US Intelligence Agencies Warn of China-Based AI Model Distillation

Serdar HocamAuthor & Editor

National security agencies have announced that Chinese AI companies are running malicious distillation campaigns targeting US models.

◉ 1 views
Intelligence agencies warn of China’s large-scale AI model distillation efforts

U.S. national security and intelligence agencies have issued a joint warning that Chinese artificial intelligence companies are conducting malicious model distillation campaigns to extract proprietary capabilities from American frontier models.

Details of the Joint Intelligence Warning

Three federal national security and intelligence agencies warned U.S. AI developers that they are being targeted by model distillation campaigns from Chinese counterparts. In this process, a model aims to learn from a larger and more advanced model by sending queries to it.

Targeted Chinese Companies and Tactics

The National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation stated that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been employing aggressive and targeted tactics. These companies have extracted billions of tokens from interactions within U.S. frontier models since 2024.

Obfuscation Methods and Terms of Service Violations

It was stated that China-based AI companies routed distillation requests through multiple pathways to gain unauthorized access and violated terms of service. These pathways include native application programming interfaces, remote cloud providers, and third-party aggregators that mask user metadata.

Targeted Leading American Models

Variants of Anthropic's Claude, OpenAI's ChatGPT, Google's Gemini, and xAI's Grok were listed among the targeted systems. While AI distillation is a legitimate technique to lower training costs, malicious firms can use it to misappropriate intellectual property.

Threat to U.S. Technological Leadership

It was reported that Chinese firms distributed operations to prevent single-point detection and sought to use the best features of U.S. frontier models to train their own systems. This situation poses a systematic threat to America's technological leadership.

Recommended Mitigation Steps for Developers

Authorized agencies recommended three key improvement steps for U.S. AI developers: implementing comprehensive detection and mitigation measures, deploying targeted response variations, and establishing cross-organizational intelligence sharing.

White House and Industry Reactions

White House Office of Science and Technology Policy Director Michael Kratsios criticized China's distillation efforts in July. Additionally, advocacy groups called on the White House to ban the sale of AI system components and semiconductor chips to China.