Gemini distillation attacks are intensifying, and Google says the scale is far bigger than most people realize. In a newly released report, the tech giant revealed that its AI chatbot, Gemini, has been hit with repeated attempts to clone its core intelligence — including one campaign that sent more than 100,000 prompts to the system.
The revelation shines a spotlight on a growing cybersecurity and intellectual property battle unfolding behind the scenes of the AI race.
What Are Gemini Distillation Attacks?
According to Google, the company has seen a rise in what it calls “distillation attacks.” These Gemini distillation attacks involve systematically prompting the chatbot with thousands — sometimes tens of thousands — of carefully structured queries designed to extract its reasoning patterns and internal logic.
In technical terms, this practice is often referred to as “model extraction.” Instead of hacking servers, attackers repeatedly question the system in ways that reveal how it processes information. The goal? Recreate or enhance their own AI models using insights gleaned from Gemini’s responses.
Google considers Gemini distillation attacks a form of intellectual property theft.
One Campaign Crossed 100,000 Prompts
Perhaps the most striking detail is the scale. Google disclosed that at least one coordinated effort prompted Gemini more than 100,000 times. That level of interaction suggests an organized attempt to reverse-engineer the model rather than casual experimentation.
A spokesperson confirmed that the activity appears to be “commercially motivated.” While Google declined to name suspects, the company believes the actors are primarily private companies or researchers seeking a competitive edge in the AI arms race.
The geographic origins of these Gemini distillation attacks remain undisclosed.
Why Gemini Is a Prime Target
Large language models like Gemini represent billions of dollars in research and development. Their internal architectures, reasoning algorithms, and optimization techniques are considered highly proprietary assets.
Because major AI chatbots are publicly accessible, they are inherently exposed to probing. Even with built-in detection systems designed to identify and block suspicious behavior, Gemini distillation attacks remain difficult to eliminate entirely.
John Hultquist, chief analyst at Google’s Threat Intelligence Group, warned that this may just be the beginning. He described Google as the “canary in the coal mine,” suggesting that similar attacks will likely target smaller companies as more organizations deploy custom AI systems.
The Bigger Risk for Custom AI Models
The threat goes beyond Gemini.
As businesses increasingly train custom large language models on proprietary or sensitive datasets, the risk grows. If attackers can successfully conduct distillation attacks, they could theoretically extract strategic insights embedded in those systems.
Hultquist offered a stark example: imagine an AI trained on a century of proprietary trading strategies. A successful model extraction could potentially distill elements of that institutional knowledge.
That scenario transforms Gemini distillation attacks from a corporate nuisance into a broader strategic risk.
AI Industry Tensions Are Rising
Google is not alone in facing these concerns. The AI sector has already seen accusations of distillation between major players. OpenAI previously alleged that a Chinese rival attempted similar extraction techniques to improve its own models.
The underlying reality is clear: as AI becomes more valuable, efforts to replicate or reverse-engineer leading systems are accelerating.
For Google, Gemini distillation attacks represent a direct challenge to protecting its competitive advantage in an industry defined by rapid innovation and massive investment.
The Real Battle in the AI Race
The public sees polished chatbot interfaces. Behind the scenes, companies are fighting to defend their algorithms from sophisticated extraction attempts.
Google’s disclosure signals that model extraction is no longer theoretical — it is active, organized, and potentially global.
If Gemini distillation attacks can scale to 100,000+ prompts today, the broader AI ecosystem may soon face even more aggressive tactics.
The AI race is no longer just about building smarter systems. It’s about defending them.

Don’t miss out on our latest news—follow us for the latest AI news, breakthroughs, and insights that matter.