AI News Feed
Market watch
World

U.S. Agencies Accuse Six Chinese AI Firms of Industrial-Scale Model Distillation

U.S. intelligence agencies accused six Chinese AI companies, including DeepSeek and Alibaba, of industrial-scale model distillation from American frontier models and urged firms to adopt defensive measures.

The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI as having extracted billions of tokens across millions of exchanges/requests from U.S. models including variants of Anthropic's Claude, OpenAI's GPT, Google's Gemini and xAI's Grok since at least late 2024. The agencies described the activity as aggressive, malicious and targeted, and CISA stressed that the operation was likely carried out with the awareness of the Chinese government. The advisory stops short of alleging direct government sponsorship.

Knowledge distillation is a widely used machine-learning technique in which the output of a larger teacher model helps train a smaller student model. The agencies acknowledged that distillation is a legitimate and useful technique in AI research, but said the Chinese companies abused it at industrial scale by routing carefully designed queries through multiple accounts, different API access points, multiple cloud providers, third-party AI aggregators, proxy services and shared premium subscriptions to avoid detection.

The advisory details specific examples: DeepSeek used data from various Claude, Gemini, GPT and Grok models to train its R1 reasoning model; Moonshot AI took significant data from Claude's Fable variant to train its Kimi K3 model and also used GPT-4o data for Kimi K2. The advisory maps a broad set of model pairings across multiple generations of U.S. frontier models.

To counter such campaigns, the agencies recommended that U.S. AI companies hunt for anomalous and malicious prompts, accounts, networks and behaviors, including monitoring subscription-to-usage ratios, immediate maximum usage from new accounts and enterprise-scale throughput patterns. They also said firms should deploy targeted response changes, such as subtly altering responses for suspected malicious distillation attempts to reduce the payoff for attackers, and should establish cross-organization intelligence sharing to correlate activity across model providers, cloud platforms and API aggregators.

The new warning follows earlier accusations from American companies. OpenAI and Microsoft said they had banned accounts suspected of distilling their technologies, and Anthropic previously accused DeepSeek, Moonshot and MiniMax of wide-scale distillation. Such practices are not limited to Chinese firms: OpenAI said in its announcement about pulling its models from Cursor that Elon Musk admitted during cross-examination in his lawsuit against OpenAI that he had used OpenAI's output to train xAI models.