Take a system trained to make predictions on a language (word or character) model – an example you’re probably familiar with is Google Smart Compose. Now feed it a prefix such as “My social security number is “. Can you guess what happens next?
Read the whole thing. There’s a bit of discussion at the end around how you can stop this learning of secrets.