惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Jina AI
Jina AI
T
The Blog of Author Tim Ferriss
B
Blog
L
LangChain Blog
Y
Y Combinator Blog
美团技术团队
博客园 - 三生石上(FineUI控件)
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
G
Google Developers Blog
量子位
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
C
Check Point Blog
D
Docker
小众软件
小众软件
The Cloudflare Blog
大猫的无限游戏
大猫的无限游戏
T
Tailwind CSS Blog
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 聂微东
Blog — PlanetScale
Blog — PlanetScale
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
IT之家
IT之家

InfoWorld

AWS boosts CloudWatch Logs query limits by 10x to ease debugging for developers, SREs 21 LLMs tuned for special domains AWS adds Advanced Prompt Optimization tool to Bedrock Capacity markets could reshape cloud computing Four cutting-edge tools for spec-driven development Anthropic puts Claude agents on a meter across its subscriptions Notion courts developers with a platform for AI agents and workflow automation Using continuous purple teaming to protect fast-paced enterprise environments A better way to work with SQL Server Evidence-driven workflows: Rethinking enterprise process design AWS debuts Graviton-powered Redshift RG instances to cut analytics costs SAP’s AI promises last year? Most are still rolling out First look: Lemonade serves up local AI with limitations GitLab CEO sees developer tool bill increasing 100-fold Red Hat adds support for agentic AI development What’s new and exciting in JDK 26 Kill the loading spinner with local-first data and reactive SQL A networking revolution at AWS Tokenmaxxing is super dumb Hands-on with React, Supabase, and PowerSync How to add AI to an existing product (without annoying users) Your AI doesn’t need another database What happens when engineering teams reorganize around AI agents Python isn’t always easy When cloud giants meddle in markets 12 model-level deep cuts to slash AI training costs The best new features in Python 3.15 Teradata launches platform for enterprise AI agents moving beyond pilots Three skills that matter when AI handles the coding MongoDB targets AI’s retrieval problem
Anthropic accuses Alibaba of using 25,000 fake accounts t...
Prasanth Aby Thomas · 2026-06-25 · via InfoWorld

The alleged campaign generated 28.8 million queries in a large-scale model-extraction effort to replicate AI capabilities.

Anthropic has accused Alibaba of using nearly 25,000 fraudulent accounts to extract capabilities from its Claude AI models, in what the US AI company described as the largest known attack of its kind against it.

The campaign, carried out between April 22 and June 5, generated more than 28.8 million exchanges with Claude, according to a June 10 letter Anthropic sent to senior members of the US Senate Banking Committee, Reuters reported.

Anthropic said the effort involved “distillation,” a technique in which a less capable AI model is trained on the outputs of a more advanced system, potentially allowing rivals to replicate some of its capabilities at lower cost.

The company said the campaign was conducted by operators affiliated with Alibaba and Alibaba Qwen, Alibaba’s AI lab, according to the report.

The allegation comes as businesses adopt generative AI tools across business functions, putting pressure on vendors to show they can detect misuse while keeping services available for corporate customers.

The dispute also comes as AI development becomes more closely tied to US-China technology tensions. Anthropic said the alleged campaign could help accelerate China’s ability to reach the capabilities of its advanced Mythos Preview model, while US officials have stepped up scrutiny of advanced AI systems over fears they could be used by military or intelligence users in countries of concern.

In February, Anthropic said it had identified similar campaigns by DeepSeek, Moonshot AI, and MiniMax to extract capabilities from Claude, with the alleged activity ranging from more than 150,000 exchanges by DeepSeek to more than 13 million by MiniMax.

Alibaba did not immediately respond to a request for comment.

A new supply chain risk

If Anthropic’s claims are true, the alleged campaign could allow Alibaba to build a comparable model in a short period of time and offer it at a much lower cost, said Anand Joshi, an AI analyst at TechInsights.

Analysts said the alleged campaign also points to a broader pattern beyond the two companies. Viewed alongside previous incidents cited by Anthropic, they said, model extraction appears to be escalating rather than remaining an isolated risk.

“The enterprise supply chain no longer ends at software, APIs, and cloud regions,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. “It now includes rented intelligence, and rented intelligence can be copied and redeployed well outside the safety controls it was born with.”

Gogia said distillation should be a board-level concern because a weaker model trained on a stronger one can inherit its capabilities without the governance and controls around the original system.

For enterprises, the allegations point to a potentially more serious risk than conventional intellectual property theft: reverse engineering at scale. If proven, they would suggest that AI models can be copied systematically, turning model extraction into a new AI supply-chain risk.

“If a rival can clone the exact brain of the AI your company relies on, they can easily find its blind spots, hack your automated systems, or cause the AI vendor to panic and shut down services that your business needs to run every day,” said Pareekh Jain, CEO of Pareekh Consulting.

Mitigating the risks


The allegation raises questions about the controls AI vendors have in place and how customers can protect themselves.

“Vendors should provide verified accounts, smart rate limits, abuse detection, usage monitoring, contractual bans on distillation, incident disclosure, and audit rights,” Jain said. “Enterprises should ask how the vendor detects and blocks large-scale model extraction and can demand contracts that guarantee backup plans and financial refunds if the AI service gets attacked or suddenly shut down.”

Joshi said enterprise customers should also press vendors for greater transparency around model development and safeguards.

“Enterprise buyers should ask what training data was used, how it was trained, what guardrails exist, how they can audit it, and so on,” Joshi said. “Model publishers will have to come up with watermarking technology in models as well as model responses. So if the model ‘skills’ are stolen, they should be able to find the thief.”