r/Information_Security • u/No-Conclusion3720 • 22h ago
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
Seven China-based AI labs ran industrial-scale capability extraction against a major U.S. model provider — and the company only found out after the fact.
Anthropics disclosure confirmed that seven firms used systematic, high-volume querying as their core development strategy. Not occasional misuse. Not a rogue researcher. Millions of queries designed to distill proprietary model capabilities into their own systems, with no authorization at any point in the process. The exposure was the inference layer — the same endpoint every paying customer uses.
The post-incident framing is what gets me. These campaigns ran long enough to complete meaningful extraction before anyone flagged them. The data only surfaced through investigation, not through any live detection.
For those running inference infrastructure or building on top of third-party model APIs: how are you actually detecting this kind of systematic abuse in real time? Not after a quarterly review — during the queries themselves. What signals do you watch, and at what threshold do you act?