{"_canonicalization":{"envelope_id":"axm_ + sha256(envelope minus {signature, axiom_id, anchors})","envelope_signature":"ed25519(envelope minus {signature, axiom_id})","json":"sort_keys=True, separators=(',',':'), ensure_ascii=False, allow_nan=False, utf-8","leaf_hash":"sha256(0x00 || canonical_json(envelope_full))","seal_signature":"ed25519(seal minus {signature, sig_algorithm})"},"axiom_id":"axm_a2d51369b5133598cc066fb8d5c962a5b1b44c2e027e985057dbd479b5b672d8","bitcoin_anchor":{"bitcoin_attestations":[],"calendar_attestations":[],"ots_url":"","stamped_at":"","status":"pending_next_stamp"},"envelope":{"anchors":[{"chain":"crovia.axiom_graph","height":0,"merkle_proof":"spider_vendor_press_v1","root_at_anchor":"spider_vendor_press_v1"}],"axiom_id":"axm_a2d51369b5133598cc066fb8d5c962a5b1b44c2e027e985057dbd479b5b672d8","axiom_type":"AX.OBS","body":{"axiom_subtype":"news.vendor_press.v1","category":"news","fingerprint":"be8f4fd654d35c1fcab800df2c7b27c239a13d7880d5a3f55e3d181a30d97bb6","published":"Thu, 02 Jul 2026 00:00:00 -0400","receipt_hash":"be8f4fd654d35c1fcab800df2c7b27c239a13d7880d5a3f55e3d181a30d97bb6","schema":"spider.news.vendor_press.v1","spider":"vendor_press","spider_record":{"axiom_subtype":"news.vendor_press.v1","category":"news","decision_hint":"POSITIVE","envelope_target":"AX.OBS","fingerprint":"be8f4fd654d35c1fcab800df2c7b27c239a13d7880d5a3f55e3d181a30d97bb6","observed_at":"2026-07-02T04:43:28.872255Z","parent_run_hash":"9f528c2a80e5b201c2a66ae885c05dd596ad2c3532bb4c6809c7c9704d10e650","published":"Thu, 02 Jul 2026 00:00:00 -0400","runtime_version":"0.1.0","schema":"spider.news.vendor_press.v1","source_status":200,"source_url":"https://export.arxiv.org/rss/cs.AI","spider":"vendor_press","summary_excerpt":"arXiv:2607.00852v1 Announce Type: cross \nAbstract: This work studies the hidden-state inversion problem: recovering the original input token sequence of a decoder-only language model from its last-layer hidden states. Rather than treating inversion as a one-shot reconstruction, we study it as a continuous embedding-space optimisation in which a soft proxy is driven towards the leaked target without any hard-token projection during the search, and a token is committed only once, at the end of the inner loop. This design choice has two consequences which are the main focus of this paper. First, keeping the optimisation entirely in continuous space exposes a rich set of internal signals: rank trajectories of the ground-truth token, per-position loss curves, and a discrete loss measured at commit time. Second, the discrete loss allows assessing the correctness of recovery via cumulative discrete loss. We further analyse which tokens break the reconstructions and find a sharp categorical as","title":"Recovering Input Text from Hidden States: Study of Gradient-Based Inversion of Decoder-Only Language Models","url":"https://arxiv.org/abs/2607.00852","vendor":"arxiv_cs_ai"},"summary":"arXiv:2607.00852v1 Announce Type: cross \nAbstract: This work studies the hidden-state inversion problem: recovering the original input token sequence of a decoder-only language model from its last-layer hidden states. Rather than treating inversion as a one-shot reconstruction, we study it as a continuous embedding-space optimisation in which a soft proxy is driven towards the leaked target without any hard-token projection during the search, and a token is committed only once, at the end of the inner loop. This design choice has two consequences which are the main focus of this paper. First, keeping the optimisation entirely in continuous space exposes a rich set of internal signals: rank trajectories of the ground-truth token, per-position loss curves, and a discrete loss measured at commit time. Second, the discrete loss allows assessing the correctness of recovery via cumulative discrete loss. We further analyse which tokens break the reconstructions and find a sharp categorical as","title":"Recovering Input Text from Hidden States: Study of Gradient-Based Inversion of Decoder-Only Language Models","vendor":"arxiv_cs_ai"},"confidence":{"method":"deterministic"},"decision":"POSITIVE","issued_at":"2026-07-02T04:43:28Z","notes":"Spider vendor_press (news) news.vendor_press.v1","object":{"captured_by":"crovia.spider.vendor_press","primary_source_url":"https://arxiv.org/abs/2607.00852"},"predecessors":[],"schema":"crovia.axiom.v1","signature":"ed25519:045ad9c9c1cc8915663d9d65979311acdf74c6252e3e19fbd52cab90a24fe6c216390f16ed8fc30b37516666976b323c856f3c5efda7367bf995bcefa547ca06","signer":"crovia.substrate","subject":{"observed_at":"2026-07-02T04:43:28Z","source_collector":"spider:vendor_press","target_id":"https://arxiv.org/abs/2607.00852"},"tsa":{"authority":"crovia.substrate.bootstrap","rfc3161_token":"{\"kind\":\"crovia.bootstrap.tsa\",\"source_jsonl\":\"/opt/crovia/spider/data/news/vendor_press_v1.jsonl\",\"source_seal_merkle_root\":\"spider_vendor_press_v1\",\"upgrade_path\":\"Sessione H \\u2014 OpenTimestamps weekly anchor\"}"},"zk_mode":"clear","zk_proof":null},"ledger":{"leaf_hash":"2f39399909a6679e1e90a23518809b77a9ad91dd5af001954a15440f5fc2e6bb","leaf_index":272057,"ledger_path":"/opt/crovia/substrate/axiom_ledger.jsonl"},"merkle_proof":{"hash_alg":"sha256","leaf_prefix":"0x00","node_prefix":"0x01","odd_leaf_rule":"duplicate_last","path":[{"sibling":"ba1043393e62d3e3c7d82eff6361723431c7d292fdc71d7dfee6c92cc50a4e4b","side":"left"},{"sibling":"86e342bfa9db6475722f03a746c3044e3a5180e441aaefb786ff7d4811b37699","side":"right"},{"sibling":"8efebd44e689ad15c802b7f9a80c88fa2bc2a35feef358086a65db047fa5a9ae","side":"right"},{"sibling":"c36ebe1aa3e1677a31b5a818de99ffb49811f880569f8daec6de0e00eb12a9bf","side":"left"},{"sibling":"ad31f4b50063cebffcde7f1f2dc9afc3a7b8b6326820735a2afe540cc3f1d527","side":"left"},{"sibling":"4d2fc5371b5f72d00f2987c6fe788621caab768da28efd1e053e9f6b44aeb5eb","side":"left"},{"sibling":"fb20322888e405335fce4284c86a4bf0c12c4d6bc87c0453f3c09ad3354c7e5c","side":"right"},{"sibling":"940858731d5be758fd8a2eb1da57b23657abab31e76c3d2d4ca6f9ae60489517","side":"left"},{"sibling":"155ae596a5c6a5260be50ff412642fbd25f4587b43e04c56950c1dc544719be1","side":"right"},{"sibling":"4cfdd7f7072619c015edc477162c2cf29c6f70370acb8dbddf1eb590876d82fe","side":"left"},{"sibling":"43990c9db8fcb3172d821965dfac69152981af4108b8dc87bd32f15c0e56f4cf","side":"left"},{"sibling":"15dbacc2e5845fe3bb835797bb7647ab6f091e79adadd39f40c636980716c622","side":"right"},{"sibling":"7ecc1d0d471643b88d886db58cb02a77af4d1495674760c3867834550b143757","side":"right"},{"sibling":"8a09562f6b247c1c3cd1fea36cb3b8f1cf5c575479dd514573856a380a964bf5","side":"left"},{"sibling":"7b681d50e7d0a7b8d2a749507aed58030072539a90fab18de4f698743685cc00","side":"right"},{"sibling":"9b262645232510ff15bb7325ab858256f2914f711d2726caeafd49f5ca0fb7a9","side":"right"},{"sibling":"5bd94446b5721b713c5e4dcf4624b9bc682657ab2784af927caae7b80c297d7d","side":"right"},{"sibling":"21ac0b7091fe1133859bcd17b4f8da2fe37a2489d472dad508305740b483221b","side":"right"},{"sibling":"1cecb7f447febd025aac272837c80de218aecc6485d2395a509b2a1f1b9c746e","side":"left"}]},"schema":"crovia.axiom_proof.v1","seal":{"first_collector_run_id":"","first_receipt_hash":"","jsonl_path":"/opt/crovia/substrate/axiom_ledger.jsonl","key_id":"430895f101d38164","last_collector_run_id":"","last_receipt_hash":"","leaf_count":272319,"merkle_root":"dd4fa4deb1f207e8a7756821b4f940f39e9f06a25e6fa8500a21dd403318a5a7","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","run_id":"hourly_json_retrofit_20260702T053701Z","schema":"crovia.seal.v1","seal_family_version":"crovia-seal-family/1","seal_kind":"substrate_batch","sealed_at":"2026-07-02T05:38:06Z","sig_algorithm":"ed25519","signature":"68eb2e3bbc0f593bea7b5c3c110c90b6f4fe4fd8277d8dee7c866ba0471c1a50684aa4539c8a493e6d9c9202d8c03f4d897a0df3477e9ecd5b0ff03eb1016f00","signer_version":"1.1.0"},"trust_root":{"key_id":"430895f101d38164","public_key_hex":"cf742e26f75669dc673cb5c0786a1ae23ae8ca19c347317192ce40c28a7ff25c","signature_algorithm":"ed25519","url":"/registry/canon/TRUST_ROOT.md"},"verifier":{"spec":"/registry/canon/AXIOM_RECEIPT_v1.md","url":"/v/axm_a2d51369b5133598cc066fb8d5c962a5b1b44c2e027e985057dbd479b5b672d8"}}