NSA, CISA, FBI Accuse Six Chinese AI Firms of Model Distillation

US intelligence agencies accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting billions of tokens from OpenAI, Anthropic, Google, and SpaceX at industrial scale.
Table of Contents
    Add a header to begin generating the table of contents

    The NSA, CISA, and FBI jointly published an advisory on September 9 accusing six Chinese AI companies of conducting systematic extraction campaigns against US frontier AI models at what the agencies describe as “industrial-scale.” The named companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — allegedly covertly extracted billions of tokens from OpenAI, Anthropic’s Claude, Google Gemini, and SpaceX’s Grok to reverse-engineer advanced capabilities without investing in equivalent compute, data, or research infrastructure.

    Distillation Technique Involves Repeated Querying to Reverse-Engineer Model Capabilities

    The extraction technique, known as “distillation,” involves repeatedly querying a target model with carefully crafted inputs to observe outputs and infer the model’s underlying training data patterns and reasoning capabilities. By analyzing responses across billions of queries, the extracting party can build a replica model that approximates the target’s capabilities without access to the original training data or model weights.

    The process works by sending millions or billions of prompts to the target AI model and recording the responses. Machine learning algorithms analyze these input-output pairs to identify patterns in how the model reasons, what knowledge it contains, and how it handles different types of queries. Over time, this analysis builds a statistical approximation of the target model’s behavior, allowing the extracting party to train their own model to mimic the target’s responses without ever accessing the original model’s code, training data, or internal weights.

    US agencies characterize this as theft because it allows Chinese firms to skip the expensive research, data collection, and computational infrastructure required to develop frontier AI capabilities independently. Instead of investing billions in training runs and proprietary datasets, distillation enables Chinese companies to replicate US model capabilities at a fraction of the cost by parasitically exploiting the original developers’ work.

    US Agencies Claim Distillation Forms the Core of Chinese AI Development Strategy

    The joint advisory characterizes the extraction campaigns as forming the “core” of Chinese AI development strategy rather than isolated instances of intellectual property theft. The agencies assert that Chinese firms use distillation to achieve capability parity with US models while bypassing the research, computational, and data costs that US companies invested to develop those capabilities.

    Six Named Chinese AI Companies Targeted OpenAI, Anthropic, Google, and SpaceX

    The advisory specifically names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as conducting the extraction campaigns. The target models include OpenAI’s GPT family, Anthropic’s Claude, Google Gemini, and SpaceX’s Grok. The agencies describe the extraction volume as reaching billions of tokens, indicating sustained, large-scale querying operations rather than casual API usage.

    National Security and Intellectual Property Implications

    US AI companies’ proprietary models and training data face compromise through the systematic extraction campaigns, potentially enabling Chinese AI firms to achieve capability parity without equivalent research and development investment. The agencies warn that this capability proliferation to adversary nations carries national security implications, particularly as AI systems are applied to military, intelligence, and critical infrastructure domains.

    The NSA, CISA, and FBI jointly published the advisory, signaling that the extraction campaigns are viewed as a national security threat rather than purely a commercial intellectual property dispute. The involvement of intelligence and cybersecurity agencies, rather than trade enforcement bodies alone, indicates concern about how copied AI capabilities might be applied to military or intelligence operations against US interests.

    The named Chinese companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — represent both major technology conglomerates like Alibaba and specialized AI startups. The breadth of companies involved suggests distillation is a widely adopted strategy across the Chinese AI sector rather than isolated behavior by a few aggressive firms.

    The advisory urges AI providers to implement rate limiting, fingerprinting, and anomaly detection systems to identify distillation attempts. Defensive measures include monitoring for unusually high query volumes from single sources, detecting patterns consistent with systematic capability probing, and analyzing query content for signs of reverse-engineering attempts.

    The agencies did not announce enforcement action against the named Chinese companies. The advisory functions as a warning to US AI providers and a public attribution of the extraction campaigns to specific Chinese entities, leaving defensive implementation to individual companies rather than imposing regulatory requirements or sanctions.

    Related Posts