US intelligence accuses Chinese AI firms of industrial-scale model distillation

NSA, FBI and CISA allege Beijing-backed campaigns to extract proprietary capabilities from American frontier models

edit
By LineZotpaper
Published
Read Time2 min
Three US intelligence and cybersecurity agencies have accused Chinese AI companies of running “aggressive, malicious, and targeted” distillation campaigns at an industrial scale to extract restricted capabilities from American frontier models, violating terms of use and potentially undermining the business models of US AI firms.

A joint advisory published Tuesday by the National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA) claims that China’s government is “likely” aware of distillation efforts conducted by DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies describe distillation as “the core – not merely a supplement – of their AI development strategy.”

Distillation involves a smaller model querying a larger one to learn its responses, improving the smaller model over time. While legitimate when authorised, commercial model providers typically forbid the practice to protect their investment. The US agencies allege Chinese firms flout those restrictions, routing requests through multiple pathways including native APIs, remote cloud providers, and third-party aggregators that obfuscate metadata. A “gray market of proxies known as ‘transfer stations’” is said to resell access to frontier models cheaply while evading safeguards.

The advisory also accuses DeepSeek of using distillation to generate synthetic data for training, suggesting its claims of requiring only modest computing power were false—a notable accusation given that DeepSeek’s earlier statements sparked investor panic. Separately, Alibaba is alleged to have leveraged industrial-scale distillation to improve its Qwen model family, which is free to download and directly challenges US competitors.

The US agencies recommend that AI companies detect and deflect distillation attempts, including subtly altering responses to suspected malicious queries and correlating activity across platforms.

China has previously responded to similar accusations by claiming US companies are equally guilty of distilling Chinese models, and has hinted at retaliatory measures should the US impose bans based on such allegations.

§

Analysis

Why This Matters

  • The allegations directly challenge the competitive landscape of AI development, threatening the revenue models of US companies that invest heavily in frontier models.
  • If confirmed, the practice could accelerate China’s AI capabilities while undermining US export controls and technology protection efforts.
  • The accusations escalate US-China tech tensions and may trigger new trade restrictions or retaliatory measures.

Background

Distillation is a well-established machine learning technique for creating smaller, more efficient models by learning from larger ones. It is legitimate when performed with permission, but unauthorised distillation violates terms of service and potentially intellectual property rights. The US government has repeatedly raised concerns about Chinese AI companies’ practices, while China has countered with accusations of US misconduct.

Key Perspectives

US Intelligence Agencies (NSA, FBI, CISA): They view distillation as a systematic, state-tolerated strategy by Chinese firms to bypass investment and regulatory barriers, using obfuscation methods like transfer stations and proxy networks. Chinese AI Companies: They have not publicly commented on this specific advisory, but Chinese officials have previously denied the allegations and accused US firms of similar behaviour. Critics/Skeptics: Some industry observers may question the scale of the threat, noting that distillation is a common research practice and that US companies also benefit from open-source Chinese models. There is also risk that the allegations are used to justify trade barriers.

What to Watch

  • Any formal US government response, such as sanctions or export controls on specific Chinese AI firms.
  • Statements from the named companies (DeepSeek, Alibaba, etc.) either denying or acknowledging the claims.
  • Potential impact on the availability of Chinese open-weight models like Qwen on global platforms.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.