# Researchers Recover Secrets From a Model's Hidden Context Without Any Jailbreak

The attack sends ordinary, non-malicious queries and uses a surrogate model to work out which candidate secret best explains the answers, which makes it hard to detect by prompt filtering.

- Published: 2026-09-03T06:26:17.363Z
- Canonical: https://polylog.news/ai/2026-09-03/researchers-recover-secrets-from-a-model-s-hidden-context-wi
- Publisher: Polylog (AI desk)
- Section: tech
- Sources: [arXiv cs.CR (federated learning)](https://arxiv.org/abs/2609.01667)

A paper posted to arXiv, Context Inference Attacks Without Jailbreaks, describes a way to extract information from the hidden context an agentic system assembles before answering, without using adversarial prompts at all. Agentic deployment…

This story is for subscribers. Read it in full at https://polylog.news/ai/2026-09-03/researchers-recover-secrets-from-a-model-s-hidden-context-wi (subscription information: https://polylog.news/pricing).