US Government Accuses Chinese AI Firms of Distilling Frontier Models

US Government Accuses Chinese Firms of Illicitly Extracting Capabilities from Top US AI Models

In a shocking revelation, the US government has accused several Chinese artificial intelligence (AI) firms of engaging in massive “distillation campaigns” to covertly extract billions of tokens from leading US AI models. The FBI, National Security Agency (NSA), and Cybersecurity and Infrastructure Security Agency (CISA) published a joint advisory on September 8, warning that these Chinese companies were exploiting US large language models (LLMs) to assist the training and development of their own proprietary models.

The affected US-based AI models include Claude, GPT, Gemini, and Grok, which are used by companies such as OpenAI, Anthropic, Google, and SpaceX. The Chinese firms allegedly extracted these tokens through distillation, a widely accepted practice in academic research where mature “teacher” AI models are used to train “student” AI models. However, the US agencies claim that these companies went beyond legitimate use cases and deliberately extracted proprietary capabilities from their competitors’ models.

The advisory highlights the alarming rate at which Chinese firms are extracting tokens, with estimates suggesting billions of exchanges/requests since at least late 2024. This illicit activity allows them to reduce development costs and save time in training their own frontier models. The US agencies suspect that these companies may be working under the guidance or awareness of the Chinese government.

To avoid detection, the Chinese firms allegedly obtain bulk premium subscriptions for US AI models and share them across teams of developers. They also use evasive techniques such as routing distillation requests through native APIs, remote cloud providers, and third-party aggregators that automatically obfuscate user metadata. Furthermore, they utilize “transfer stations,” a gray market of proxies used specifically to bypass geographic restrictions and evade safeguards.

Specifically, the advisory mentions DeepSeek, which allegedly ran an organized distillation campaign against frontier models since at least late 2024. The company targeted specific knowledge domains to extract proprietary functionality and reasoning capabilities, reportedly reducing its compute and research costs. Moonshot AI also faced accusations of extracting significant data from Anthropic’s Claude model and Google’s GPT-4.

The US agencies recommend that US AI companies implement comprehensive detection and mitigation measures to identify anomalous and malicious behavior. They should also share intelligence with other AI organizations to gain awareness of broader campaigns and tune their responses to reduce the effectiveness of these illicit activities. By doing so, US-based AI firms can protect their proprietary capabilities and maintain a competitive edge in the rapidly evolving AI landscape.

As the AI industry continues to grow, this incident highlights the need for increased vigilance and cooperation between governments, companies, and researchers to prevent such malicious activities. The US government’s advisory serves as a wake-up call for the global AI community to prioritize cybersecurity and protect their intellectual property from those who would seek to exploit it.


Source: Dark Reading — 2026-09-09