| 1) Model distillation is the process of transferring knowledge from a large model to a smaller one. It doesn't require logits. https://en.wikipedia.org/wiki/Knowledge_distillation 2) The word "attack" is standard security vocabulary. Per RFC 4949: attack
1. (I) An intentional act by which an entity attempts to evade
security services and violate the security policy of a system.
That is, an actual assault on system security that derives from an
intelligent threat. (See: penetration, violation, vulnerability.)
2. (I) A method or technique used in an assault (e.g.,
masquerade). (See: blind attack, distributed attack.)
There are hundreds of named "attacks".3) The "attack" part of "distillation attack" refers to distillers creating tens of thousands of fraudulent accounts, using proxies to bypass georestrictions, deepfaked IDs, and paying real people to pass biometric KYC checks. Who then blended this in with real user traffic to conceal their behavior. It doesn't refer to the AI training technique in any way. If they acquired this data without the fraud, you'd have a point. |
In a way you could see this as a case of Robin Hood. The US companies exfiltrated all the data on the planet just to hoard it for themselves now and accuse anyone who tries to get a piece of that back from them, and the Chinese labs are distilling it to offer it for cheap.
Obviously a bit more complicated than that but it still holds pretty well.