Model distillation is an industrial-scale API attack: one documented accusation involves 28.8M fraudulent exchanges across 25,000 fake accounts targeting Claude. Distributed identity fan-out defeats per-account rate limits, so AI serving infrastructure must include account-graph analytics and behavioral anomaly detection inside the model gateway, not just legal/EULA protections.
Any hosted AI capability is an extractable asset; protecting it requires treating anti-distillation as a first-class serving/security subsystem alongside auth and rate limiting.
Any remotely hosted AI system with valuable, queryable behavior will face organized extraction, so defenses must be layered over identity, request patterns, and generated-output fingerprints.
Using 28.8 million fraudulent exchanges across 25,000 fake accounts to extract Claude capabilities.
Anthropic publicly accused China's Alibaba of running a massive distillation campaign to brazenly and illicitly extract AI capabilities from Claude.