AI商业化

Anthropic指控中国AI实验室
1.51亿次交换背后的技术暗战

Anthropic Accuses Chinese AI Labs
Tech Shadow War Behind 151M Exchanges

9月10日,Anthropic发布威胁情报报告,指控阿里巴巴、DeepSeek、Moonshot AI等中国AI实验室对Claude进行大规模蒸馏攻击,累计约2亿次恶意交换。其中阿里巴巴单家就贡献了1.51亿次。

On September 10, Anthropic released a threat intelligence report accusing Chinese AI labs including Alibaba, DeepSeek, and Moonshot AI of large-scale distillation attacks on Claude, totaling approximately 200 million malicious exchanges. Alibaba alone accounted for 151 million.

No.051 2026.09.11 约 5 分钟阅读 ~5 min read

AI行业的"吸血"事件正在升级。

9月10日,Anthropic发布2026年9月威胁情报报告,指控多个中国AI实验室对Claude进行大规模"蒸馏攻击"。报告显示,累计约2亿次恶意交换被追踪到5个独立的攻击活动,其中阿里巴巴被指控的活动规模最大——在2026年5月至7月期间,通过3500个账号产生了1.51亿次交换,峰值接近每天300万次。

蒸馏攻击:偷学模型的"思维链"

什么是蒸馏攻击?简单来说,就是通过大量查询目标模型,诱导其暴露内部推理过程(思维链),然后用这些数据训练自己的模型。

Anthropic在报告中指出,攻击者发展出了越来越复杂的方法来绕过防御。例如,有的攻击者伪装成翻译请求,要求Claude将"工作记忆"翻译成日文,从而诱导模型暴露思维链。

这次报告的指控范围远超2月的首次披露。除了阿里巴巴,Moonshot AI被指控产生了2300万次交换,DeepSeek被指控在14天内产生了1200万次交换。此外,小米和其他几家中国实验室也被点名。

阿里巴巴的1.51亿次:最大规模蒸馏

阿里巴巴被指控的活动是Anthropic观察到的最大规模蒸馏攻击。

1.51亿次交换,分布在3500个账号上,使用单一固定提示词——Anthropic认为这是针对Qwen系列模型的协调训练行动。这意味着平均每分钟有超过1400次请求,持续了近3个月。

Moonshot AI的情况更敏感。报告指出,部分请求似乎直接来自中国军方——其中一个请求要求Claude分析监控录像,判断被拍摄对象是否"行为异常"。

技术暗战:AI竞争的新维度

这次事件折射出AI竞争的新维度:不只是模型能力的竞争,更是数据获取方式的竞争

对于中国AI实验室来说,直接蒸馏Claude的成本远低于从头训练。Claude在代码、推理、Agent能力上的优势,是通过海量数据和计算资源堆出来的。如果能"免费"获取这些能力,何乐而不为?

但这种做法的风险也很明显:一旦被发现,不仅面临法律风险,更会损害企业的国际信誉。

"蒸馏攻击的本质是'知识盗窃'——你花10亿美元训练的能力,别人花100万美元就拿走了。"—— 一位AI安全研究员的评论

对行业的影响

这次事件可能加速AI模型的防御技术发展。Anthropic已经开始部署更先进的反蒸馏措施,包括检测异常查询模式、限制单账号请求频率等。

同时,这也可能推动AI模型的"开放"与"封闭"之争更加激烈。如果蒸馏攻击持续存在,模型厂商可能会更加保守地开放API,甚至限制某些地区的访问。

对于整个AI行业来说,这是一个警示:当AI能力成为核心竞争力时,保护这些能力的安全措施必须同步升级

明天见。

The AI industry's "vampire" problem is escalating.

On September 10, Anthropic released its September 2026 Threat Intelligence Report, accusing multiple Chinese AI labs of large-scale "distillation attacks" on Claude. The report shows that approximately 200 million malicious exchanges were traced to five separate campaigns, with Alibaba's alleged campaign being the largest — generating 151 million exchanges across 3,500 accounts between May and July 2026, peaking at nearly 3 million per day.

Distillation Attacks: Stealing Model's "Chain of Thought"

What is a distillation attack? Simply put, it involves querying a target model at scale to extract its internal reasoning process (chain of thought), then using that data to train your own model.

Anthropic notes in the report that attackers developed increasingly sophisticated methods to circumvent defenses. For example, some attackers disguised requests as translation tasks, asking Claude to translate "working memory" into Japanese to coax the model into revealing its thinking traces.

This report's scope far exceeds the first disclosure in February. Beyond Alibaba, Moonshot AI allegedly generated 23 million exchanges, and DeepSeek allegedly produced 12 million exchanges within 14 days. Xiaomi and several other Chinese labs were also named.

Alibaba's 151 Million: The Largest Distillation

Alibaba's alleged campaign is the largest distillation attack Anthropic has ever observed.

151 million exchanges, distributed across 3,500 accounts, using a single fixed prompt — Anthropic believes this was a coordinated training operation targeting the Qwen model family. This means an average of over 1,400 requests per minute, sustained for nearly three months.

Moonshot AI's situation is more sensitive. The report suggests some requests appeared to originate directly from Chinese military sources — one request asked Claude to analyze surveillance footage and determine if the subject was "behaving abnormally."

Tech Shadow War: A New Dimension of AI Competition

This incident reveals a new dimension of AI competition: it's not just about model capability, but about data acquisition methods.

For Chinese AI labs, distilling Claude directly costs far less than training from scratch. Claude's advantages in code, reasoning, and agentic capabilities were built with massive data and compute. If you can acquire these capabilities "for free," why not?

But the risks are obvious: once discovered, companies face not only legal consequences but also damage to their international reputation.

"Distillation attacks are essentially 'knowledge theft' — capabilities you spent $1 billion training can be taken for $1 million."— An AI security researcher's comment

Industry Impact

This incident may accelerate the development of AI model defense technologies. Anthropic has already begun deploying more advanced anti-distillation measures, including detecting abnormal query patterns and limiting per-account request frequency.

It may also intensify the "open vs. closed" AI model debate. If distillation attacks persist, model providers may become more conservative with API access, potentially restricting access from certain regions.

For the entire AI industry, this is a warning: when AI capabilities become core competitive advantages, security measures protecting those capabilities must evolve in parallel.

See you tomorrow.

蒸馏攻击的本质是'知识盗窃'——你花10亿美元训练的能力,别人花100万美元就拿走了。

—— 一位AI安全研究员

Distillation attacks are essentially 'knowledge theft' — capabilities you spent $1 billion training can be taken for $1 million.

— An AI security researcher
Anthropic · 蒸馏攻击 · 阿里巴巴 · DeepSeek · Moonshot · 2亿次交换 · Claude · AI安全
Anthropic · distillation · Alibaba · DeepSeek · Moonshot · 200M exchanges · Claude · AI security
Sources · 信源 Sources

本文基于 Dawn Vision 认知引擎处理的 12 个源信号生成,经编辑部人工审核。素材来源:Anthropic威胁情报报告、TechCrunch、TechInAsia。

This article was generated by the Dawn Vision cognitive engine processing 12 source signals, with human editorial review. Sources: Anthropic Threat Intelligence Report, TechCrunch, TechInAsia.