Live data from Hacker News

Anthropic says Alibaba illicitly extracted Claude AI model capabilities

reuters.com

811–820 of 1001 posts

Re: Anthropic says Alibaba illicitly extracted Claude AI model capabilities

#812

“Distillation attack” are we joking here. If anything these models should be compelled to be public since they have been trained off public data. What an absurd overreach to call this an attack. It’s clear they are scapegoating national security and China at this point to build an anti-competitive moat. I generally really like Anthropic’s work and models but stuff like this scares me for the future. We are positionin…

Since they hide their thinking traces it really doesn't make too much sense. We know one of their fixed degradations they talked about in a recent blog post was if you left claude code idle for too long they would rehydrate it without the thinking traces in the context and it degraded performance. So direct forms of distillation wouldn't be expected to get as good of results as they are getting.

However, they could have used it as a judge etc. during training.

Re: Anthropic says Alibaba illicitly extracted Claude AI model capabilities

#813
post #807

“Distillation attack” are we joking here. If anything these models should be compelled to be public since they have been trained off public data. What an absurd overreach to call this an attack. It’s clear they are scapegoating national security and China at this point to build an anti-competitive moat. I generally really like Anthropic’s work and models but stuff like this scares me for the future. We are positionin…

The core of the training data is public, but the part that actually makes these models smart came from (pretty highly-paid) experts via platforms like Mercor. Claude didn't magically learn to write good code by reading all of GitHub - humans trained it in that, more or less manually.

...and the rest of the training data (ie. the entire corpus of copyrighted works) was not written by experts expecting compensation? Double standards.

Re: Anthropic says Alibaba illicitly extracted Claude AI model capabilities

#814
I guess "paid to use our model" doesn't sound as sanction-worthy as "illicitly extracted .. model capabilities" and "attacked".

I guess we can say that Anthropic attacked and illicitly extracted data from WikiPedia, Reddit, Stack Overflow, etc, etc.

X.ai attacked and illicitly extracted data from OpenAI

https://techcrunch.com/2026/04/30/elon-musk-testifies-that-x...

Meta attacked and illicitly extracted data from LibGen

https://x.com/jason_kint/status/1879152507865485497/photo/1

And more generally the US-based AI companies have perpetrated a massive distillation attack on the entire human race.

Not that it makes any difference, but I wonder if Anthropic, while claiming that Alibaba "extracted Claude model capabilities", in fact have any clue what Alibaba did with their paid Claude responses. It would seem to amount to industrial espionage if Anthropic do know, although I expect they don't.

Re: Anthropic says Alibaba illicitly extracted Claude AI model capabilities

#815
post #813
post #807

Earlier quoted context omitted.

The core of the training data is public, but the part that actually makes these models smart came from (pretty highly-paid) experts via platforms like Mercor. Claude didn't magically learn to write good code by reading all of GitHub - humans trained it in that, more or less manually.

...and the rest of the training data (ie. the entire corpus of copyrighted works) was not written by experts expecting compensation? Double standards.

I didn't say that.

Re: Anthropic says Alibaba illicitly extracted Claude AI model capabilities

#817

“Distillation attack” are we joking here. If anything these models should be compelled to be public since they have been trained off public data. What an absurd overreach to call this an attack. It’s clear they are scapegoating national security and China at this point to build an anti-competitive moat. I generally really like Anthropic’s work and models but stuff like this scares me for the future. We are positionin…

> If anything these models should be compelled to be public since they have been trained off public data

I'm starting to come around to this idea TBH. For a while my position was: "these companies have invested billions into training these models, therefore they should be able to control them and profit off them" but looking deeper at where they got their training data, my view is starting to shift.

IMHO I feel like we need new laws around AI, specifically training data. Something like: "you can train an AI model and ignore copyright laws, BUT you must then make the model open weight", a company can still develop closed weight models but then they must aquire permission to use training data.

But it gets murky because if something like that was on the books then AI labs would just train open weight models and then distill them into their closed weight models.

Re: Anthropic says Alibaba illicitly extracted Claude AI model capabilities

#818

There's two basic kinds of distillation: 1) the massive [and dumb] method where you ask a question and use the answer as reinforcement (Black Box), and 2) more targeted distillation where you use one model to directly inform/train/guide another model (RLAIF). The latter is basically fine-tuning the model with direction from another model. Thousands of businesses do this every day to fine-tune. This is almost certainl…

> These complaints of distillation are inflating the problem to make it sound worse than it is Unfortunately, the Reuters piece itself is complicit in this dramatization. The lede paragraph parrots Anthropic's talking point that distillation is an "attack", without using quotes that would alert the reader that this framing is a corporate talking point. Distillation is NOT an attack.

Distillation done via bulk automated activity of fraudulent accounts, in violation of a terms-of-service, can reasonably be called a "an attack" – specifically a "distillation attack" – even though distillation itself isn't necessarily an "attack".

This is similar to how compromising an account through bulk automated trials of many passwords is reasonably called "an attack" – specifically a "dictionary attack" – even though using a dictionary is not itself an "attack".

You shouldn't need to smuggle your sympathies (for the tactic or perpetrators) or antipathies (for the target) into peculiar judgy language prescriptivism against common, understood usages.… that then label Reuters "complicit" for simply reporting Anthropic's claims accurately. That's what Reuters is supposed to do, in a story about a letter Anthropic wrote!

Re: Anthropic says Alibaba illicitly extracted Claude AI model capabilities

#819

“Distillation attack” are we joking here. If anything these models should be compelled to be public since they have been trained off public data. What an absurd overreach to call this an attack. It’s clear they are scapegoating national security and China at this point to build an anti-competitive moat. I generally really like Anthropic’s work and models but stuff like this scares me for the future. We are positionin…

> If anything these models should be compelled to be public since they have been trained off public data. What an absurd overreach to call this an attack.

> It’s clear they are scapegoating national security and China at this point to build an anti-competitive moat.

If all that is required to train these models is public data, why can't Alibaba just use that?

The fact that Alibaba has to resort to scraping Claude suggests there already is a moat...

Re: Anthropic says Alibaba illicitly extracted Claude AI model capabilities

#820

Reminds me a bit of the anecdote of Steve Jobs complaining about people ripping off the Mac GUI, in the mid to late 1980s, when he gave no public acknowledgement to the work done by Xerox on the Alto and Star operating system. "you're trying to rip off what I've already ripped off!" Crawl the whole Internet to build a gargantuan sized LLM and then complain you're being copied...

I’d agree with you if it doesn’t cost billions to train models.
Post reply on HN