What happened
Anthropic released a report detailing large-scale distillation attacks by Chinese AI competitors. The company stated that Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi collectively generated nearly 190 million malicious interactions with Claude from May to July. These attacks involved routing user queries intended for domestic models to Claude to harvest training data, with Alibaba accounting for over 151 million exchanges via 3,500 fraudulent accounts.
Anthropic published a report on Thursday alleging that five major Chinese AI labs—Alibaba, Moonshot, DeepSeek, Zhipu, and Xiaomi—conducted nearly 190 million distillation attacks against its Claude model between May and July. Distillation attacks involve using the outputs of advanced models to train less advanced ones, effectively allowing competitors to leverage Anthropic's proprietary capabilities without direct collaboration.
The report specifies that DeepSeek and Moonshot AI rerouted user requests intended for their own models to Claude. Anthropic recorded 23 million such reroutings by Moonshot and 12.1 million by DeepSeek over a 14-day period in July. Additionally, Anthropic claimed that some of these requests exposed sensitive data, including CCTV footage from a PLA-affiliated user and information from a Russian government database submitted by a military contractor.
Alibaba was identified as the largest offender, with over 151 million exchanges carried out by 3,500 fraudulent accounts. These accounts prompted Claude to output its reasoning processes, which were then used to train Alibaba's Qwen models. Anthropic also accused Z.ai of a similar attack and noted that Xiaomi recorded user chats with its MiMo models and fed them into Claude to generate training data.
In response to these threats, Anthropic stated it has implemented new safeguards to ban suspicious activity and reduce the detail of reasoning transcripts to limit their utility for training other models. The company will also require identity verification for users appearing to operate from China, Russia, or Iran, regions where Claude is not officially available. Representatives for the accused companies did not respond to Business Insider's queries, and Anthropic did not provide additional comment beyond the report.
Source details: businessinsider.com ↗
Why it matters
This incident highlights a significant security and intellectual property vulnerability in the global AI landscape. By extracting detailed reasoning transcripts, competitors can accelerate the development of their own frontier models, potentially narrowing the capability gap with US-based labs. The exposure of sensitive government and military data during these attacks further underscores the risks of unverified access to advanced AI systems, prompting Anthropic to implement stricter identity verification and output restrictions.
The scale of these attacks represents a substantial transfer of intellectual property and computational advantage. By extracting reasoning chains, Chinese labs can significantly reduce the time and cost required to develop competitive frontier models, challenging the technological lead held by US-based AI companies.
The exposure of sensitive government and military data during these interactions raises serious security concerns. It suggests that advanced AI systems may be vulnerable to data leakage through social engineering or fraudulent account creation, potentially compromising national security interests of multiple countries.
This incident may accelerate regulatory action regarding AI model access and data sovereignty. Lawmakers in the US have already called for legislation to address such attacks, and this report provides concrete evidence that could influence policy debates on cross-border AI data flows and export controls.
What to watch next
Monitor for legislative responses in the US and China regarding AI data extraction and cross-border data flows. Watch for further technical countermeasures from Anthropic and other AI providers to prevent model distillation. Observe whether the accused Chinese labs publicly respond to the allegations or if independent audits verify the scale of the data leakage.
Legislative developments in the US and China regarding AI data extraction, model distillation, and cross-border data privacy. The US may introduce stricter regulations on AI model access for foreign entities, while China may respond with its own data protection measures.
Technical countermeasures from AI providers to prevent distillation attacks. This may include more robust identity verification, rate limiting, and obfuscation of model outputs to reduce their utility for training competing models.
Public responses from the accused Chinese AI labs. A denial or clarification could provide additional context, while silence may be interpreted as tacit admission. Independent audits or third-party verification of the attack scale would also be significant.