Are you joking...? Sorry if so! Just in case: It's illegal in both the PRC and the USA.
In the PRC, they[1] leaked tons of national secrets on the PRC's latest AI campaigns, the inner workings of their "opinion monitoring" (read: performative panopticon) and "stability" (read: violent oppression) departments, Chengdu's whole CCTV network, direct-energy weapons plans, espionage activities in Syria to hunt down Uyghur refugees, and god knows what else that Anthropic didn't divulge to us common folk.
In the US, it's very clearly an attempt to rip off a competitor. I'm not sure how else you could possibly see it. Even if you're a distillation fan in general (which A. why and B. plz don't), they did this through a network of Japanese and Signaporean shell accounts, presumably at least some of which were abusing Anthropic's subscription service in a ToS double-whammy, as it would be exorbitantly expensive otherwise. They also had to hack around Anthropic's API to get CoT traces, which seems impossible to explain away as anything innocent.
I've been beating the "China isn't necessarily an enemy, it's gonna take us all to handle AI" drum for literally years, but this attack was just... gross. Gross in scale and gross in arrogance. Not a good sign for the dawning alignment crisis, to say the least :(
TL;DR: Use these services if you want, but know that you're supporting aggressive escalations and companies that very clearly don't give a flying fuck about violating the law, much less your ToS. So... buyer beware, I guess.
[1]: For clarity, Z.ai was not alone in this, nor were they most egregious attack -- Moonshot.ai (kimi) took that coveted prize. DeepSeek was involved, too.
What does any of this have to do with the legality of distilling Claude?
> use these services if you want, but know that you're supporting aggressive escalations and companies that very clearly don't give a flying fuck about violating the law, much less your ToS
From my European point of view the same risk/concerns apply when using US providers
It comforts Americans to believe their exceptionalism is both persistent/eternal and fully justified.
Replying to a massive, blatant cyberattack with "lol America would prolly do the same" is not helpful nor rational. I am under no illusions about the exceptionalism of my state, especially considering the ongoing fascist self-coup. That's not the end of this discussion, not by a long shot.
> alignment crisis
Alignment is meaningless; as you've noticed, humans aren't all that "morally aligned".
If the tool needs safety measures it should be kept in a safe enclosure like we do with CNC machines, furnaces, and so on.
Replying to everyone to hack HackerNews' Gish Gallop feature (nulla poena sine lege!):
Moral relativism is an attractive proposition when you first examine the topic, but it quickly falls apart; there's a reason it's not even a coherent camp in contemporary philosophy beyond some vagueities from radical post-modernists. Just to go over some of the greatest hits:- Is what [DICTATOR/MURDERER/CRIMINAL] bad, or merely not to your taste? If the latter, then you have no coherent reason to argue they should be punished. We would never imprison people who don't like vanilla ice cream because 51% of the population does like it.
- If another culture had a deeply held belief to [HORRIBLE_THING] to, say, children, would you just shrug and say "different strokes for different folks"? What if [MURDERER] just had a different culture?
- No, the fact that nature is red in tooth and claw does not disprove morality; we are very, very, very far from our pre-rational, animalistic roots, and to go back now would be unthinkable.
Thousands of scientists have been studying this problem for 76 years now, going on 77; your hunch about physical machines does not overrule their findings about the capabilities and tendencies of minds wrought from sand. I think this is just blatantly false, likely based in a misunderstanding of criminal law vs. civil law. Civil courts still deal with legality.The broader discussion of why distillation is bad and dangerous and immoral is left as an exercise for the reader, as it was above with the parenthetical. It's not a complex argument; I guarantee you understand it if you're reading this.
The same thing as above -- the fact that laypeople can not think of a criminal charge that they've heard on Law & Order that corresponds to this behavior does not mean that it's legal. It's textbook fraud, regardless of what particular detail you focus on. I think the fact that it's happening at such a large scale is proof that very smart, well-resourced labs in China (the producers of the world's best OS models, including the incredible GLM-5.3-Flash) think it's feasible. I'm not sure it's productive to question them in the absense of any indication to the contrary.This is a great question still, not trying to shut you down. But I think the fundamental issue is a misunderstanding of what distillation is -- it's not directly stealing literal atomic parameters and piling them up. They might try to focus on substructures within these massive networks, but even that isn't strictly necessary for a distillation attack.
Sorry, I never linked it! This is from the latest Anthropic safety report (of "Anthropic Houtis build missile" fame), and no, these cannot be hallucinated -- the leaked secrets were inputs, not ouputs. https://www.anthropic.com/threat-intelligence-report-septemb... This is just blatant word games, sorry. I'm sure intended in good faith, and I understand the impulse -- I consider myself a radical anti-IP slacktivist, after all. But "both things involve information transfer" is just not a coherent point; lots of things fit that description. These are cyberattacks. Yes, anyone can cyberattack cyberattackers. But, y'know... an eye for an eye... I am not at all concerned with the value of the resulting artifacts as assessed by the (already totally unhinged) NYSE et. al. I am concerned about user respect, law following, truth telling, blatant cyber warfare at a time of rising tensions, accidental data leakages at a scale that'd be hard to fathom 5 years ago, bad-faith public postures, and a general distaste for fraud.Moral relativism is about handling the disparity of moral frameworks in the world, which you acknowledge exists at several points. The inverse of moral relativism is moral absolutism, which is that there exists precisely one set of moral facts. The space between these two is a spectrum, by the way, and usually we choose our position on the spectrum depending on what our purposes are. If we're talking about a disparate cultural collective, moral relativism is structurally necessary. Relativism just means we have a contextual differentiator, just generally in philosophy, not just in moral studies.
The struggle you have with pinning down moral relativism I think betrays the fact that your understanding of it is low quality. A good ear mark is, can you name a single passage from a treatise on moral relativism that you like? If you can't find a single aspect of a philosophical construction to advocate for, that means you don't actually understand it.
You also keep sliding between conflating moral relativism with moral anti-realism and even moral nihilism at one point. These are different axes.
> Realism + Absolutism
All moral facts converge for every single person. As a matter of fact, they aren't facts at all. Morals are a hinge of the Wittgenstein variety.
> Realism + Relativism
Moral facts are derived from frameworks, or contexts, which are themselves grounded facets of reality.
> Anti-Realism + Absolutism
Kantian Constructivism. There are no facts which are coherent without a framework, but moral claims are still necessarily only capable of being universal.
> Anti-Realism + Relativism
Moral reality is constructed by the framework, grounded only to the framework.
You didn't explain why it's illegal or why distillation is bad.
Nulla poena sine lege?
Interesting. Where can I see this leaked data about the inner workings of Chinese opinion monitoring?
Like Anthropic and OpenAI are? After all, didn't they distill all the information in the world into their model(s)?
I mean, if they get to distill other's IP, why can't others distill their IP?
Yes, wont somebody please think of the shareholders whose IP had been stolen...
Source for 1? Are we sure those aren't hallucinations?
I'm always wondering when "distillation" comes up how feasible it is, or if it's just BS.
The Antrophic article mentions "16 million" conversations, GLM models are in the 700-300 billion parameter ranges and while the frontier sizes aren't know but Gemini suggests Astra and Mythos are at around 10 trillion. That'd amount to extracting 40k parameters per conversation without a lot of errors if it was just a distillation (from an unknown source/algorithm as opposed to distilling your own model).
Now, I can imagine these conversations being used as a verification step that they're not missing stuff in their training, and that their models are capable of most of the same things, but that's mostly confirming that they've stolen the same data from the public as Antrophic/OpenAI has stolen already.
Or am I missing something here that makes real "distillation" feasible?
[dead]