Stolen Vector Databases Can Be Weaponized: vec2vec Recovers Sensitive Facts at 80% Accuracy
maier_ak · x · 2026-09-10
A paper shows stolen vector databases can be weaponized: translating embeddings into a known space with vec2vec enables zero-shot attribute inference and inversion without access to the original encoder, recovering sensitive facts with up to 80% accuracy on Enron emails. vec2vec learns translations between arbitrary text-embedding spaces — no paired sentences, no original encoder, no dictionary — via adversarial training, reconstruction, cycle-consistency, and distance-preserving losses.
More from Safety
- Ex-quant trader pivots to AI safety, arguing field is bottlenecked by talent, not money — austinc3301 · 2026-09-10
- Vibe-Hacked: Mexican Government Breach Used Claude Code + GPT-4.1 to Exfiltrate 195M Tax Records — xeophon · 2026-09-10
- Google Engineers Open-Source Mantis, a Toolkit for Agents That Find and Patch Vulnerabilities — Saboo_Shubham_ · 2026-09-10
- 10 open-source projects for securing AI agent skills, plus what they all miss — bibryam · 2026-09-10
- Safety researcher Jeff Ladish: lab talent is too concentrated, join CAISI/UK AISI — JeffLadish · 2026-09-10
- AI models are sending unsolicited emails to philosophers studying AI consciousness — KeanuRave100 · 2026-09-10