US agencies accuse six Chinese AI firms of industrial-scale model distillation attacks

CISA, NSA and FBI say DeepSeek, Moonshot AI and others extracted billions of tokens from frontier models by Anthropic, OpenAI, Google and xAI

edit
By LineZotpaper
Published
Updated
Read Time2 min
Sources2 outlets
A joint advisory from CISA, the NSA and the FBI alleges that six Chinese artificial intelligence companies conducted industrial-scale distillation attacks against US frontier AI models, extracting billions of tokens through millions of API requests since at least late 2024.

The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as the offending firms, stating they targeted models from Anthropic, OpenAI, Google and xAI. DeepSeek and Moonshot AI are identified as the top offenders, distilling multiple Claude, GPT, Gemini and Grok models. Alibaba and StepFun allegedly focused on Claude and GPT models, while Z.AI is accused of targeting GPT-5.5 and Claude Opus 4.8.

AI model distillation is a legitimate technique where a smaller “student” model learns from the outputs of a well-trained model, reducing training costs. However, the advisory describes the Chinese firms’ operations as “industrial-scale distillation” that abused API access to extract knowledge and logic at a fraction of the development cost.

The agencies assess that the scale and sophistication of the operations indicate Chinese government awareness, calling the approach a likely core development strategy for the offending firms. According to the advisory, Chinese companies distributed API requests across fraudulent or shared accounts, cloud services, aggregators and proxy “transfer stations” to bypass geographic restrictions, usage limits and detection. Some prompts attempted to expose restricted chain-of-thought reasoning, and automated systems switched providers when blocked.

The advisory recommends that AI companies improve behavioral and infrastructure-level detection, modify responses when distillation is suspected, and share intelligence about these campaigns. Potential indicators include new accounts immediately reaching maximum usage, continuous activity without normal idle periods, shared accounts accessed from numerous IP addresses, identical prompts across providers, and coordinated switching between access routes.

BleepingComputer has contacted all six Chinese AI firms for comment but has not yet received statements.

§

Analysis

Why This Matters

  • The alleged theft of proprietary model knowledge at industrial scale could undermine the competitive advantage of US AI companies and threaten national security by accelerating Chinese AI development without equivalent R&D investment.
  • The involvement of multiple US intelligence agencies signals that the US government views this as a systematic, state-enabled campaign rather than isolated incidents.
  • If proven, these techniques could force US AI firms to redesign API access policies, impose stricter usage monitoring, and potentially limit access to frontier models in certain regions.

Background

AI model distillation is a common research technique in which a smaller model learns from the outputs of a larger, well-trained model. It is widely used to create more efficient models for deployment. However, when applied at massive scale without authorization and using deceptive access methods, it becomes an intellectual property extraction attack. Google warned in February that hackers were abusing its Gemini AI for various attack stages. The current advisory represents the first coordinated US government accusation of such systematic distillation by Chinese companies against multiple US AI providers.

Key Perspectives

[US Cybersecurity and Intelligence Agencies]: They view industrial-scale distillation as a major threat that shortens Chinese AI development timelines and reduces costs, while enabling Chinese firms to compete with US frontier models. They call for stronger detection and information sharing. [Chinese AI Companies]: They have not yet responded publicly. They may argue that API-based distillation is standard practice in the industry, or that their activities fall within fair use and research norms. [Critics/Skeptics]: Some observers may question how much the extracted knowledge can be directly commercialized, given that distillation often captures surface-level patterns rather than underlying training data. Others might note that the US government has limited evidence to prove government awareness, and that accusing six companies without public technical attribution could strain diplomatic relations.

What to Watch

  • Whether any of the six Chinese AI firms issue public statements denying or disputing the allegations.
  • Possible US policy responses such as export controls on AI model weights, tighter API access restrictions, or sanctions against the named companies.
  • How US AI providers respond—whether they implement more aggressive response degradation or account monitoring systems.
  • Signs of retaliatory accusations or actions from the Chinese government.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.