虎嗅

Large companies can't hide their secrets anymore—a paper teaches you how to distill something worth a hundred yuan using Claude technology.

原文:大厂藏不住了,一篇论文教你百元蒸馏Claude

Summary of Key Findings

A recent paper has revealed a shocking fact within the AI industry: The encryption and reasoning processes used by large companies to protect the core technologies of their top-tier AI models have been completely cracked using an extremely simple method. By merely invoking a low-cost, entry-level AI model, it is possible to reconstruct the original, encrypted reasoning logic. This means that the AI technology secrets developed at great expense by these companies could be at risk of widespread leakage.

Detailed Analysis

1. What exactly is an AI’s “thinking chain,” and why is it encrypted?

You can think of an AI’s “thinking chain” as its “scratch paper” during problem-solving. For example, if you ask an AI, “How much change is there when I spend $100 on 3 cups of milk tea, each costing $25?” A top-tier AI won’t give the answer directly; instead, it will calculate step by step internally: “3 cups × $25 = $75, $100 – $75 = $25.” This sequence of steps constitutes its thinking chain.

Why do large companies encrypt this information? Because the thinking chain is their unique secret: it determines how the model thinks and produces accurate results, representing a core competency that took hundreds of millions to develop. Once encrypted, users can only see the final answer and not the intermediate steps, preventing others from copying the technology.

2. How simple is the cracking method? Can a low-level model do it?

The method described in the paper is surprisingly straightforward:

  • Take the encrypted thinking chain (which might look like a string of random characters or hidden intermediate results) and feed it into a low-level AI model (such as GPT-3.5, which is more than 10 times cheaper than GPT-4).
  • Have the low-level model “guess” the original steps that correspond to the encrypted content.
  • The result? The low-level model can accurately reconstruct the original reasoning logic, and the cost of this process is almost negligible (possibly just a few cents per attempt).

To put it another way, it’s like locking a piece of paper with problem-solving steps in a password-protected folder, only for someone to open it with a cheap lock costing $5 and copy all the steps.

3. What’s the impact on large companies? What are the consequences of core secrets being leaked?

For large companies, this is equivalent to having their “wealth stolen”:

  • Loss of competitive advantage: Other companies can acquire the encrypted thinking chain and either imitate or improve upon their models. For instance, high-precision legal document generation, once a proprietary capability of a major company, could now be replicated by smaller firms, threatening the company’s monopoly.
  • Reduced commercial value: Top-tier AI models, which used to command high prices (e.g., millions per year for customized services), may see their values halved due to the leakage, significantly impacting revenue.
  • Trust crisis: Customers may become wary of using the models, fearing that sensitive information (such as internal company data) could be compromised, leading them to opt for safer alternatives.

4. What’s the impact on ordinary people?

This doesn’t seem like a concern for you, but the effects could be close at hand:

  • Cheaper AI services: With smaller companies able to replicate large-scale models, market competition will intensify, potentially driving down prices of AI tools (for example, GPT-4 may eventually be replaced by cheaper alternatives).
  • Privacy concerns: If your chat content or work data is processed by AI and the intermediate thinking chain can be cracked, your privacy could be at risk. For instance, if you ask an AI how to hide income for tax purposes, the attacker could see the sensitive question you entered.
  • Faster AI progress: More companies will gain access to core technologies, accelerating the development of innovative AI applications (such as more intelligent educational or medical AI systems).

5. How will the AI industry address this vulnerability? What’s the future direction?

Large companies won’t sit idly by and are likely to take the following actions:

  • Upgrade encryption techniques: They will use more complex encryption methods, such as breaking the thinking chain into fragments or adding random noise to make it harder for low-level models to decode.
  • Change model design: They may abandon the traditional explicit thinking chain and adopt more concealed reasoning processes (e.g., having the model perform calculations internally without leaving visible traces).
  • Legal protection: They may file lawsuits against cracking attempts or apply for stricter patents to prevent the misuse of core technologies.

In summary, this breakthrough highlights that the protection of technical secrets in AI is perhaps more fragile than we thought. The future competition in the AI industry will not only focus on model capabilities but also on security measures.