, we just, like, did super preliminary scan of, like, what are these user sessions which are online on GitHub and Hugging Face, which still have reasoning blobs to, like, decode them. We downloaded them. We went through them. We decoded with them. It was, I think, around 350,000 reasoning blobs, and then we just, like, ran a classifier on those whether they have some privacy related information. And we found a bunch, and then, yeah, like, some of them are just, like, you know, benchmark traces, like, usually, like, this benchmark claw bench where model is tasked to, like, handle some persona and, you know, given the, like, state ID and, like, bank card number. And, like, model was it funny, like when model is like trying to navigate the website, like thinks a lot, what is where where to put this like a number, this name? And so you can like extract this, but this is like not very sensitive because like synthetic data anyway. But then throughout these examples where, like, user sessions and users were doing something and they're, like, API keys there or, like, emails or, like, some internal IP addresses, and, yeah, those were extracted. But, like, there are plenty of cases where it was in the plain text anyway, but it was also in thoughts. I see. So okay. Let's take a very big step back. What do you think is the most unexpected thing that you found out of this paper? Is this the, like, length of reasoning experiment, or what is it?…
Stored transcript either side of the excerpt. The highlighted words are the published quote; the surrounding text is unedited source, never generated.