Model inversion
Models can reveal things about the data they were trained on, sometimes reproducing fragments of it directly.
That makes training data a privacy question rather than only a technical one. Personal information included in a training set does not necessarily stay inside the model, and there is no reliable way to remove it afterwards short of retraining. It is a good reason to be careful about what goes in, because the decision is effectively permanent.
Checked against the primary source.
