惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
C
Check Point Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
T
Threatpost
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Know Your Adversary
Know Your Adversary
C
Cyber Attacks, Cyber Crime and Cyber Security
T
Tor Project blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
Spread Privacy
Spread Privacy
Latest news
Latest news
Project Zero
Project Zero
T
Threat Research - Cisco Blogs
P
Palo Alto Networks Blog
雷峰网
雷峰网
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
N
News and Events Feed by Topic
P
Privacy International News Feed
Vercel News
Vercel News
T
The Exploit Database - CXSecurity.com
S
Secure Thoughts
Application and Cybersecurity Blog
Application and Cybersecurity Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
F
Full Disclosure
T
Tenable Blog
Last Week in AI
Last Week in AI
Y
Y Combinator Blog
SecWiki News
SecWiki News
C
CERT Recently Published Vulnerability Notes
Forbes - Security
Forbes - Security
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
S
Security Affairs
The GitHub Blog
The GitHub Blog
J
Java Code Geeks
Blog — PlanetScale
Blog — PlanetScale
N
Netflix TechBlog - Medium
O
OpenAI News
Google DeepMind News
Google DeepMind News
V
Vulnerabilities – Threatpost
Engineering at Meta
Engineering at Meta
Hacker News - Newest:
Hacker News - Newest: "LLM"
N
News and Events Feed by Topic
The Cloudflare Blog
Stack Overflow Blog
Stack Overflow Blog
Schneier on Security
Schneier on Security
W
WeLiveSecurity
Recorded Future
Recorded Future
C
CXSECURITY Database RSS Feed - CXSecurity.com
博客园 - 三生石上(FineUI控件)

Forbes - Business

Pickleball Slam 4 Preview — History Of The Event And Behind The Scenes Prep With The Players How To Get Masters 2027 Tickets Lottery Dates And Odds ‘Malcolm In The Middle: Life’s Still Unfair’ Is Likely A Wrap For Show Tony Gonzales, Eric Swalwell Will Resign Following Sexual Misconduct Allegations Suspect In Sam Altman Molotov Attack Charged With Attempted Murder Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Dan Orlovsky Compares Ty Simpson To Brock Purdy, Names Surprising NFC Contender As Fit For 2026 NFL Draft Prospect IndyCar’s Chip Ganassi Racing, OpenAI Hope For ‘Competitive Advantage’ Shingles Altered Achilles Rehab For Pacers Star Tyrese Haliburton, But He’s Back On The Court NYT Pips Today: Hints, Answers And Walkthrough For Tuesday, April 14 LVMH Founder Bernard Arnault’s Fortune Falls $50 Billion This Year Inter Miami CF Kicks Off New Era For South Florida Soccer In Nu Stadium IndyCar’s AJ Foyt Racing Hires Toby Sowery As Reserve Driver IndyCar’s Chip Ganassi Racing Goes Green With Green Sports Alliance Rory McIlroy Claims Second Straight Masters Title At Augusta Rockets Claim Fifth Seed In West Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 Design Details In ‘The Drama’ Delve Deep Into Character AEW Dynasty 2026 Results, Winners And Live Updates On April 12 Former Dodgers Infielder, 3-Time MLB All-Star And Champion, Dies After Cancer Battle Townsend And Wild Secure Double Golds At Pro Pickleball Association Australia Moreton Bay Los Angeles Dodgers Prospect James Tibbs III Is Tearing Up Triple-A Hungary’s Authoritarian Orban—Boosted By Trump—Loses. European Leaders Celebrate. Review: Blackbraid Delivers Exteme Metal Masterclass To Dublin, Ireland Colorado Is Emerging As An Energy Innovation Hub U.S. Military Ships In Strait of Hormuz Violate Ceasefire, Iran Warns (Live Updates) Rosé’s All-Time Sales Chart Record Has Been Beaten IC3 Report Reveals Surge In Cryptocurrency Investment Scams The Top Contenders For The 2026 NCAA Gymnastics All-Around Title What Time Does ‘Euphoria’ Season 3 Come Out? How To Watch Tonight John Nolan, ‘Batman’ Films And ‘Person Of Interest’ Actor, Dies At 87 BTS Dominates The Biggest Songs Chart In America — Again Jannik Sinner Ties Novak Djokovic’s Masters 1000 Mark—Will Return To World No. 1 Will Iran War Result In Nuclear Weapon Transfers To The Middle East? Iran Reportedly Used Chinese Satellite To Target U.S. Bases—Here’s How China And Russia Could Help Iran Why Diesel Prices Spike Faster Than Gasoline In A Crisis UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami Taemin Dazzles At Coachella Debut And Premieres 6 New Songs: Full Setlist UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 WNBA Draft 2026 Date, Time, Order And Top Prospects Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction Avengers’ Biggest Battle? Taking On ‘Dune: Part Three’ At Christmas U.S.-Iran Peace Talks Stretch Into Sunday—As Iran Denies U.S. Navy Destroyers Passed Through Hormuz Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Why Dewey Actor Was Recast For ‘Malcolm In The Middle’ Revival Series Eric Swalwell Is Being Investigated In New York After Sexual Assault Claim Against Him Artemis Reached The Moon. The Grid Can Reach The 21st Century Pope Leo XIV Says 'Enough Of War!' As He Urges ‘Mediation’ To End Iran Conflict NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) U.S.-Iran Peace Talks Stretch Into Sunday—As Iran Denies U.S. Navy Destroyers Passed Through Hormuz Beyond Private Credit—The Overlooked Risks Of Banks’ Ties To Nonbanks ‘Euphoria’ Musician Labrinth Suggests He Was Treated Poorly Before Leaving Hit Show Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams UFC Tonight: What Time Does The UFC 327 Fight Card Start? Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records Harry Styles Flies With His Oldest Hit Thanks To A Box Office Smash New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU Chris Stapleton’s High-Profile Collaboration Becomes A Certified Hit Miley Cyrus Charts The Biggest New Sales Smash In America Pet Shop Boys’ Visual History Told In New Book China Seizes An Island While The World Is Watching Iran Ozzy Osbourne’s Name Helps A Rock Band Chart A New Top 10 Hit Forbes House of the Week: 3 Things We Crave Make U.S. Air Cargo More Valuable Than Ocean Ocean Tight Ends To Trade Away In Dynasty Fantasy Football Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns What’s At Stake In Hungary’s Election For Ukraine And Russia Coachella 2026: All 95 Surprise Guests Who Appeared This Year Coachella Accidentally Plays New KATSEYE EP Announcement Before Debut Performance KATSEYE Performs ‘Golden’ At Coachella with HUNTR/X voices KATSEYE Feature ‘KPop Demon Hunters’ Singers For 'Golden' At Coachella WWE SmackDown Results, Winners And Grades On April 10, 2026 WWE SmackDown Results As Pat McAfee Announces 25% Off WrestleMania 42 Tickets Bini Makes History For Filipino Music At Coachella 2026: Full Setlist 5 Under-The-Radar Winners And Losers In The Iran War So Far Menswear In The Post-Covid Age Is High Tech And High Touch Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 ‘Hacks’ Season 5 Release Schedule Reveals Final Episodes For Series Packers Trade Inconsistent Dontayvion Wicks To The Eagles Dan Levy’s Netflix Crime Comedy ‘Big Mistakes’ Takes Huge, Hilarious Risks Inside 30 Years Of Progress At The Wendy Hilliard Gymnastics Foundation With A $1.2 Billion Sale To Unilever, Grüns’ Founder Mints A Fortune What Does ‘You The Birthday’ Mean? TikTok’s Viral Phrase, Explained Kenny Omega Talks Comeback And Facing MJF At AEW Dynasty FIFA World Cup 2026: Why Ticket Scandals Still Cloud the Tournament Two Months Out Oldest US Navy Supercarrier Sailing In ‘Southern Seas 2026’ Exercises Huang Urges People To ‘Move To California’ As Billionaire Tax Looms BTS ARIRANG World Tour: What To Expect For New Fans And Old ‘You, Me & Tuscany’ Rotten Tomatoes Reviews Like Where Rom-Com Lands IRS Issues New ‘No Tax On Tips’ Rules—Here’s Who Qualifies Trump Wants To Build An Arch In D.C.—Here’s What It Would Look Like Molotov Cocktail Thrown At Sam Altman’s Home, OpenAI Says—Suspect Arrested
Foreign Entities Such As China Are Siphoning American AI Models At Our Steep Loss And Their Huge Gain
Lance Eliot · 2026-05-01 · via Forbes - Business
Diverse Group of Professionals Meeting in Modern Office: Brainstorming IT Programmers Use Computer Together, Talk Strategy, Discuss Planning. Software Engineers Develop Inspirational App Program

Foreign entities are using AI distillation to illegally siphon from American-made advanced AI.

getty

In today’s column, I examine the underhanded and insidious efforts by foreign entities to siphon off American-made generative AI and large language models (LLMs), doing so to craft their own AI variations at a fraction of the cost and to exploit the hard-earned progress made in AI by the United States.

It is outrageous, illegal, and being undertaken surreptitiously. The United States is urgently taking notice on behalf of American AI makers and performing rapid action to detect, curtail, and seek to prevent these shameful and unlawful intrusions.

Let’s talk about it.

This analysis of AI breakthroughs is part of my ongoing Forbes column coverage on the latest in AI, including identifying and explaining various impactful AI complexities (see the link here).

The AI Technique Of Distillation

I will start by covering crucial foundational considerations.

Suppose an AI maker wants to use one of their existing full-sized AI models to enhance a smaller and less capable one of their AI models. This can be readily performed via a technique known as distillation. The typical use of distillation involves an AI maker deciding to create or enhance an SLM (small language model). They pour some of the contents of the LLM into the SLM, aiming to further fill in or pump up what the SLM can do (see my detailed explanation on how AI distillation works, at the link here).

You can think of AI distillation as a teacher-student type of arrangement. The LLM acts as the teacher. The SLM is the student. The larger-sized LLM shares aspects with the SLM to bolster the capabilities of the smaller AI. This is a relatively routine practice and is commonly undertaken. AI makers do this frequently, and so do AI practitioners and hobbyists. If done appropriately and legally, it is perfectly aboveboard.

The twist is that distillation can be utilized in a legal way but can also be performed illegally.

The illegal approach involves surreptitious distilling from someone else’s LLM and essentially stealing their intellectual property (IP). Why would this be done? Because you can take a relatively slim or hollow SLM and pump it up to become much more full-bodied at a super low price. The SLM emerges as a robust LLM overnight. Rather than having to pay and get suitable approval, the underhanded path rips off the hard work and vast invested efforts of whoever made and owns the teaching LLM.

Being Sneaky And Stay Below The Radar

You might be thinking that detecting when an illegal distillation is taking place ought to be easy-peasy. All you seemingly need to do is monitor when the teaching LLM is actively giving up tons of its content. It would be akin to a water pipe that someone turned on widely or slyly tapped into, and the water is gushing out. If the contents of the teaching LLM are gushing out, voila, you’ve got an unauthorized distillation happening.

The thieves are wise to such adversarial detection. They know that if they simply pumped out content at a high rate of distillation, doing so would be caught and summarily cut off. It is a much too obvious form of a cyberhack. Though an individual who isn’t in the know might try this blatant means, a large entity or actor would be too astute to fall into that crude method.

A sophisticated cyberhacking would employ proxy swarms. You might liken this to using thousands upon thousands of small drones. Drones are relatively small, cheap, and yet are extraordinarily powerful when used in a massive way. We’ve all seen how lots of drones working in unison can readily threaten a large warship at sea or an expensive large-sized warplane.

Spinning Up Thousands Or Millions Of Accounts

In the case of AI distillation thievery, here’s how a foreign entity might proceed. Keep in mind that a foreign entity could be a country or some entity that has sizable resources to devote toward cyberhacking.

The entity creates thousands or perhaps millions of fake accounts in the generative AI model that is being targeted. This isn’t being done singularly by human hand. Instead, an automated script running on a computer server will create these accounts (they become AI bot-controlled accounts). Furthermore, servers across the globe are tapped into so that the accounts appear to be geographically dispersed. It isn’t obvious where the accounts originate from.

If you are wondering why an AI maker wouldn’t instantly get suspicious about perhaps millions of new accounts, the gist is that many of the major LLMs already have hundreds of millions of accounts, and new accounts by actual people are being created at an amazing pace. OpenAI has stated that ChatGPT and GPT-5 have somewhere around 900 million weekly active users. The stats suggest that with ChatGPT, GPT-5, Google Gemini, Anthropic Claude, xAI Grok, Microsoft CoPilot, and additional mainstay LLMs, the number of worldwide AI users in total is perhaps 1.5 billion or more.

Thus, creating thousands or even millions of new accounts by a cyberhacker is not going to raise alarm bells, especially by dispersing the geographic origins of the accounts. It will look as though more people from around the world are opting to make use of modern-era generative AI. No-harm, no-foul.

Don’t Need To Break Glass

Does distillation break or crack the AI and, therefore, ought to be detectable?

Nope, it is the mere act of submitting prompts and obtaining responses. The idea is straightforward for doing the distilling. Suppose you wanted to find out what AI can tell you about Einstein’s most famous equation. You could merely ask a question and get a response. Then, based on the response, you ask another question. Keep doing this until it seems that you’ve extracted as much as feasible from the AI about e=mc squared.

Collect together all those prompts and responses. Keep them recorded as pairs. Those prompt-response pairs are then fed into the AI that you are trying to train in Einstein’s theory of relativity. By pumping in perhaps thousands or millions of such pairs, the other “student” AI patterns on the prompts and responses, ultimately becoming boosted on the topic of Einstein’s theory.

No need to do anything tricky or out of the ordinary. Just submit prompts, collect responses, and do so until it seems that enough has been distilled to move on to some other topic. Distillation has the appearance of an everyday user who is interacting with the AI on a normal basis. You would be hard-pressed to discern that it was a bot that was essentially stealing from the AI.

Is It Stealing If Only Dipping In

A frequent question comes up when I give talks about AI and distillation, namely that AI distillation doesn’t especially seem to be a crime per se. Normal users are allowed to enter prompts and get responses from LLMs. The cyberhacker is doing the same.

What’s the beef?

If you were to inspect the online licensing agreements of the AI makers, you’ll see a clause that says you cannot use the prompt-response pairs for distillation. The AI makers don’t want you to use their AI for distillation, and adamantly stipulate that you aren’t to do so. It is a flat no. You are welcome to use the prompt-response pairs for all sorts of other purposes, but not for distillation.

Another angle about whether this is legal or illegal has to do with the fact that when you get the AI to give you responses, you aren’t actually removing anything from the AI. The AI is merely sharing with you a response. It displays contents. The actual contents of the AI are still intact. In that sense, it perhaps seems odd to claim that you are “stealing” from the AI.

We customarily think of stealing as removing an item. When someone steals a camera that’s in the front seat of your car, they take the camera away from the car, and they rob you of the possession of the camera. The AI giving you a response to a prompt is not going to somehow remove content from the AI.

The more appropriate way to think of this is when someone makes a bootleg copy of a movie, the original movie is still intact, but the bootlegger has nonetheless committed a crime and stolen something of value. The same applies to LLMs (well, just to let you know, there’s all manner of arcane debates on that -- I’ve covered those IP issues elsewhere, see the link here).

Jailbreaking Often Included

I’ve mentioned earlier that to do the AI distillation, you can merely enter everyday prompts. That is indeed the case. But sometimes there are special inner elements of AI that are guarded by the AI maker. For example, there are usually AI safeguards that won’t let you ask for details on how to make toxic poisons or explosive devices.

A foreign entity might want to get those facets from the AI.

To do so, they will employ various AI cracking schemes, often referred to as jailbreaking. The use of jailbreaking can potentially enable the foreign entity to extract secrets that are highly sensitive or supposed to be kept away from all users of the AI. For my discussion of how jailbreaking is undertaken, see the link here.

AI Distillation By Foreign Entities

Now that you are sufficiently up-to-speed about AI distillation, let’s shift our focus to how American makers of AI are being ripped off by foreign entities via the use of AI distillation techniques.

A publicly posted policy memorandum on April 23, 2026, by Michael J. Kratsios, Assistant to the President for Science and Technology Director in the White House Office of Science and Technology Policy, entitled “Adversarial Distillation of American AI Models,” made these salient points (excerpts):

  • “The United States leads the world in artificial intelligence (AI) technologies. That lead reflects decades of foundational research, bold entrepreneurial risk-taking, and hundreds of billions of dollars in annual private investment.”
  • “However, the United States government has information indicating that foreign entities, principally based in China, are engaged in deliberate, industrial-scale campaigns to distill U.S. frontier systems.”
  • “Leveraging tens of thousands of proxy accounts to evade detection and using jailbreaking techniques to expose proprietary information, these coordinated campaigns systematically extract capabilities from American AI models, exploiting American expertise and innovation.”
  • “Industrial distillation activities that aim to systematically undermine American research and development and access proprietary information are unacceptable.”

I liken these foreign entity activities to the types of subterfuge that took place during the Cold War era. I’m sure you know that spies would try to obtain American secrets, such as how to make certain kinds of missiles or weapons. Espionage tactics often leaned into the use of dispersed human actors, including individual researchers, governmental officials, industry practitioners, and others, to make copies of secret plans, proprietary documents, and so on.

The Big Picture Comes To Mind

Nowadays, those same spying tradecraft precepts are being retooled as AI bots that converge in proxy swarms on a targeted LLM in an AI distillation attack. This allows scaling far beyond what human hands alone could accomplish. Deploying thousands of semi-autonomous accounts to perform coordinated queries is relatively cheap and easy to undertake. It is much less expensive than building the same content from scratch, can be done in a fraction of the time in comparison to the right way to do things, and is quite difficult to detect.

Not the perfect crime, but it ranks up there in the AI underhanded cyberhacking world.

American companies working individually won’t necessarily have the wherewithal to tackle the spying tactics of AI distillation that occur on an industrial scale. Sure, they are doing what they can to devise AI safeguards around this, but the foreign entities are going after a wide swath of LLMs and can keep maneuvering as they do so.

A mix of defensive tactics and strategies is being constantly crafted and advanced.

Technical defenses include:

  • Behavioral monitoring across accounts (detect coordinated querying patterns).
  • Use of data watermarking or data fingerprinting to trace model lineage.
  • Adopt differential privacy or output perturbation (though this can degrade usefulness).
  • Enforce query throttling tied to aggregate signals, not just per-account limits.
  • Devise stronger jailbreak resistance via adversarial training.

Operational controls that can be implemented include:

  • Establish account verification tiers to limit high-volume access.
  • Enact API usage auditing and anomaly escalation.
  • Proceed with red-teaming focused on extraction scenarios.

Policy responses include:

  • Consider the adoption of various AI distillation-related export controls on model weights and high-end computing.
  • Craft legal frameworks treating large-scale AI extraction as IP theft and economic espionage.
  • Seek to establish agreed and enforceable international norms around AI model distillation practices.

Steps Outlined In The Memorandum

The recently released White House memorandum offers several steps that are being undertaken, including sharing information across American AI companies about AI distillation subterfuge taking place, and having the federal government work closely with AI makers to develop best practices for identifying, mitigating, and remediating these industrial-scale efforts by foreign entities.

It is a never-ending cat-and-mouse game.

There is a famous line known amongst AI insiders that there are two types of AI companies: those that have had their AI breached and those that don’t know it yet. Boom, drop the mic. Seriously, there are undoubtedly foreign entities at this very moment performing AI distillation on American-made LLMs. It is real. It is happening. And more is coming down the pike.

We must be vigilant, take proactive AI cybersecurity precautions, and protect the revered goose that lays the golden eggs.