AI Risk Atlas Prototype/DemoUnofficial independent experiment. Not an official xAI product. Scores can be wrong.

Back to watch register
15Privacy & surveillanceBelow the top 20

Extraction of private training records

CapabilityDomain knowledgeImpact domainCap-adjacent

Statement (NASA form)

Given that memorisation attacks already recover unique strings from large models, there is a possibility of medical notes, source code, or identity documents coming back out resulting in a breach with no incident date, because the leak was the training run.

Likelihood
3Probable
Consequence
4Critical
Urgency
3Priority

You cannot rotate a secret the model ingested in 2023.

Composite 15 = 3×4 + 3

Applicable mitigations

Related on the map