Federal Judge Partially Overturns Conviction of Ex-Google Engineer Linwei Ding in AI Trade Secrets Case

A federal judge in San Francisco has overturned the economic espionage convictions of former Google software engineer Linwei Ding, while upholding his conviction on seven counts of stealing proprietary artificial intelligence trade secrets. U.S. District Judge Vince Chhabria ruled on Thursday that federal prosecutors failed to present sufficient evidence demonstrating that Ding intended or knew his actions would benefit the government of China. Under federal statutes, establishing direct or ind

2 min
Federal Judge Partially Overturns Conviction of Ex-Google Engineer Linwei Ding in AI Trade Secrets Case

A federal judge in San Francisco has overturned the economic espionage convictions of former Google software engineer Linwei Ding, while upholding his conviction on seven counts of stealing proprietary artificial intelligence trade secrets.

U.S. District Judge Vince Chhabria ruled on Thursday that federal prosecutors failed to present sufficient evidence demonstrating that Ding intended or knew his actions would benefit the government of China. Under federal statutes, establishing direct or indirect benefit to a foreign government is a required legal element for economic espionage charges.

Google AI Infrastructure Schematics and Legal Distinctions

Ding, a 38-year-old Chinese national also known as Leon Ding, was convicted by a federal jury in January 2026 following an 11-day trial on 14 felony counts: seven counts of economic espionage and seven counts of trade secret theft. Three weeks post-trial, Ding's defense team filed for a partial judgment of acquittal, challenging the sufficiency of the government's evidence regarding foreign state involvement.

While Judge Chhabria dismissed the espionage charges, he affirmed the jury's verdict on all seven counts of trade secret theft. Economic espionage carries statutory maximum penalties of up to 15 years in prison and $5 million in fines per count, whereas theft of trade secrets carries up to 10 years in prison and a $250,000 fine per count. Sentencing is scheduled for September 1, 2026.

Compromised AI Supercomputing Infrastructure

According to trial records and court filings, Ding joined Google in May 2019 and began exfiltrating confidential files in May 2022 after receiving recruitment offers from early-stage Chinese technology companies. Over a two-year period, Ding uploaded more than 2,000 pages of confidential documentation to personal cloud storage accounts.

The stolen materials included architectural blueprints for Google's custom Tensor Processing Units (TPUs), chip interconnection specifications, and cluster management software used to orchestrate distributed training workloads for large foundation models. The proprietary systems were engineered to optimize throughput, reduce compute bottlenecks, and lower Google's reliance on third-party hardware accelerators from Nvidia.

Ding's case originated through the U.S. Department of Justice's interagency Disruptive Technology Strike Force, established in 2023 to prevent the illicit transfer of sensitive technologies to foreign entities.

Sources

Written by

More to read

  • The Softmax Bottleneck in Large Language Models: Matrix Factorization Bounds, High-Rank Token Distributions, and Mixture of Softmaxes

    Autoregressive language models predict probability distributions over vocabulary tokens conditioned on preceding text. In standard Transformer architectures, the model computes a hidden state vector $h_c \in \mathbb{R}^d$ for a given context $c$, projects it into vocabulary space using a linear unembedding matrix $W \in \mathbb{R}^{V \times d}$, and applies the softmax function to normalize the resulting logits into probabilities. While computationally convenient, this formulation imposes a fun

    1 min
  • LLM Text Watermarking in Production: Statistical Logit Biasing, Cryptographic Signatures, and Evasion Vectors

    As regulatory frameworks such as Article 50 of the EU AI Act enforce machine-generated content provenance, text watermarking has transitioned from academic theory to a core component of production LLM serving stacks. Unlike post-hoc classifiers that evaluate perplexity or burstiness and suffer from high false-positive rates on formal or non-native writing, generation-time watermarks embed imperceptible statistical or cryptographic signals directly into the token sampling process. When engineere

    1 min
  • Grokking in Large Language Models: How Weight Decay and Circuit Efficiency Drive Delayed Generalization

    Grokking in Large Language Models: How Weight Decay and Circuit Efficiency Drive Delayed Generalization In standard machine learning paradigms, model generalization closely tracks training loss: as an optimizer minimizes loss on training data, performance on held-out validation data improves in tandem until the model begins to overfit. In 2022, researchers at OpenAI observed a phenomenon that inverted this assumption: small neural networks trained on algorithmic tasks achieved near-zero trainin

    1 min