Research questionCan black-box attackers identify and reconstruct prompts supposedly removed from language models without knowing them in advance?Machine unlearning may suppress responses to removed data without eliminating signals that reveal what was removed. The difficulty is determining whether an attacker can use those signals to discover and reconstruct forgotten prompts that are initially unknown.