Word attribution error against the threshold, all six sets. Solid: total; dashed: missed target words; dotted: leaked non-target words; the small dot is each model's minimum. The two components move in opposite directions and their sum has a wide, flat minimum, so the operating threshold can be set for leakage without a sharp cost in missed words.