<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Reasoning Extraction on Lynx Tech Blog</title><link>https://blog.lynxflow.co/en/tags/reasoning-extraction/</link><description>Recent content in Reasoning Extraction on Lynx Tech Blog</description><generator>Hugo -- gohugo.io</generator><language>en</language><lastBuildDate>Sun, 09 Aug 2026 00:00:00 +0800</lastBuildDate><atom:link href="https://blog.lynxflow.co/en/tags/reasoning-extraction/index.xml" rel="self" type="application/rss+xml"/><item><title>Turn Off the Vendor’s Scratchpad and Hand the Model a New One: A Simple Attack for Extracting AI Reasoning</title><link>https://blog.lynxflow.co/en/posts/extracting-llm-reasoning-traces-via-tool-params/</link><pubDate>Sun, 09 Aug 2026 00:00:00 +0800</pubDate><guid>https://blog.lynxflow.co/en/posts/extracting-llm-reasoning-traces-via-tool-params/</guid><description>&lt;img src="https://blog.lynxflow.co/images/extracting-llm-reasoning-traces-via-tool-params.png?v=090500" alt="Featured image of post Turn Off the Vendor’s Scratchpad and Hand the Model a New One: A Simple Attack for Extracting AI Reasoning" /&gt;Vendors Locked the Front Door, but Forgot the Window Major model vendors have reached an unspoken consensus: you don’t get to see the raw reasoning process. OpenAI, Anthropic, and Google only return either a “summarized thought process” or a chunk of encrypted data through their APIs, which you can pass back unchanged so the model can continue the context, but you cannot read its contents.
The rationale is perfectly legitimate: raw reasoning may contain API keys, email addresses, access tokens,</description></item></channel></rss>