signalAI热榜2026-10-02
OpenAI blocks distillation theft, but researchers say same trick still works on Azure for GPT-6 Astra and other models
OpenAI halted a distillation attack involving over 4,000 users and 16,000 requests in July, linking the group to Moonshot AI. Researchers Joachim Schaeffer and team found the same attack still works on Microsoft Azure, allowing reasoning extraction from GPT-6 Astra and Anthropic models up to Sonnet 5. OpenAI added protections for Azure endpoints on September 27, but researchers argue uniform security across all cloud platforms is necessary.
- for who
- AI safety researchers, cloud API providers, and companies using third-party hosting for frontier models
- why now
- Azure still exposes GPT-6 Astra to distillation attacks, weeks after OpenAI patched its own API.
- what changes
- The realization that deploying a model on a less protected cloud platform can nullify its built-in safety measures, forcing providers to enforce consistent security across all endpoints
- to do
- Review your AI model's hosting platform for protection gaps, and demand equivalent security measures from cloud providers before deployment
key points
- OpenAI blocked 16,000 requests from 4,000 users linked to Moonshot AI
- Attack still worked on Azure for GPT-6 Astra and Anthropic Sonnet 5
- Researchers advocate uniform cloud protections to prevent extraction
#ai security#model distillation#openai#azure#gpt-6 astra
score
score 7 out of 10. 0-10: how dense the facts are, multiplied by how much you can do with them after reading. 8+ means the topic's evidence bar is met: benchmarks and availability for a new model, amount and investors for a funding round, revenue figures for a solo-money story. Below 5 an item does not enter the digest. A press release scores 3 or less, a reprint loses 2, anything older than 14 days loses 1, a headline that misleads loses 3.
read the source