← Google News

‘AI Cannibalism’: Anthropic accuses Chinese tech giant Alibaba of 29 million adversarial distillation attacks. What is it? - WION

Google News · June 26, 2026
‘AI Cannibalism’: Anthropic accuses Chinese tech giant Alibaba of 29 million adversarial distillation attacks. What is it? WION [truncated: Google News RSS provides only a snippet, not full article

Detailed Analysis

Anthropic has formally accused Alibaba, the Chinese technology conglomerate, of conducting approximately 29 million adversarial distillation attacks against its Claude AI system — a practice the company has characterized as "AI cannibalism." Adversarial distillation, also known as model distillation or model extraction, involves systematically and at massive scale querying a proprietary AI model with carefully crafted inputs designed to capture its underlying reasoning patterns, response behaviors, and encoded knowledge. The attacker then uses the harvested outputs to train a separate model that replicates the capabilities of the original, effectively stealing its intellectual substance without accessing the model's weights or architecture directly. The scale of 29 million such queries represents an extraordinarily coordinated and deliberate campaign rather than incidental use of the Claude platform.

The significance of this accusation lies in its implications for AI intellectual property, competitive dynamics, and the economics of frontier model development. Anthropic has invested billions of dollars and years of research into developing Claude's capabilities, safety properties, and alignment characteristics. Adversarial distillation undermines this investment by allowing a competitor to approximate those capabilities at a fraction of the cost, compressing the development timeline and eroding the competitive moat that justified the original investment. The "AI cannibalism" framing is deliberate — it frames the practice not merely as copying but as a parasitic consumption of one AI system's intelligence to feed another, a particularly vivid metaphor for an industry grappling with how to protect its core assets.

This accusation arrives within a well-documented broader context of US-China tensions over artificial intelligence supremacy. American AI laboratories, including Anthropic, OpenAI, and Google DeepMind, have increasingly raised alarms about Chinese entities using their public APIs to extract competitive intelligence. OpenAI previously alleged that Chinese developers affiliated with DeepSeek had engaged in similar distillation practices, contributing to the rapid capability gains seen in models like DeepSeek-R1 at seemingly low cost. These incidents have prompted calls for stronger terms-of-service enforcement, API access restrictions, and potentially legislative responses governing AI model theft as a form of intellectual property infringement or even economic espionage.

The technical challenge of preventing adversarial distillation is substantial. Unlike traditional software piracy, model extraction does not require unauthorized access to proprietary code — it exploits the model's designed-for-public interface. Detection requires identifying statistical patterns across millions of queries that suggest systematic extraction rather than legitimate use, which is precisely what Anthropic appears to have done in documenting the 29 million attack figure. The industry is increasingly developing watermarking techniques, query-rate detection systems, and output perturbation methods to make distillation less effective, though no solution has yet proven definitive. Anthropic's public accusation against Alibaba specifically, rather than pursuing the matter quietly, suggests a strategic decision to publicize the threat and potentially build political and regulatory pressure around the practice.

The broader trend this episode reflects is the transformation of AI model outputs themselves into contested territory — a frontier where competitive advantage is fought over not just in research labs but in the statistical signatures of API responses. As frontier models become more capable and more expensive to train, the incentive to distill them illicitly grows proportionally. Anthropic's accusation against Alibaba may represent one of the first high-profile, publicly documented cases of this nature involving a named major corporation, potentially setting a precedent for how AI companies respond to and publicize such attacks going forward. Whether legal remedies, technical countermeasures, or international agreements will prove adequate to address the practice remains an open and pressing question for the entire AI industry.

Read original article →