Nicholas discusses the distinction between model stealing and training data extraction, emphasizing the motivations behind each. While model stealing primarily harms the organization that invested in training the model, training data extraction raises significant privacy issues, particularly for patients whose data may be exposed. The conversation highlights the ethical implications of these attacks and the differing techniques used to execute them.