Завантаження...
A team of international researchers has unveiled a sophisticated method for extracting the hidden reasoning processes from advanced AI models, potentially revealing how some Chinese AI companies may be systematically copying proprietary technology from leading US models. The breakthrough research, conducted by scientists from University of Tübingen, Max Planck Institute, MATS Research, and Snyk, exposes a fundamental vulnerability in how major AI providers protect their intellectual property.
The technique successfully extracted "reasoning traces" - the step-by-step thought processes AI models use to solve complex problems - from frontier models including Claude, GPT, and Gemini. These internal reasoning patterns are typically kept secret by companies to prevent competitors from using them to train rival systems. However, the researchers discovered they could bypass these protections by exploiting smaller versions of the same models that have received less alignment training.
The method works by taking advantage of the fact that AI companies offer multiple model sizes to balance performance and cost. While larger models are more capable, they're also more expensive to run and access. Users often choose smaller, weaker variants for certain tasks to reduce costs. The researchers found that these smaller models, sharing the same decryption keys but having weaker safety guardrails, were more willing to reveal the hidden reasoning traces when prompted appropriately.
Perhaps most concerning for US AI companies, the research provides evidence suggesting that Moonshot AI's Kimi K3 model produces strikingly similar reasoning patterns to Claude Opus 4.8 and GPT 5.6 Sol for certain prompts. This similarity suggests possible "distillation" - a technique where knowledge from one model is transferred to train another. However, the researchers noted they cannot definitively prove causation, and other Chinese models like DeepSeek showed no such similarities.
The security implications extend beyond competitive concerns. The same method successfully recovered sensitive personal information, including passwords and API keys, embedded in reasoning traces captured from users' machines. This vulnerability affected all major frontier model providers tested, though companies have since implemented mitigations after being alerted to the issue last month.
Distillation has become a flashpoint in US-China AI competition. Earlier this year, OpenAI informed lawmakers that DeepSeek appeared to have copied one of its models to build the R1 reasoning system. Similarly, Anthropic reported that Alibaba had systematically distilled its models to create the Qwen series. These accusations highlight growing tensions over intellectual property in AI development.
The practice itself isn't inherently problematic - distillation is a widely used, legitimate technique for efficiently transferring capabilities between models. It's particularly common in developing open-weight models that can be freely downloaded and modified. However, when used to copy proprietary technology without permission, it raises significant legal and competitive concerns.
Industry leaders remain divided on how to address distillation. Meta CEO Mark Zuckerberg recently argued that distillation is fundamental to open-source AI development and warned that restricting it could disadvantage US innovation. Others contend that Chinese companies gain unfair advantages by copying US technology to create cheaper alternatives.
Experts question whether distillation restrictions would significantly impact competitive dynamics. Kyle Miller from the Center for Security and Emerging Technologies suggests that Chinese companies possess sufficient expertise to develop cutting-edge models independently if needed. The actual benefit distillation provides to Chinese labs remains unclear, as it only enhances existing capabilities to a limited degree.
While companies have addressed the immediate security vulnerabilities that allowed personal information extraction, the broader issue of reasoning trace recovery persists. Completely preventing such extraction would require fundamental changes to how AI APIs operate, presenting significant technical challenges.
The research underscores the complex balance AI companies must strike between protecting intellectual property and maintaining usable services. As AI models become increasingly sophisticated and valuable, securing their internal processes while enabling practical applications will likely require new approaches to system architecture and security.
The findings also highlight the rapid pace of AI security research and the need for continuous vigilance as new vulnerabilities emerge. As the AI industry continues to evolve, protecting proprietary technology while fostering innovation through legitimate collaboration will remain a critical challenge for companies and policymakers alike.
Related Links:
Note: This analysis was compiled by AI Power Rankings based on publicly available information. Metrics and insights are extracted to provide quantitative context for tracking AI tool developments.