US says Chinese firms extracted billions of tokens from frontier AI models

US Intelligence Agencies Expose Chinese Firms’ Industrial-Scale Theft of AI Models

A shocking joint advisory from top US cybersecurity and intelligence agencies reveals that six Chinese AI companies have been conducting industrial-scale distillation attacks on American frontier AI models, extracting billions of tokens since at least late 2024. The affected firms include DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, which targeted models from prominent tech giants such as Anthropic, OpenAI, Google, and xAI.

At the heart of these attacks is a legitimate technique called distillation, where a “student” model learns from the outputs of a well-trained model to reduce training costs and speed up AI deployment. However, when misused, this approach can be exploited by malicious actors to extract sensitive knowledge and logic from powerful models, effectively allowing them to compete with their creators at a fraction of the cost.

The Chinese firms in question employed sophisticated tactics to bypass detection, distributing API requests across fraudulent or shared accounts, APIs, cloud services, aggregators, and “transfer station” proxies. These attacks often involved attempting to expose restricted chain-of-thought reasoning, as well as automated systems switching providers and checking whether defenders had degraded the responses.

The US agencies assess that the scale and sophistication of these operations indicate Chinese government awareness, suggesting that this approach is a core development strategy for the offending firms. In fact, the advisory explains that Chinese-based AI companies conducting industrial-scale distillation against U.S. AI models can see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.

The advisory recommends that AI companies improve behavioral and infrastructure-level detection, modify responses when distillation operations are suspected, and share intelligence about these campaigns with all stakeholders. Potential indicators of such attacks include new accounts immediately reaching maximum usage, continuous activity without normal human idle periods, shared accounts accessed from numerous IP addresses or user agents, identical prompts across multiple providers, unusually high subscription-to-usage ratios, and coordinated switching between access routes.

As AI technology continues to advance at breakneck speed, it’s essential for companies and individuals to be aware of these types of threats and take proactive steps to protect their sensitive data. By staying informed about the latest security risks and best practices, you can help prevent your own AI models from falling victim to industrial-scale distillation attacks.

To stay ahead of potential threats, consider implementing robust behavioral detection mechanisms and sharing intelligence with other stakeholders in the industry. Regularly monitor your API usage and subscription-to-usage ratios for suspicious activity, and be cautious when encountering new accounts or automated systems accessing your resources. By being vigilant and proactive, you can help ensure that your AI models remain secure and effective.


Source: Bleeping Computer — 2026-09-09