NSA, CISA, and FBI accuse six Chinese AI firms of industrial-scale distillation of US models

The NSA, CISA, and FBI published a joint cybersecurity advisory this week accusing six Chinese AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — of running “aggressive, malicious, and targeted” distillation campaigns against US frontier AI models since at least late 2024, extracting billions of tokens across millions of requests.
What Distillation Is, and Why It's Controversial Here
Distillation — training a smaller, cheaper model on the outputs of a larger one — is a legitimate and widely used technique across the AI industry. But doing so against a rival's paid API at industrial scale typically violates terms of service, and can let a company approximate a competitor's capabilities without bearing the underlying research cost. The advisory specifically calls into question DeepSeek's widely cited $5.6 million training-cost claim, arguing the figure doesn't reflect resources spent on distillation from rival models.
Which Companies Targeted Which Models
According to the advisory, DeepSeek targeted Claude (3.7, Sonnet 4/4.5, Opus 4.1), Gemini 2.5, GPT-4/4o/5, and Grok 4 to train its R1 and V3 models. Moonshot AI extracted Claude Opus, Sonnet, and Fable data along with GPT-3/4o/5 outputs to train Kimi-K2 and Kimi-K3. Alibaba distilled Claude 4/Sonnet and GPT-5 for its Qwen model family. MiniMax, StepFun, and Z.AI targeted a similar mix of Claude, Gemini, and GPT models for their respective systems.
Recommended Countermeasures
The agencies recommend AI companies monitor subscription-to-usage ratios and sudden maximum-usage patterns from newly created accounts, “subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs,” and share activity data across providers to reveal coordinated campaigns that no single company could detect alone.
Implications
The advisory formalizes allegations AI labs have made informally for over a year, and puts US intelligence agencies directly in the middle of the broader AI competitiveness contest with China. It could accelerate technical countermeasures — rate limiting, output watermarking, behavioral fingerprinting — across US model providers, and adds a national-security framing to a dispute that has mostly played out as commercial terms-of-service violations until now.
Source: CISA, CyberScoop
Originally reported by CISA. Read the original article for additional details.
View original source