Chinese AI Labs Secretly Leveraged Millions of Claude Exchanges for Model Training

Anthropic reports that Chinese entities, including Alibaba, Moonshot, and DeepSeek, engaged in unauthorized AI model training. They used “illicit distillation,” training their models on outputs from Anthropic’s Claude without permission. This practice infringes intellectual property and may violate data privacy, as sensitive information was accessed. Alibaba’s campaign involved millions of interactions, while Moonshot and DeepSeek also systematically diverted user requests to Claude for training data.

Anthropic has revealed a sophisticated network of large-scale, unauthorized AI model training operations orchestrated by China-based entities, including prominent players like Alibaba, Moonshot, and DeepSeek. The U.S. artificial intelligence company announced on Thursday that these organizations engaged in “illicit distillation,” a technique where the output of a highly capable AI model, such as Anthropic’s Claude, is systematically used to train and replicate its functionalities in other models without permission.

This clandestine practice, detailed in a new threat intelligence report from Anthropic, not only infringes on intellectual property but also raises significant concerns regarding data privacy and security. The report highlights that some of the data extracted through these distillation efforts included sensitive information originating from individual users, major multinational corporations, and even state-affiliated actors. Such unauthorized access and utilization of data are likely in direct violation of privacy regulations and the terms of service agreements of the implicated AI labs.

Anthropic’s investigation identified specific instances of these illicit activities. Operators affiliated with Alibaba were found to have leveraged Claude’s outputs to enhance their own Qwen models. Similarly, Moonshot AI, the developer behind the Kimi family of AI models, was observed routing user requests intended for Kimi to Claude, subsequently using the generated responses to train its proprietary models.

The scale of Alibaba’s operation appears to be the most significant distillation campaign Anthropic has yet documented. Between May and July, this campaign involved an astonishing volume of over 151 million interactions with Claude. The report indicates that this activity reached its zenith with nearly 3 million exchanges per day, facilitated by more than 3,500 fraudulent accounts. Beyond simply replicating capabilities, Anthropic’s findings suggest Alibaba also utilized Claude for broader AI research initiatives, including advancements in reinforcement learning and model architecture.

**Moonshot and DeepSeek’s Deceptive Tactics**

The report further scrutinizes the operations of Moonshot AI, a Beijing-based company. Anthropic’s findings reveal that Moonshot systematically diverted a substantial portion of customer requests meant for its Kimi models to Claude, presenting Claude’s responses to users as if they were generated by Kimi. During a concentrated 10-day period, Moonshot relayed close to 300,000 customer requests to Anthropic, with the vast majority routed to Claude Opus models. These requests were funneled through a network of 5,380 accounts identified as fraudulent, predominantly appearing to be based in Singapore and Japan. Moonshot then archived these interactions, extracting Claude’s reasoning transcripts to serve as training data for its own development. Between May and July, over 23 million exchanges were attributed to Moonshot’s distillation efforts. Crucially, some of these customer queries contained sensitive information, and Anthropic remains uncertain whether Moonshot had obtained customer consent for routing their requests to a third-party AI.

DeepSeek, a company that gained considerable recognition last year for its powerful yet cost-effective AI models, employed similar deceptive strategies. Anthropic observed DeepSeek transferring exchanges to Claude without informing its own customers. Over a mere 14-day period in July 2026, Anthropic detected more than 12 million distillation attacks attributable to DeepSeek.

The comprehensive report from Anthropic, which names several other major Chinese AI firms, details a wide array of malicious activities disrupted between December 2025 and August 2026. These activities span seven distinct categories: cyber operations, influence operations, surveillance, scams and fraud, biological misuse, conventional weapons development, and the aforementioned AI model distillation. The ramifications of these findings extend beyond the competitive landscape of AI development, touching upon critical issues of cybersecurity, intellectual property rights, and the responsible governance of advanced artificial intelligence.

Original article, Author: Tobias. If you wish to reprint this article, please indicate the source:https://aicnbc.com/25629.html

Like (0)
Previous 7 hours ago
Next 5 hours ago

Related News