Language Models are Injective and Hence Invertible
2025/10/17 by Giorgos Nikolaou, Tommaso Mencattini, Nikolaou, Giorgos +9 · 43 voices · 5 citations
#cs.LG #cs.AI
paper · pdf · doi:10.48550/arxiv.2510.15511
Abstract
Transformer components such as non-linear activations and normalization are inherently non-injective, suggesting that different inputs could map to the same output and prevent exact recovery of the input from a model's representations. In this paper, we challenge this view. First, we prove mathematically that transformer language models mapping discrete input sequences to their corresponding sequence of continuous representations are injective and therefore lossless, a property established at initialization and preserved during training. Second, we confirm this result empirically through billions of collision tests on six state-of-the-art language models, and observe no collisions. Third, we operationalize injectivity: we introduce SipIt, the first algorithm that provably and efficiently reconstructs the exact input text from hidden activations, establishing linear-time guarantees and demonstrating exact invertibility in practice. Overall, our work establishes injectivity as a fundamental and exploitable property of language models, with direct implications for transparency, interpretability, and safe deployment.
Citations
Cited by
Discussions
- Language models are injective and hence invertible [hn, 231 points, 148 comments]
- I did not expect that: Large Language Models are invertible: arxiv.org/abs/2510.15511 [bsky, 74 points, 4 comments]
- your embeddings are not safe! every prompt directly maps to its embedding and back. they’re isomorphic SipIt is a linear time algorithm for quickly and efficiently extracting input text from embedding [bsky, 28 points, 3 comments]
- Language Models are Injective and Hence Invertible [lobsters, 26 points, 6 comments]
- Researchers claim their tool can use generated text to discover the prompt that generated it: “language models operate as maps on the *sequence* space rather than the embedding space … all information [bsky, 20 points, 1 comments]
- 詳細はリンク先の記事、および当該の論文を参照ください。 arxiv.org/abs/2510.15511 [bsky, 17 points, 1 comments]
- IMO, the biggest implication here should be for legal challenges to AI companies. This demonstrates that they should *not* fall under fair use exemptions to copyright. They are not akin to a human rea [bsky, 11 points, 0 comments]
- It’s nice to see that sometimes the best way to do an exciting ML paper is still to prove some theorems [bsky, 8 points, 1 comments]
- Language Models Are Injective and Hence Invertible [hn, 4 points, 1 comments]
- Language Models Are Injective and Hence Invertible [hn, 3 points, 1 comments]
- arxiv.org/abs/2510.15511 [bsky, 3 points, 0 comments]
- The bidirectional in BERT means that the model can read the whole sequence at once, instead of autoregressively. That does not in any way mean you can invert it. There are very special types of Neural [stackexchange, 2 points]
- Language Models are Injective and Hence Invertible arxiv.org/abs/2510.15511 [bsky, 2 points, 0 comments]
- omg what?! only at abstract level so far but this is surprising?!????? [bsky, 2 points, 0 comments]
- New arXiv paper just shattered a core myth about AI. LLMs don’t compress meaning — they remember everything. Hidden states are perfect mirrors of our words, not abstractions. Privacy and governance mu [bsky, 1 points, 0 comments]
- arxiv.org/abs/2510.15511 big if true [bsky, 1 points, 0 comments]
- Kielimallit ovat purettavissa. Tällä on valtavia seurauksia tekijänoikeuden, tietoturvan ja kielimallien käytön kannalta. arxiv.org/abs/2510.15511 [bsky, 1 points, 0 comments]
- ..approach model interpretability, debugging, and even privacy protection in AI systems. ArXiv paper on language model injectivity: https://arxiv.org/abs/2510.15511 Llama 3 models reference: https://a [bsky, 1 points, 1 comments]
- Language Models Are Injective and Hence Invertible [hn, 1 points, 0 comments]
- Language Models Are Injective and Hence Invertible [hn, 1 points, 0 comments]
- Language Models Are Injective and Hence Invertible [hn, 1 points, 2 comments]
- Language Models Are Injective and Hence Invertible https://arxiv.org/abs/2510.15511 [bsky, 0 points, 0 comments]
- Language Models are Injective and Hence Invertible arxiv.org/abs/2510.15511 [bsky, 0 points, 0 comments]
- https://bsky.app/profile/news.ycombinator.com.web.brid.gy/post/3m4fvsuxahc52 [bsky, 0 points, 0 comments]
- Language models are injective and hence invertible https://arxiv.org/abs/2510.15511 (http://news.ycombinator.com/item?id=45758093) [bsky, 0 points, 0 comments]
- Language Models Are Injective and Hence Invertible https://arxiv.org/abs/2510.15511 (https://news.ycombinator.com/item?id=45758093) [bsky, 0 points, 0 comments]
- Language Models Are Injective and Hence Invertible arxiv.org/abs/2510.15511 Discuss: www.sqox.com/c/?id=8b8452... [bsky, 0 points, 0 comments]
- arxiv.org/abs/2510.15511 I can't tell if I'm missing something or if this paper is basically completely trivial. like, their algorithm to recover context relies on observing the hidden layer state aft [bsky, 0 points, 1 comments]
- Language Models Are Injective and Hence Invertible https://arxiv.org/abs/2510.15511 (https://news.ycombinator.com/item?id=45758093) [bsky, 0 points, 0 comments]
- Language Models Are Injective and Hence Invertible view on hacker news [bsky, 0 points, 0 comments]
- The paper itself: arxiv.org/pdf/2510.15511 [bsky, 0 points, 0 comments]
- ⚡ Hackernews Top story: Language Models Are Injective and Hence Invertible [bsky, 0 points, 0 comments]
- Language Models are Injective and Hence Invertible [bsky, 0 points, 0 comments]
- "Language Models are Injective and Hence Invertible" https://arxiv.org/abs/2510.15511 [bsky, 0 points, 0 comments]
- @theaifix.show have you seen the latest research? LLMs are deterministic and you can reverse the input and training data. www.arxiv.org/pdf/2510.15511 [bsky, 0 points, 0 comments]
- Language Models Are Injective and Hence Invertible [bsky, 0 points, 0 comments]
- Language Models Are Injective and Hence Invertible #HackerNews https://arxiv.org/abs/2510.15511 [bsky, 0 points, 0 comments]
- Language Models Are Injective and Hence Invertible https://arxiv.org/abs/2510.15511 https://news.ycombinator.com/item?id=45758093 [bsky, 0 points, 0 comments]
- Language Models Are Injective and Hence Invertible https://arxiv.org/abs/2510.15511 [bsky, 0 points, 0 comments]
- Language models are injective and hence invertible View Article | Join the HN Conversation Summary of HN discussion 🧵👇 #hacker-news [bsky, 0 points, 1 comments]
- 📰 Language Models Are Injective and Hence Invertible 🔗 https://arxiv.org/abs/2510.15511 💬 Discuss on HN [bsky, 0 points, 0 comments]
- Here is the full article. [bsky, 0 points, 1 comments]
- Language Models are Injective and Hence Invertible https://lobste.rs/s/ukvfgs #security #math #ai [bsky, 0 points, 0 comments]
Related