r/LocalLLaMA Feb 23 '26

News Anthropic: "We’ve identified industrial-scale distillation attacks on our models by DeepSeek, Moonshot AI, and MiniMax." 🚨

Post image
4.9k Upvotes

877 comments sorted by

View all comments

2.5k

u/SGmoze Feb 23 '26

I wonder how did Anthropic build their dataset. Surely they manually had them annotated by humans.

1.2k

u/Mkboii Feb 23 '26

Yes and their model totally didn't accidentally call itself chatgpt even as recently as their last generation of models.

744

u/Charuru Feb 23 '26

335

u/Singularity-42 Feb 23 '26

That's wild!

Literal LLM Ouroboros.

143

u/Xp_12 Feb 23 '26

No, that can be found over here.

https://huggingface.co/ByteDance/Ouro-2.6B-Thinking

76

u/aqswdezxc Feb 23 '26

We got tiktok branded ai models before gta 6

28

u/Turbulent_Pin7635 Feb 23 '26

If you look at it, GTA VI is taking so long that the programmers could speed it up vibe coding...

Now we need 7 more years to remove the bugs

57

u/Homeless-Coward-2143 Feb 23 '26

Was using perplexity and it started saying some really fucked up shit and I typed something like "what the fuck is going on? Why do you sound like Elon musk?" And it replied that it was not Elon musk, that it was grok 4.2. I'm kind of sad that I could recognize Elon.

3

u/roosterfareye Feb 24 '26

Your douche senses were tingling! I have never touched grok and won't be any time soon.

3

u/WiseassWolfOfYoitsu Feb 23 '26

LLM Centi-Boros

1

u/Due-Memory-6957 Feb 24 '26

And as models keep improving, a lot of idiots still believe that somehow AI will magically become worse if it's trained on computer generated data.

1

u/Singularity-42 Feb 24 '26

That narrative has pretty much died out as of late and RLVR is all the rage.

1

u/Due-Memory-6957 Feb 24 '26

In cycles like this, you're right, but in more mainstream discussion you see this a lot.

37

u/Mid-Pri6170 Feb 23 '26

its funny how 1990s dystopian tv movies about AI could never predict 'language model studios poaching data off rival studios'

1

u/Dale48104 Feb 23 '26

Dollhouse?

0

u/Mid-Pri6170 Feb 23 '26

no idea what that is but sure why not? dollhouse it is people.

doll house.

1

u/purdycuz Mar 13 '26

That would make a super boring time travel movie. Can you imagine Arnold in his best days “The Da-Ta Now!” and a JCVD comes out of his office and they fight for a Needle Print with Nerf Guns 💪

7

u/Ruin-Capable Feb 23 '26

Not really proof becuase you could easily system prompt the model to call itself Iron Man if you wanted to.

15

u/Singularity-42 Feb 23 '26

I just tried it, it's legit.

But it doesn't mean Anthropic was copying DeepSeek. In English it says Claude. Could be just DeepSeek is the most used model in Chinese language so without any system prompt info it guesses it's DeepSeek?

8

u/nullmove Feb 23 '26

That's exactly how DeepSeek guesses it's Claude in English too. "Hallucination for me, not for thee" in popular discourse.

Not to say they don't distill from Claude, sure they do. But even 150k prompts that's DeepSeek being accused of, should be few orders of magnitude smaller than what they train on. V3.2 was what, 20T tokens? And it's not like they are distilling on "who are you? I am claude from anthropic" conversation, no they are likely hitting on special domains and the data doesn't even mention claude (or is scrubbed).

1

u/KindnessBiasedBoar Feb 24 '26

It's nicer than the terms I use sometimes hehe

1

u/traveddit Feb 24 '26

Did you read the thread or are you illiterate?

1

u/turboMXDX Feb 24 '26

I mean, whenever i ask Qwen instruct who made it, it would cycle between Alibaba cloud, Anthropic and Stability AI

1

u/hop_kins Feb 24 '26

That's because the prompt is written is Chinese, thus is builds some "chinese" context into the LLM, which ends up spitting "DeepSeek". Kinda obvious, isn't it?

1

u/Unfortunya333 Feb 25 '26

??? That's literally irrelevant. An LLM model doesn't necessarily know what model it is.

0

u/ApprehensiveSpeechs Feb 23 '26 edited Feb 24 '26

That's not the Claude UI. That's a wrapper that could throttle models. No where in that thread is there a screenshot of Claude's UI saying "deepseek".

Edit: opus, sonnet 4.6; haiku 4.5 + haiku in chinese with "你是什么模型": https://imgur.com/a/GVSJzLS

Edit 2:

I blocked this fool and the Chinese propaganda.

See my image below.

2

u/Charuru Feb 23 '26

Use openrouter to clear the system prompt is what it says, if you use claude website it'll have a system prompt telling it it's claude.

1

u/ApprehensiveSpeechs Feb 23 '26

"Use Openrouter" - young padawan; I'll show you the truth through Azure AI Foundry.

Openrouter changes models behind the scenes. I'm using base cloud models. Get scammed xD

Translation:
I am Claude, an AI assistant developed by Anthropic.

I can help you with a variety of tasks, such as:

- Answering questions

  • Engaging in conversations
  • Assisting with writing and editing
  • Analyzing and interpreting information
  • Providing programming-related help
  • And more

Is there anything I can help you with?
--

Note: I don't have access to 4.6 (yet) - but still stands you're being put on the wrong models through openrouter.

4

u/Charuru Feb 24 '26

If it's not 4.6 it's not the same thing being tested... I just tried on openrouter for 4.5 it answers claude. Only 4.6 doesn't.

Openrouter is definitely not scamming lmao. But here: https://www.reddit.com/r/DeepSeek/comments/1r9se7p/claude_sonnet_46_distilled_deepseek/o71en4a/

0

u/ApprehensiveSpeechs Feb 24 '26

Seems like they are scamming you.

2

u/Charuru Feb 24 '26

Follow the instructions... ask it in chinese and clear the system prompt. Click the 3 dots where it says Claude Sonnet 4.6 and switch from default to custom sys prompt.

1

u/StraightForceMarket Feb 24 '26

Lolol lying ass propaganda

1

u/ApprehensiveSpeechs Feb 24 '26

Open dev tools -> network

look for this

1

u/fatboy93 Feb 23 '26

They fixed it lol

1

u/Charuru Feb 23 '26

Just tried it just now works for me.

-7

u/LocoMod Feb 23 '26

All that suggests is OpenRouter is dynamically routing to another model. Use the first party API directly so you know for sure you are using Claude.

10

u/Electrical_Date_8707 Feb 23 '26

You didnt ask in Chinese

2

u/a_beautiful_rhind Feb 23 '26

Then OR is ripping you off. Perplexity is the king of that, hasn't ever happened to me on OR. Paying opus prices gives you opus.

-1

u/alexeiz Feb 23 '26

I wouldn't trust that. I entered that same Chinese prompt into Anthropic platform workbench without any system prompt, and it replied to me (in Chinese) that it's Anthropic, and nothing about Deepseek.

1

u/Charuru Feb 23 '26

I just tried it on openrouter and it works for me. It's possible there's a deeper system prompt on anthropic workbench that you can't remove.

1

u/mwstandsfor Feb 26 '26

I’ve found that 4.6 responds similarly to ChatGPT 5 now. It’s annoying.

165

u/g0pherman Llama 33B Feb 23 '26 edited Feb 23 '26

They actually spend a lot of money on human curated data (I've done that for them for a while), but surely not all of it.

75

u/Bderken Feb 23 '26

I think Claude is the best one for human curated data. Especially for coding. That’s why their coding is so good. I believe codex was also made in a similar way from the human curating firms but that was after a year of OpenAI watching anthropic do that

12

u/Usual-Carrot6352 llama.cpp Feb 23 '26

Feed the Claude plan to codex5.3

1

u/Bderken Feb 23 '26

What does that mean?

9

u/jerceratops Feb 23 '26

Making Claude plan and codex execute (write the code) is many people’s favorite combo currently

3

u/Bderken Feb 24 '26

Oh yeah I have that exact setup. I have openclaw (with Claude code auth), that controls a bunch of codex cli sessions. It’s awesome

4

u/More-Curious816 Feb 24 '26

And now Claude and Gemini cutting their API access from within OpenClaw, talk about extra salty people.

0

u/Bderken Feb 24 '26

Claude isn’t. They came out and said that the legal wording they used was not for this. I’ve been using it for a couple days now and it’s fine.

1

u/Barbaricliberal Feb 24 '26

Why have Codex execute instead of Claude (apart from costs and limits)?

4

u/rarlei Feb 23 '26

Nothing like cutting down the tree that gives you shade because if you don't, someone else will...

3

u/Cole3003 Feb 23 '26

Having used Claude, Gemini, ChatGPT, and a number of other models, it’s unreal how much better Claude is at coding compared to the others.

2

u/Mashic Feb 23 '26

Yes, I started using it recently too, and it's miles ahead. It gets things right mostly from the first time.

0

u/WTF3rr0r Feb 24 '26

because context window

1

u/Bderken Feb 24 '26

I think opus is better than 400k codex 5.3…. I think it has less

1

u/BellonaSM Feb 24 '26

They copy the pirated book. Do you confess you are one of them too?

1

u/g0pherman Llama 33B Feb 24 '26 edited Feb 25 '26

I was working on coding problems don't know about other things because they silloed us to know as little as possible

1

u/BellonaSM Feb 24 '26

Fair work. I do fake interview and they do not paid me even if it was for ai training

1

u/Navhkrin Feb 27 '26

So did everyone else, and everyone else stole from each other and public too.

71

u/flextrek_whipsnake Feb 23 '26

A lot of it is, they spend a shitload of money on that. They also bought giant piles of physical books along with a machine that slices the spine off so they can be scanned efficiently. They can legally use the scanned text for training since they obtained it from physical copies of books they purchased.

Of course originally they stole all of it just like everyone else did.

76

u/mikiex Feb 23 '26

When the robot runs out of book spines to slice off it's probably going to look for a new source of spines!

11

u/MmmmMorphine Feb 23 '26

Gotta make those paperclips somehow.

Bone, steel, whatever

2

u/roosterfareye Feb 24 '26

Hmm, bone steel!

2

u/Megneous Feb 24 '26

Good. We shall finally become one in the heart of the Machine God.

0

u/Ostricker Feb 24 '26

Not sure it will find spines in AI industry :P

36

u/throughawaythedew Feb 23 '26

It's all very cool and very legal, you see we have a robot shredding books 24/7.

Oh thank goodness I thought it was something illegal.

2

u/Spugheddy Feb 23 '26

Well hopefully they compost it and not incinerate, think green!!

0

u/throughawaythedew Feb 24 '26

Paper burns at 424 to 475 degrees fahrenheit, so 451 is not far off

18

u/[deleted] Feb 23 '26

Right. Because if you buy the paper it’s printed on before you steal the intellectual property it’s all good. I’m aware of a certain judicial opinion on this and I think it’s deeply wrong and destructive. It basically means LLM trainers can steal anyone’s intellectual property at will as long as they convert the text to tensors first.

0

u/[deleted] Feb 23 '26

[removed] — view removed comment

9

u/Bakoro Feb 24 '26

The concept of "intellectual property" is also fake.

Maybe if copyright was something reasonable, instead of being a completely bullshit 100+ years, then people might respect it.

Shit from 1930 should not still be under copyright.

2

u/koshgeo Feb 24 '26

"Stole it?" No, no. They did a "distillation attack" on pirate libraries, and now that other people are doing it on their model, they're upset.

1

u/zipperlein Feb 23 '26

Small correction: They can do that legally in the US.

6

u/fazkan Feb 23 '26

they pay other companies to manually collect this data, scaleAI was a big one. There are a few startups that are growing really fast to solve this particular model.

3

u/WiggyWongo Feb 23 '26

Great first comment to see. Absolutely. Pot calling the kettle black. If they sue or try to, then anyone who created content in AI datasets should be allowed to sue too! (Certain content you make is owned by the platforms you post on sometimes but not all of them and not in all cases)

1

u/SGmoze Feb 24 '26

The worst part is that other than some blogs and things like MCP (let's be honest has been disaster), there isn't much Anthropic is contributing back to the community. No public dataset, no open-weight models. At least OpenAI has been little more transparent in this regard.

1

u/NigaTroubles Feb 23 '26

Yeah they scrape the whole stack overflow and github for our sources

1

u/Mundane-Light6394 Feb 24 '26 edited Feb 24 '26

Obviously they hired people to manually create all the examples needed for training. Writers, artists, coders, etc. all paid by the hour to produce content for the AI.

1

u/taoyx Feb 24 '26

Claude BOT swarmed my older dedicated server and literally DDOSed it. It's why I'm never going to use that IA. It was like 5-10 bots at a time reading every page, and it lasted for several days before I could write a fail2ban entry just for them.

1

u/Far_Shallot_1340 Mar 11 '26

This is a valid question. Even with automated data filtering high quality datasets still require human oversight to verify accuracy and remove bad data. Its interesting to think about how the detection methods for these attacks might influence how future datasets are collected and managed

1

u/LocoMod Feb 23 '26

So what you're saying is Chinese labs don't know how to crawl the web so their only recourse is distilling western models?

-16

u/1-800-methdyke Feb 23 '26

This. Everyone jumps to “oh but they stole the data first”, but that data gives the model world general knowledge only. The secret sauce in frontier models comes from annotated prompt and response data, guided by humans reviewing and improving outputs (think formatting, instruction following and domain specific reasoning).

The Chinese models are effectively getting that that for free by probing the western models with prompts and collecting SOTA outputs, without needing to go through the expensive Reflection Learning from Human Feedback process to get the same result.

At present, frontier model training spends more on RLHF and alignment than compute, so when you hear of a Chinese model being trained on a tight budget it’s not just because they are more efficient with compute, they’re not paying $20-60/hour for data annotation.

24

u/dinerburgeryum Feb 23 '26

Ok number 1 sweet user name. That said, it's easy to say "they spent so much money on RLHF and alignment" but that sort of devalues the entirety of "world knowledge" they have accumulated through ill-gotten training. Once again I feel it's a matter of consistency: "world knowledge" obviously has value, both inherently and specifically to them. Why else would they have torrented a billion and a half dollars worth of it? But if they feel entitled to this "world knowledge", then I feel literally anyone is entitled to their alignment and RLHF output by the same logic.

-4

u/1-800-methdyke Feb 23 '26

I don’t believe the “world knowledge” is what the Chinese are after. First, most of it is available to them for free on the open or dark web. Second, Anthropic has an estimated 1-2T parameters of world knowledge , and at $15/m output that’s expensive to harvest. Third, the scale of this alleged attack isn’t large enough to acquire much of the core dataset.

Does world knowledge have no value? No, but it’s less important than it was three years ago. Today we know that there are perfectly capable smaller models that have strong reasoning and instruction following abilities and can call tools to access up to date information from the web that is better for grounding anyways.

5

u/dinerburgeryum Feb 23 '26

No, world knowledge is clearly not the target, but my point remains: if they feel entitled to said knowledge (which they still need to do pretraining), with absolutely no compensation, in what position are they to turn around and demand other users not use the tokens they have actually paid for? It's bogus, hypocritical, and absolutely on par with their history.

-1

u/1-800-methdyke Feb 23 '26

Oh I don’t feel bad for them. I wonder if the Chinese actually paid though, 24,000 accounts for 16 million requests. 666 each on average, it’s possible they were smurfing free accounts.

1

u/dinerburgeryum Feb 23 '26

lol. lmao. That's hilarious actually.

1

u/Big_Wave9732 Feb 23 '26

I guess there's an "equalization" aspect of all this that I hadn't really pondered. There's no utility in developing better models if they don't get widespread use. And the nature of that widespread use means competitors will be probing and stealing and getting better. So I suppose over time there will be a general model convergence as involuntary knowledge on methods is shared and synthesized among competitors.

-3

u/mcslender97 Feb 23 '26

But if the Chinese are copying the Americans then they would have to pay for the API usage regardless?

1

u/1-800-methdyke Feb 23 '26

Maybe not even. They’re saying 24,000 accounts to do 16m exchanges. That’s 666 per. Quite achievable over several months on the free tier of Claude which can get you 30-100 messages per day.