A joint advisory published Tuesday by the National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA) claims that China’s government is “likely” aware of distillation efforts conducted by DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies describe distillation as “the core – not merely a supplement – of their AI development strategy.”
Distillation involves a smaller model querying a larger one to learn its responses, improving the smaller model over time. While legitimate when authorised, commercial model providers typically forbid the practice to protect their investment. The US agencies allege Chinese firms flout those restrictions, routing requests through multiple pathways including native APIs, remote cloud providers, and third-party aggregators that obfuscate metadata. A “gray market of proxies known as ‘transfer stations’” is said to resell access to frontier models cheaply while evading safeguards.
The advisory also accuses DeepSeek of using distillation to generate synthetic data for training, suggesting its claims of requiring only modest computing power were false—a notable accusation given that DeepSeek’s earlier statements sparked investor panic. Separately, Alibaba is alleged to have leveraged industrial-scale distillation to improve its Qwen model family, which is free to download and directly challenges US competitors.
The US agencies recommend that AI companies detect and deflect distillation attempts, including subtly altering responses to suspected malicious queries and correlating activity across platforms.
China has previously responded to similar accusations by claiming US companies are equally guilty of distilling Chinese models, and has hinted at retaliatory measures should the US impose bans based on such allegations.