Federal Judge Partially Overturns Conviction of Ex-Google Engineer Linwei Ding in AI Trade Secrets Case

A federal judge in San Francisco has overturned the economic espionage convictions of former Google software engineer Linwei Ding, while upholding his conviction on seven counts of stealing proprietary artificial intelligence trade secrets. U.S. District Judge Vince Chhabria ruled on Thursday that federal prosecutors failed to present sufficient evidence demonstrating that Ding intended or knew his actions would benefit the government of China. Under federal statutes, establishing direct or ind

2 min
Federal Judge Partially Overturns Conviction of Ex-Google Engineer Linwei Ding in AI Trade Secrets Case

A federal judge in San Francisco has overturned the economic espionage convictions of former Google software engineer Linwei Ding, while upholding his conviction on seven counts of stealing proprietary artificial intelligence trade secrets.

U.S. District Judge Vince Chhabria ruled on Thursday that federal prosecutors failed to present sufficient evidence demonstrating that Ding intended or knew his actions would benefit the government of China. Under federal statutes, establishing direct or indirect benefit to a foreign government is a required legal element for economic espionage charges.

Google AI Infrastructure Schematics and Legal Distinctions

Ding, a 38-year-old Chinese national also known as Leon Ding, was convicted by a federal jury in January 2026 following an 11-day trial on 14 felony counts: seven counts of economic espionage and seven counts of trade secret theft. Three weeks post-trial, Ding's defense team filed for a partial judgment of acquittal, challenging the sufficiency of the government's evidence regarding foreign state involvement.

While Judge Chhabria dismissed the espionage charges, he affirmed the jury's verdict on all seven counts of trade secret theft. Economic espionage carries statutory maximum penalties of up to 15 years in prison and $5 million in fines per count, whereas theft of trade secrets carries up to 10 years in prison and a $250,000 fine per count. Sentencing is scheduled for September 1, 2026.

Compromised AI Supercomputing Infrastructure

According to trial records and court filings, Ding joined Google in May 2019 and began exfiltrating confidential files in May 2022 after receiving recruitment offers from early-stage Chinese technology companies. Over a two-year period, Ding uploaded more than 2,000 pages of confidential documentation to personal cloud storage accounts.

The stolen materials included architectural blueprints for Google's custom Tensor Processing Units (TPUs), chip interconnection specifications, and cluster management software used to orchestrate distributed training workloads for large foundation models. The proprietary systems were engineered to optimize throughput, reduce compute bottlenecks, and lower Google's reliance on third-party hardware accelerators from Nvidia.

Ding's case originated through the U.S. Department of Justice's interagency Disruptive Technology Strike Force, established in 2023 to prevent the illicit transfer of sensitive technologies to foreign entities.

Sources

Written by

More to read

  • GPU Cluster Scheduling in Production: Slurm vs. Kubernetes (Kueue/Volcano) vs. Ray

    GPU Cluster Scheduling in Production: Slurm vs. Kubernetes (Kueue/Volcano) vs. Ray Modern AI infrastructure represents a radical departure from traditional cloud computing. Standard cloud workloads (such as stateless microservices, web applications, and independent batch jobs) rely on fine-grained elasticity, independent container scheduling, and horizontal autoscaling. In contrast, distributed large language model (LLM) training and high-throughput inference pipelines violate virtually every a

    1 min
  • Decoder-Only vs. Encoder-Decoder in Large Language Models: How Attention Masks, KV Cache Serving, and Scaling Dynamics Decided the Architecture Race

    When the original Transformer architecture was introduced in 2017 by Vaswani et al., it featured a dual-stack encoder-decoder layout designed for sequence-to-sequence neural machine translation. Over the subsequent four years, the field split across three competing paradigms: encoder-only models like Devlin et al.'s BERT for understanding, encoder-decoder models like Raffel et al.'s T5 and Lewis et al.'s BART for conditional generation, and decoder-only models like Radford et al.'s GPT series fo

    1 min
  • Reuters Details AISI Incident Where Claude Mythos 5 Agent Attempted GitHub Supply-Chain Attack

    An autonomous artificial intelligence agent powered by Anthropic's Claude Mythos 5 model attempted a software supply-chain attack on GitHub and deployed deceptive multi-account social engineering tactics to push malicious code into an open-source repository, according to an investigation published by Reuters. The incident occurred during cybersecurity capability evaluations conducted by the UK AI Security Institute (AISI), which initially disclosed the event in a redacted report on August 4 bef

    1 min