What an attacker can recover through an inference API alone, what the published results actually demonstrated, and which API surfaces widen the attack.