US Government Accuses Chinese AI Firms of Stealing Proprietary Capabilities from US Models
The US government has accused several top Chinese artificial intelligence (AI) firms of engaging in massive campaigns to extract proprietary capabilities from leading US AI models. The firms, which include Alibaba, DeepSeek, and Moonshot AI, allegedly used a process called distillation to covertly extract billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX’s Grok, among others.
At the heart of this scandal is a widely accepted practice in the academic community known as distillation. In distillation, mature “teacher” AI models are used to train “student” AI models, making them more efficient and improving their performance on specialized tasks. However, what makes this case different is that these Chinese firms allegedly trained on outputs obtained in violation of the terms of service, deliberately extracting a competitor’s proprietary capabilities and using evasive techniques to avoid detection.
The US agencies claim that these firms are doing this with the awareness of the Chinese government, and that they see significantly shorter AI development timelines and reduced financial expenditures as a result. To save money during this intensive process, China-based AI firms allegedly obtain bulk premium subscriptions for US AI models and share them across teams of developers. They also use complex techniques to route distillation requests through native APIs, remote cloud providers, and third-party aggregators that automatically obfuscate user metadata.
The advisory from the FBI, NSA, and CISA outlines multiple techniques used by these Chinese firms to access US frontier models at an industrial scale. These include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures.
Specific companies were accused of specific wrongdoing. DeepSeek allegedly ran an organized distillation campaign against frontier models of US AI companies since at least late 2024 in order to “generate synthetic training data for its models.” Moonshot AI, meanwhile, allegedly extracted significant Claude Fable 5 data to train its Kimi-K3 model and GPT-4o data to train its Kimi-K2 model.
The advisory made clear that these firms are likely using this stolen technology to reduce their own costs and development time. The authoring agencies recommend that US AI companies implement comprehensive detection and mitigation measures to find anomalous and malicious behavior, share intelligence with other AI organizations to gain awareness of broader campaigns, and tune responses for suspected malicious attempts to reduce the effectiveness of these tactics.
For individual users and developers, this news serves as a reminder of the importance of security in the AI space. As AI models become increasingly sophisticated and widely used, the risk of intellectual property theft and misuse grows. By staying informed about emerging threats and best practices, individuals can better protect themselves against these types of attacks.
Source: Dark Reading — 2026-09-09