6.2 AI for Defence · Module 6 ยท Adversarial Risks

Model Inversion & IP Exposure

Why ‘it trains on input’ is a confidentiality problem โ€” and the three leak patterns.

AdversarialIP~12 min

The big idea

Model inversion is the risk that data fed into a model which trains on user input can be extracted later. That's exactly why the PSPF Advisory restricts use to providers with contractual no-training defaults (or a completed FOCI assessment). For contractors, three IP-leak patterns recur: a code leak (Samsung-style), a document leak (NSW RA-style), and a capability leak โ€” drafting tenders or white papers with capability-revealing content in a public LLM that retains and may train on it.

Key insight: Assume anything placed into a consumer AI that trains on input may resurface later. Enterprise/API services with contractual no-training guarantees are the baseline for anything you'd mind seeing again.

What you'll see

Model inversion and the three contractor IP-leak patterns.

The risk and the patterns

What to guard against. Tap to expand.

Key points to remember

Model inversion: data that trained a model can sometimes be extracted.
No-training contractual guarantees are the baseline for sensitive work.
Three contractor leak patterns: code, document, capability.
Even a brief 2023 ChatGPT bug exposed other users' histories โ€” nothing in a public tool is guaranteed private.