United States cybersecurity and intelligence agencies have issued a stark warning, revealing that six Chinese artificial intelligence companies have engaged in extensive, industrial-scale "distillation" attacks on leading American frontier AI models. These operations, believed to have been ongoing since at least late 2024, have resulted in the extraction of billions of data tokens, representing a significant effort to leverage the capabilities of highly advanced AI systems without incurring the substantial research and development costs.
A joint advisory released by the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the Federal Bureau of Investigation (FBI) identified DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as the entities involved. The advisory details how these firms allegedly orchestrated millions of requests to access and learn from the outputs of powerful AI models developed by prominent U.S. companies, including Anthropic, OpenAI, Google, and xAI.
The agencies’ assessment suggests that the sheer scale and sophisticated nature of these operations strongly indicate awareness and potential backing from the Chinese government. This strategic approach is considered a likely core development strategy for the implicated firms, allowing them to accelerate their AI development timelines and significantly reduce financial expenditures.
The Art and Abuse of AI Distillation
AI model distillation is, in principle, a legitimate and widely used technique within the AI research and development community. It involves a smaller, less complex "student" model learning from the outputs of a larger, more powerful "teacher" model. This process is akin to a student learning from an expert’s knowledge and reasoning. The primary benefits include reducing the computational resources required for training, leading to faster deployment of AI applications and lower operational costs. Developers can create more efficient models that retain much of the performance of their larger counterparts, making advanced AI more accessible.
However, as Google itself cautioned in a February advisory, the potential for abuse is significant. When conducted outside controlled environments and through unauthorized means, distillation attacks can exploit Application Programming Interface (API) access to effectively siphon the knowledge and intricate logic embedded within state-of-the-art models. This allows competing entities to replicate or closely approximate the capabilities of these advanced systems at a fraction of the original training cost, bypassing the immense investments in data, compute power, and human expertise that go into developing frontier AI.
A Sophisticated Scheme to Evade Detection
The advisory from CISA provides a detailed account of the methods employed by the Chinese firms to circumvent detection mechanisms and operational limits. To mask their activities and bypass geographical restrictions, usage caps, and monitoring systems, these companies are accused of distributing their API requests across a complex web of fraudulent or shared accounts, numerous APIs, cloud services, third-party aggregators, and "transfer station" proxies. This distributed approach makes it significantly harder for the targeted AI providers to identify and block the illicit activity.
The nature of the queries themselves also points to a deliberate attempt to extract core functionalities. Some of the prompts were designed to expose the "chain-of-thought" (CoT) reasoning processes of the AI models. Chain-of-thought reasoning is a crucial advancement in AI that allows models to break down complex problems into intermediate steps, mimicking human-like logical progression. Extracting this capability is a high-value target for competitors seeking to understand and replicate sophisticated problem-solving abilities.
Furthermore, the advisory highlights the use of automated systems that actively tested the defenses of the AI providers. These systems would switch between different API providers or access routes if one was blocked, and crucially, they would check whether the AI’s responses had been degraded or altered in response to suspected distillation attempts. This indicates a dynamic and adaptive strategy aimed at overcoming defensive measures in real-time.
Advanced Tactics and the "Industrial Scale"
CISA’s advisory elaborates on the advanced nature of these tactics, stating, "Advanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures." This level of sophistication underscores that these are not isolated incidents but rather coordinated, large-scale efforts.

The economic implications are significant. The advisory explicitly states, "China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model." This presents a clear competitive disadvantage for U.S. companies that invest heavily in original research and development, as their innovations can be rapidly replicated by competitors who circumvent these substantial costs.
Identifying the Key Players and Their Targets
The advisory specifically names the companies involved and outlines their alleged targeting strategies:
- DeepSeek and Moonshot AI: These two firms are identified as the most prolific offenders, allegedly involved in distilling multiple AI models, including Claude (from Anthropic), GPT (from OpenAI), Gemini (from Google), and Grok (from xAI). Their broad targeting suggests an aim to gain comprehensive insights across various leading AI architectures.
- MiniMax: This company is reported to have targeted Claude, Gemini, and GPT models. While less broad than DeepSeek and Moonshot AI, their focus still represents a significant effort to extract capabilities from major U.S. AI platforms.
- Alibaba and StepFun: These firms are accused of targeting Claude and GPT models. Their objective is stated as improving their own AI products by learning from the advanced functionalities of these models.
- Z.AI: This entity is alleged to have specifically targeted GPT-5.5 and Claude Opus 4.8, indicating an interest in the most advanced versions of these frontier models.
The collective efforts of these six companies represent a concerted push to leverage U.S. AI advancements, potentially enabling China to close the AI gap more rapidly.
Recommended Defenses and Indicators of Compromise
In response to these findings, the U.S. agencies have put forth several recommendations for AI companies to bolster their defenses:
- Enhanced Detection: Improve both behavioral and infrastructure-level detection mechanisms to identify anomalous usage patterns indicative of distillation.
- Adaptive Responses: Modify AI model responses when distillation operations are suspected. This could involve providing slightly altered outputs or introducing subtle errors to confuse the distillation process.
- Intelligence Sharing: Foster robust intelligence sharing among all stakeholders, including AI providers, cybersecurity firms, and government agencies, to create a more unified defense against these evolving threats.
The advisory also lists several potential indicators that AI providers should monitor to detect such activities:
- Immediate Maximum Usage: New accounts that rapidly reach their maximum usage limits.
- Continuous Activity: Uninterrupted activity without the normal periods of human idleness or breaks.
- Shared Account Abuse: Shared accounts accessed from a multitude of geographically diverse IP addresses or employing a wide array of user agents.
- Identical Prompts Across Providers: The same or very similar prompts being submitted to multiple different AI providers simultaneously or in rapid succession.
- High Subscription-to-Usage Ratios: An unusually high ratio of subscription costs to actual usage, potentially indicating automated, high-volume request generation.
- Coordinated Access Route Switching: Synchronized changes in access pathways or proxy usage, suggesting an automated system reacting to blocking attempts.
These indicators provide actionable intelligence for companies to strengthen their security postures and identify potential breaches.
Broader Implications and Geopolitical Context
The revelations underscore the escalating competition and tension in the global AI landscape. Frontier AI models represent a significant national strategic asset, with profound implications for economic competitiveness, national security, and technological leadership. The ability to extract and replicate these capabilities without commensurate investment can significantly alter the global balance of power in AI development.
This situation is unfolding against a backdrop of broader U.S.-China technological competition, where issues of intellectual property theft, data security, and supply chain integrity are paramount. The U.S. government’s public advisory serves not only as a directive for industry but also as a clear signal to China regarding its concerns about these practices.
The long-term implications could include a bifurcated AI ecosystem, where distinct sets of AI models and standards emerge, driven by national interests and security concerns. It also raises questions about the future of open-source AI development and the ethical considerations surrounding the use and protection of advanced AI technologies.
The advisory from CISA, NSA, and the FBI represents a significant escalation in the ongoing efforts to safeguard U.S. AI innovation. The coordinated release of this information highlights the seriousness with which these agencies view the threat of industrial-scale AI distillation and the potential for widespread economic and strategic repercussions. The AI industry now faces the challenge of implementing robust defenses against increasingly sophisticated methods of intellectual property extraction in the rapidly evolving world of artificial intelligence.






