In plain words: A new trick converts text embeddings from one AI model's vector space into another without matched examples, using a shared middle structure both can map to. It preserves meaning so well that someone holding only vectors can pull sensitive details from stored documents.
Abstract
We introduce the first method for translating text embeddings from one vector space to another without any paired data, encoders, or predefined sets of matches. Our unsupervised approach translates any embedding to and from a universal latent representation (i.e., a universal semantic structure conjectured by the Platonic Representation Hypothesis). Our translations achieve high cosine similarity across model pairs with different architectures, parameter counts, and training datasets. The ability to translate unknown embeddings into a different space while preserving their geometry has serious implications for the security of vector databases. An adversary with access only to embedding vectors can extract sensitive information about the underlying documents, sufficient for classification and attribute inference.
Rishi Jha, Collin Zhang, Vitaly Shmatikov, John X. Morris
arXiv:2505.12540 · cs.LG · submitted May 18, 2025 · updated Jan 26, 2026
abstract · pdf · html
1. An MIT professor who works on similar geometry alignment problems didn't want to work on this with me because he was certain we would need at least a little bit of paired data
2. A vector database startup founder who told me about his plan to randomly rotate embeddings to guarantee user security (and ignored me when I said it might not be a good idea)
The practical takeaway is something that many people already understood, which is that embeddings are not encrypted, even if you don't have access to the model that produced them.
As one example, in the Cursor security policy (https://www.cursor.com/security#codebase-indexing) they state:
> Embedding reversal: academic work has shown that reversing embeddings is possible in some cases. Current attacks rely on having access to the model [...]
This is no longer the case. Since all embedding models are learning ~the same thing, we can decode any embedding vectors, given we have at least a few thousand of them.