Large language models can reconstruct forbidden knowledge