How to Steal Reasoning Without Reasoning Traces
Abstract
Many large language models (LLMs) generate multi-step reasoning traces (a.k.a. chains of thought) but expose only final answers and brief reasoning summaries. Recent work recovered reasoning traces through provider-specific API vulnerabilities that were subsequently patched. We ask whether properly hiding reasoning traces is sufficient to prevent extraction of a model's reasoning capabilities. The answer is no. We introduce Trace Inversion models that synthesize detailed reasoning traces with only ordinary black-box access to models' inputs and outputs. We show that (1) fine-tuning student models on synthesized traces substantially improves downstream reasoning, enabling distillation from proprietary black-box LLMs, and, in many cases, (2) the synthesized traces heavily overlap with the ground-truth traces (where the latter are available).
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.