Anthropic says Alibaba must be punished for largest Claude cloning attack

Anthropic says Alibaba must be punished for largest Claude cloning attack

Anthropic 称阿里巴巴必须因史上最大规模的 Claude 克隆攻击受到惩罚

Anthropic has accused the Chinese firm Alibaba of launching the largest attack yet attempting to clone Claude, as China races to match the capabilities of Anthropic’s leading model following Mythos’ release and subsequent restriction from foreign markets. Anthropic 指控中国公司阿里巴巴发起了迄今为止规模最大的 Claude 克隆攻击。随着 Mythos 的发布及其随后对外国市场的限制,中国正竞相追赶 Anthropic 领先模型的能力。

Ars obtained a June 10 letter sent to Senators Tim Scott (R-SC) and Elizabeth Warren (D-Mass.) one day ahead of a Senate committee hearing on “AI and the American Dream.” In the letter, Anthropic shared “new, confidential evidence of the largest campaign to illicitly extract Claude’s capabilities we have ever measured.” Ars 获得了一封 6 月 10 日寄给参议员蒂姆·斯科特(共和党,南卡罗来纳州)和伊丽莎白·沃伦(民主党,马萨诸塞州)的信件,这封信是在参议院委员会举行关于“人工智能与美国梦”听证会的前一天发出的。在信中,Anthropic 分享了“我们所测量过的、旨在非法提取 Claude 能力的最大规模行动的最新机密证据”。

The attacks occurred between April 22 and June 5, when “operators affiliated with Alibaba and Alibaba Qwen, Alibaba’s AI lab” allegedly generated “more than 28.8 million exchanges with Claude through almost 25,000 fraudulent accounts,” Anthropic said. Violating Claude’s terms of service and access restrictions, this campaign “targeted some of Claude’s most valuable capabilities, such as agentic reasoning, software engineering, and long-horizon tasks.” Anthropic 表示,这些攻击发生在 4 月 22 日至 6 月 5 日期间,当时“隶属于阿里巴巴及其 AI 实验室 Alibaba Qwen 的操作员”据称“通过近 25,000 个欺诈账户与 Claude 进行了超过 2,880 万次交互”。该行动违反了 Claude 的服务条款和访问限制,其“目标是 Claude 最有价值的一些能力,例如代理推理、软件工程和长周期任务”。

According to Anthropic, Alibaba evaded detection by “using obfuscation techniques and proxy networks.” As Chinese demand for reliable obfuscation techniques increases, Anthropic warned there’s already “a growing circumvention economy” to fuel an ever-expanding web of future distillation attacks. 据 Anthropic 称,阿里巴巴通过“使用混淆技术和代理网络”逃避了检测。随着中国对可靠混淆技术的需求增加,Anthropic 警告称,目前已经存在一个“不断增长的规避经济”,为未来不断扩大的蒸馏攻击网络提供动力。

Alibaba allegedly ignored Trump warning

阿里巴巴被指无视特朗普的警告

Like other Chinese labs attempting to copy US frontier models, Alibaba’s aim, Anthropic alleged, was to extract Claude’s capabilities “without incurring the training and R&D costs required to train” their own frontier model. These attacks have become “widespread” and “turn hundreds of billions of dollars in American investment and R&D into a massive subsidy for our geopolitical competitors,” Anthropic said. Anthropic 指控称,与其他试图复制美国前沿模型的中国实验室一样,阿里巴巴的目的是在“无需承担训练自身前沿模型所需的训练和研发成本”的情况下提取 Claude 的能力。Anthropic 表示,这些攻击已经变得“普遍”,并将“数千亿美元的美国投资和研发成果变成了我们地缘政治竞争对手的巨额补贴”。

Importantly, Anthropic said, the Alibaba campaign occurred after Donald Trump took steps to curb such illicit distillation attacks and defend US national security. In April, Trump accused China of “industrial-scale” AI theft after Anthropic accused Chinese firms DeepSeek, Moonshot, and MiniMax of using the same tactic as Alibaba allegedly used to generate “over 16 million exchanges with Claude through approximately 24,000 fraudulent accounts.” Anthropic 强调,阿里巴巴的这一行动发生在唐纳德·特朗普采取措施遏制此类非法蒸馏攻击并捍卫美国国家安全之后。今年 4 月,在 Anthropic 指控中国公司 DeepSeek、Moonshot 和 MiniMax 使用与阿里巴巴据称相同的策略,通过“约 24,000 个欺诈账户与 Claude 进行了超过 1,600 万次交互”后,特朗普指责中国进行“工业规模”的人工智能窃取。

OpenAI and Google have published findings on similar attacks on their models, Anthropic said. Anthropic accused Alibaba of “brazenly” racing to make a copycat Claude, seemingly unfazed by Trump’s threats to crack down on foreign efforts to copy US frontier models despite depending on US investors. Anthropic 表示,OpenAI 和 Google 也发布了关于其模型遭受类似攻击的调查结果。Anthropic 指责阿里巴巴“厚颜无耻”地竞相制造 Claude 的山寨版,尽管依赖美国投资者,但似乎并未被特朗普打击外国复制美国前沿模型努力的威胁所吓倒。

“Alibaba is listed on the New York Stock Exchange, maintains business operations in the United States, and is accountable to US investors and regulators,” Anthropic’s letter noted, “yet this activity unfolded in the weeks after” Trump’s memo warned that cloning attempts were “unacceptable.” Ars could not immediately reach Alibaba for comment. Anthropic 的信中指出:“阿里巴巴在纽约证券交易所上市,在美国维持业务运营,并对美国投资者和监管机构负责,然而这一活动却发生在特朗普备忘录警告克隆尝试是‘不可接受的’之后的几周内。”Ars 未能立即联系到阿里巴巴置评。

Anthropic wants firms like Alibaba punished

Anthropic 希望像阿里巴巴这样的公司受到惩罚

Alibaba is already preparing to clash with Trump, though. In a lawsuit filed Tuesday, Alibaba accused the Trump administration of blacklisting the company after falsely linking the company to the Chinese military, Reuters reported. Alibaba is seeking to remove the Trump designation, which they claimed has “no basis in fact or law.” 不过,阿里巴巴已经在准备与特朗普对抗。据路透社报道,在周二提起的一项诉讼中,阿里巴巴指责特朗普政府在将其与中国军方错误关联后,将该公司列入黑名单。阿里巴巴正寻求撤销特朗普的这一认定,并称其“在事实和法律上均无依据”。

“Alibaba is governed by an independent board, none of whom has any military affiliation,” Alibaba said. “Its products and services are built for retail, logistics, and enterprise information technology—not weapons, defense, or intelligence.” “阿里巴巴由一个独立的董事会管理,其中没有任何人与军方有任何关联,”阿里巴巴表示。“其产品和服务是为零售、物流和企业信息技术构建的,而非武器、国防或情报。”

Anthropic appears unconvinced, however, that Alibaba isn’t working with the Chinese government. In the letter, Anthropic warned that without stronger interventions, these distillation attacks will “help China reach Mythos Preview-level capabilities sooner.” 然而,Anthropic 似乎并不相信阿里巴巴没有与中国政府合作。在信中,Anthropic 警告称,如果没有更强有力的干预,这些蒸馏攻击将“帮助中国更快地达到 Mythos 预览版级别的能力”。

To keep the US ahead of China, Anthropic recommended that Congress pass legislation with three objectives. First, antitrust laws must be updated to allow AI firms to share information about evolving Chinese tactics to deter more threats. Second, the US needs more export controls on chips to hamstring Chinese access to advanced compute so that they simply can’t train on US model outputs. That could make conducting distillation attacks pointless, Anthropic suggested. Finally, Congress should pass laws penalizing Chinese labs’ “bad behavior” so that it’s “more difficult and costly” to rely on distillation attacks to advance Chinese models. 为了保持美国对中国的领先地位,Anthropic 建议国会通过包含三个目标的立法。首先,必须更新反垄断法,允许人工智能公司共享有关中国不断演变的策略的信息,以阻止更多威胁。其次,美国需要对芯片实施更多的出口管制,以限制中国获取先进计算能力,从而使他们无法利用美国模型的输出进行训练。Anthropic 建议,这可能会使进行蒸馏攻击变得毫无意义。最后,国会应通过法律惩罚中国实验室的“不良行为”,使依靠蒸馏攻击来推进中国模型变得“更加困难和昂贵”。

Penalties could include limiting Chinese firms from accessing US models or advanced US chips or from relying on data centers outside of China, Anthropic suggested. Anthropic declined to clarify whether Alibaba’s alleged attacks were significant enough to help meaningfully accelerate China’s AI capabilities or comment on any specific steps taken to thwart the attacks. Anthropic 建议,惩罚措施可能包括限制中国公司访问美国模型或先进的美国芯片,或限制其依赖中国境外的数据库。Anthropic 拒绝说明阿里巴巴所谓的攻击是否足以显著加速中国的 AI 能力,也未评论为挫败这些攻击所采取的具体步骤。

Instead, a spokesperson provided a statement to Ars, echoing sentiments expressed in the letter to senators. “We believe combating the threat of illicit distillation requires coordinated action between government and industry, and we will continue working with Congress and the Administration to maintain American AI leadership,” Anthropic said. 相反,一位发言人向 Ars 提供了一份声明,呼应了致参议员信中表达的观点。“我们认为,打击非法蒸馏的威胁需要政府和行业之间的协调行动,我们将继续与国会和政府合作,以保持美国在人工智能领域的领先地位,”Anthropic 表示。

China races to match Mythos’ capabilities

中国竞相追赶 Mythos 的能力

Anthropic’s letter positions the AI firm as intent on helping the US hold the line so that China cannot surpass US capabilities. If that happened, Anthropic warned that China could blindside a defenseless US—suddenly possessing “advanced cyber capabilities to deploy against the US government and American companies and exploit vulnerabilities faster than previously possible.” Anthropic 的信件将该公司定位为致力于帮助美国守住防线,以防止中国超越美国的能力。Anthropic 警告称,如果这种情况发生,中国可能会让毫无防备的美国措手不及——突然拥有“可针对美国政府和美国公司部署的先进网络能力,并以比以往任何时候都快的速度利用漏洞”。

It’s important to keep the US as far ahead as possible, Anthropic’s letter said, because “the larger the capability gap,” the “more time the US government will have to harden cyber defenses and adopt AI systems across national security domains” as China’s AI advances. Additionally, Anthropic warned that if the US ignores disti… Anthropic 的信中表示,保持美国尽可能领先至关重要,因为“能力差距越大”,“随着中国人工智能的进步,美国政府将有更多时间来加强网络防御并在国家安全领域采用人工智能系统”。此外,Anthropic 警告称,如果美国忽视蒸馏……