Breaking
SecurityConfirmed

Alleged Chinese AI theft rings alarm bells

FBI, NSA and CISA warn of industrial-scale distillation campaigns targeting US frontier models.

··2 hours ago·3 min read
woman in black top using Surface laptop
Photo by Christina @ wocintechchat.com M on Unsplash

American law enforcement and intelligence agencies are ringing alarm bells over what they describe as an aggressive campaign by Chinese AI companies to siphon off the core capabilities of US frontier models through a technique called knowledge distillation. The joint advisory, published by CISA, details a pattern of activity that the agencies say amounts to systematic extraction of proprietary functionality, threatening US technological leadership.

An industrial-scale threat

The advisory, drafted with the NSA and FBI, warns US AI companies about ongoing "aggressive, malicious, and targeted distillation activities at an industrial scale." The agencies claim that Chinese companies, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, have extracted billions of tokens across millions of exchanges from US frontier models since at least late 2024.

These models include variants of Claude, GPT, Gemini, and Grok. The scale of the operation, as described, suggests a coordinated effort rather than isolated incidents. The agencies note that this was likely done with the awareness of the Chinese government, though they stop short of saying it was officially sanctioned.

What is knowledge distillation?

Knowledge distillation is a machine learning technique where a smaller "student model" learns to mimic the behavior of a larger, pre-trained "teacher model." IBM defines it as a way to transfer learnings from a large model to a smaller one, often for model compression and knowledge transfer.

The technique itself is legitimate and widely used in AI research. However, the advisory stresses that China-based AI companies are employing it in bad faith. Instead of investing months and millions to develop new capabilities, they appear to be sending carefully designed questions to US models and extracting the answers to train their own systems.

Who is allegedly involved?

On the Chinese side, the models being trained include DeepSeek R1 and V3, Moonshot's Kimi-K2 and Kimi-K3, and MiniMax's M2. The US models targeted range from earlier versions like GPT-4, Claude 3.7, and Gemini 2.5 Flash Preview to newer ones like Claude Fable 5 and GPT-5.

The advisory lists these examples, indicating a broad scope of extraction that has impacted multiple frontier models over time.

Evading detection

The report describes how the allegedly malicious actors routed their requests through multiple accounts, different API access points, multiple cloud providers, third-party AI aggregators, proxy services, and "transfer stations." They also used premium subscriptions shared between developers to work around defenses designed to disrupt the process.

This level of obfuscation suggests a deliberate effort to evade detection and prolong the extraction campaigns.

This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations.

— The advisory, published by CISA, NSA, and FBI

What US companies should do

To protect their intellectual property and maintain a competitive edge, US AI companies are urged to implement comprehensive detection and mitigation strategies. This includes hunting for anomalous and malicious prompts, accounts, networks, and behaviors.

Monitoring subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns can help spot potential distillation attempts.

Deploying deceptive responses

The advisory recommends a second step: "deploy targeted response changes." This involves subtly altering responses for suspected malicious distillation attempts to attenuate the payoffs for companies conducting such campaigns. In other words, AI companies should consider making their models provide misleading outputs when they detect that knowledge is being extracted.

Finally, US AI firms are encouraged to set up cross-organization intelligence sharing, correlating activity across model providers, cloud platforms, and API aggregators to better defend against these coordinated efforts.

Why this matters for the AI industry

The allegations highlight the high stakes in the race to develop advanced AI. If Chinese companies are indeed leveraging distillation at this scale, it could undermine the competitive advantage of US firms.

For businesses relying on AI, this could mean increased costs or delays as model providers focus on security. The advisory signals that the US government views AI protection as a national security priority, which could lead to more stringent regulations and oversight of AI development and usage.

#ai#knowledge-distillation#cisa#nsa#fbi#cybersecurity

Sources

Iliyas

Founder & Editor, Xploitwire

This article was written and reviewed against the sources listed above before publication, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories