Anthropic Flags 7 Chinese AI Firms for illicit distillation, Says They Trained on Claude Data
IT DAILY ·
✦ AI Summary
Anthropic said it had detected signs of large-scale illicit distillation involving 7 Chinese AI companies and research organizations targeting Claude.
The targets were Alibaba, Moonshot AI, DeepSeek, Zhipu AI, Xiaomi, SenseTime, and MiniMax, and Anthropic said they had used fake accounts and proxies to mass-collect Claude's responses and reasoning process before using them to train other models.
China's Ministry of Commerce said distillation is a common and neutral technical means in AI, and rejected the U.S. criticism as lacking factual and legal basis.
Anthropic said it had detected signs of large-scale illicit distillation involving Chinese AI companies and Claude. Anthropic published its "AI Misuse Detection and Response" report on the 10th, local time, and disclosed the findings in the report.
The companies and research organizations named were 7 Chinese AI firms: Alibaba, Moonshot AI, DeepSeek, Zhipu AI, Xiaomi, SenseTime, and MiniMax.
Distillation is a training technique that uses the generated answers of a high-performance AI model to train another model. The problem arises when it is carried out on a large scale without the other party's permission.
Anthropic defines the use of fake accounts and proxies as illicit distillation. The collected material was Claude's responses and reasoning process, the method was mass collection, and the purpose was training another model. Anthropic said it regarded such behavior as illicit distillation.
Anthropic's report presented signs, by scale, that several companies had routed traffic through Claude or extracted its reasoning process to operate and train their own models. Among them, Alibaba was named as the largest-scale case in the report, and Anthropic said operators linked to Alibaba collected the reasoning process of Claude Opus 4.6 and 4.7 from May through July. The collection was intended for use in training Qwen models, and the Claude requests and responses observed in the Alibaba-linked attacks exceeded 151 million. During the period when the attacks were concentrated, more than 3,500 fake accounts were deployed, and the daily conversation volume during that time reached nearly 3 million.
A similar pattern was also confirmed in the case of Moonshot AI. From May through July, Moonshot AI routed some customer requests to Claude instead of Kimi and provided users with Claude's answers. Anthropic said Moonshot AI extracted Claude's reasoning process in the process, and that the use case was model training. The requests and responses confirmed in Moonshot AI-related attacks exceeded 23 million.
DeepSeek was also found to have routed some requests to Claude without informing customers. DeepSeek extracted Opus reasoning information, and the confirmed DeepSeek-related requests and responses totaled more than 12.1 million. Anthropic also said it had confirmed cases in which sensitive information, including internal corporate documents, was sent to Claude among DeepSeek user inputs.
Investigators found that Zhipu AI and Xiaomi generated data for training their own models by using Claude's reasoning information and user conversations. SenseTime was found to have used Claude conversation logs collected through a third-party data vendor. Anthropic said MiniMax was found to have collected conversations with U.S. AI models and users through a separate proxy service.
AI model distillation is a method of improving a student model's performance by using a teacher model's large-scale responses as training data.
Anthropic said it had identified with high confidence signs that a certain research institute in China had carried out unauthorized distillation attacks targeting its Opus-class models after February 2026. Anthropic said it continues to detect and block the attacks.
Anthropic said it may require users to verify their identity if it detects signs of potential misuse, such as unauthorized resale of Claude or accounts operating in countries where the service is not supported, including China, Russia, and Iran. Accounts that do not complete identity verification will be blocked. Anthropic said it will continue to incorporate information obtained during the investigation and blocking of distillation attacks into future safeguards.
The Chinese government pushed back against the U.S. criticism of Chinese AI companies' distillation activities. China's Ministry of Commerce on the 9th refuted the U.S. government's claims. The U.S. government said Chinese AI companies had secured the capabilities of advanced U.S. AI models through "industrial-scale" distillation. In response, China's Ministry of Commerce said the claim had no factual or legal basis.
China's Ministry of Commerce said distillation is a common method of mutual learning among models in the AI field. It also said distillation is, in essence, a neutral technical means. It added that distillation is used by AI model companies around the world, including U.S. firms.
The Chinese side said China has opened its open-source models to companies around the world, including U.S. firms. It then said U.S. companies have also been distilling Chinese AI models on a large scale. On that basis, China's Ministry of Commerce argued that the U.S. criticism amounted to a "double standard."
China's Ministry of Commerce said the U.S. side is seeking industrial monopoly under the pretext of cracking down on distillation. It also criticized the U.S. side for interfering in normal commercial activities while invoking national security. It added that the U.S. side is suppressing competition.
Source: IT DAILY · Yang Seung-gap
Original: https://www.itdaily.kr/news/articleView.html?idxno=241555
References
This article was produced with the help of an automated content generation algorithm.
Source: IT DAILY
View originalThis article was summarized and organized by BizCrush based on the original article from IT DAILY. For exact quotations and full details, please refer to the original article.