Does Mean Pooling Erase Text?
Abstract
Mean pooling and normalization aggregate a token sequence into one vector, but do they erase its lexical identity? We study reconstruction from native Nemotron-3-Embed-8B passage embeddings, with controlled raw-token pooling across six models as complementary evidence. For a specified fixed-length causal transformer parameter family, we establish generic spherical injectivity in exact arithmetic, without guaranteeing injectivity of trained checkpoints or efficient reconstruction. Under open-weight and victim-query access, our method combines a learned base inverter, target-conditioned prefix guidance, residual-conditioned iterative correction, and victim re-embedding with a persistent candidate archive. Reconstructing eight-token AG-News fragments from native passage embeddings reaches 87.54% token accuracy and 72.60% exact match. On separate eight-token WikiText-2 raw-pooling benchmarks, Nemotron-3 and Jina-v4 reach 94.40% and 97.20% exact match, respectively. Recovery depends strongly on model and domain and deteriorates markedly in the tested 16- and 32-token raw-pooling settings. Candidate-oracle analyses show that most failed reconstructions lack the complete target in the generated archive, while numerical audits show that small residuals need not identify the original text. These findings distinguish architectural identifiability, numerical separation, and computational recoverability, exposing short-text reconstruction risks without implying universal invertibility.
est. 32% chance this paper gets accepted at ICLR 2027.
What do you think this paper will get?
All positions stay anonymous.