Characterize generalization beyond digit and binary predicates

Investigate whether inadvertent context-leakage attacks and measurements generalize to predicate types, language models, and deployment configurations beyond the digit-value and binary-attribute settings evaluated in the paper.

Background

The experimental evaluation considers two predicate families: numeric digit values and binary attributes representing whether user-memory attributes are present. It also uses a fixed collection of models and deployment assumptions, including black-box query access and the ability to perform estimation queries. The paper explicitly leaves open whether its findings extend to other predicates, models, and deployment configurations.

References

We leave generalization to other predicate types, models, and deployment configurations open.

Inadvertent Context Leakage in Language Models  (2608.19857 - Fairoze et al., 20 Aug 2026) in Section 6, paragraph “Limitations.”

We treat this result as exploratory, with model-class invariance unresolved.

Selection, Recombination, or a Fresh Solve? A Candidate-Free Control for Single-Pass Test-Time Aggregation  (2608.18379 - Farmanfarmaian, 18 Aug 2026) in Appendix G, “The reasoning-trained variant”; Section 5, Limitations