China AI firms accused of mass model distillation
CISA, NSA, and FBI say DeepSeek, Alibaba, Moonshot AI and others systematically extracted proprietary data from U.S. frontier AI models via industrial-scale distillation.
NSA, CISA, and FBI issued a joint advisory alleging that multiple China-based AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—have conducted industrial-scale knowledge distillation campaigns against U.S. frontier AI models (Claude, GPT, Gemini, Grok variants) since at least late 2024. The advisory characterizes this activity as extending beyond legitimate distillation research into systematic extraction of proprietary functionality, reasoning capabilities, and domain-specific optimizations, violating U.S. AI companies' terms of use. The agencies assess this is likely conducted with Chinese government awareness and represents a core strategy—not a supplement—for closing the capability gap with U.S. models while reducing training costs and timelines.
The advisory details TTPs mapped to the MITRE ATLAS framework plus four novel techniques not yet catalogued: regional restriction/subscription evasion via bulk premium account procurement, centralized request-routing infrastructure spanning native APIs/cloud providers/third-party aggregators/"transfer station" proxies, automated metadata sanitization to strip organizational identifiers, and systematic quota/cost optimization. Detection indicators include shared accounts across multiple IPs/user agents, 24/7 sustained usage without human variation, anomalous subscription-to-API usage ratios, and new accounts hitting maximum usage immediately rather than ramping gradually.
Recommended mitigations for U.S. AI companies include behavioral detection and monitoring of subscription/usage patterns, targeted response degradation (differential privacy, downgraded model responses) for suspected malicious distillation traffic without alerting the requester, and cross-organization intelligence sharing of infrastructure and behavioral indicators to reveal distributed campaigns that appear isolated to any single provider. The advisory also references NIST AI 100-2e2025 mitigations such as differential privacy, pre/post-training interventions, and prompt formatting controls.
Mentioned in this report
Source reporting: https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free