Search the Atlas

Search risks, controls, and glossary terms

LowModel InversionTheoretical

Model inversion / data reconstruction

Privacy & Data Protection

Description

Attackers reconstruct sensitive training inputs from model outputs or gradients.

Example scenario

Aggregated outputs let an attacker reconstruct features of confidential customer profiles.

Real-world evidenceTheoretical

While purpose limitation violations are a well-established GDPR compliance concern, documented enforcement actions that specifically identify an AI model as the mechanism by which data was processed beyond its collected purpose — as opposed to broader data governance failures — remain rare and are not yet a confirmed production AI incident category.

No public incident on record — evidence level: Theoretical

Primary mitigations

  • Differential privacy
  • output perturbation
  • access restriction
  • gradient protection
  • inversion testing.

Detection signals

Inversion attack simulation; reconstruction-fidelity testing.

Mitigating controls

4
Non-agentic controls

Related risks in Privacy & Data Protection