US Warns Chinese AI Firms Are Illicitly Distilling Models #AI


Artificial Intelligence & Machine Learning
,
Governance & Risk Management
,
Next-Generation Technologies & Secure Development

CISA Says DeepSeek, Alibaba and Others Extracted Billions of Tokens From US Frontier AI Systems

Image: Shutterstock

The U.S. government warned that Chinese companies are illicitly distilling American-made artificial intelligence models, formally acknowledging complaints from frontier labs like Anthropic and OpenAI.

See Also: How Skilled Attackers Weaponize AI Faster

The Cybersecurity and Infrastructure Security Agency, the NSA and the FBI published Tuesday an advisory urging organizations to improve monitoring, response and information sharing on suspected distillation. The alert named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.ai.

Those companies extracted “billions of tokens across millions of exchanges/requests from U.S. frontier models,” the advisory said, tapped variants of Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini and xAI’s Grok models to teach their systems how to respond to prompts.

Despite the advisory, the Trump administration did not lay out potential consequences if it proves Chinese AI labs are illicitly distilling information from models created by American companies.

AI companies use distillation to train their models on other models’ responses so they can learn from a “teacher model” without being fed a large training dataset. This is a legitimate method, especially when developing a smaller-weight version of a large language model – although there is an unspoken rule that labs should inform other companies of their intentions. CISA said Chinese AI companies “are engaging in aggressive, malicious and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models.”

CISA said it believes extracting capabilities from AI models causes significant economic losses and undermines American competitive advantage.

“Likely with the knowledge of the Chinese government, the China-based AI sector has turned to a comprehensive distillation strategy in an attempt to bridge the technological and performance gaps between their AI models and U.S. frontier AI models,” CISA said.

CISA and the other agencies advised American AI companies to take three immediate actions to guard against illicit distillation, including implementing comprehensive detection and mitigation, deploying targeted response changes and establishing cross-organization intelligence sharing.

The agency said Chinese AI companies accessed American models through APIs and used proxies known as transfer stations to bypass geographic restrictions set by companies.

CISA said Chinese companies have been illicitly distilling American models since at least 2024. It said DeepSeek conducted the distillation campaign to train its R1 and V3 models.

The agency said Moonshot AI, which developed Kimi K3, tapped data from Claude Fable 5 for Kimi K3 and GPT 4o for Kimi K2, as well as other models across the American AI ecosystem. Fable 5 was one of the Anthropic models the company held back after the Trump administration exercised export controls against it.

Frontier AI labs have contended with what they consider to be illicit distillation for a while now. In June, Anthropic asked the U.S. government to impose export controls on Chinese labs after accusing Alibaba of training its Qwen models on Claude responses. This follows a February complaint, also by Anthropic, that DeepSeek, Moonshot AI and MiniMax had suspiciously large exchanges with Claude. OpenAI and Microsoft told the government in early 2025 that they believe DeepSeek used output from their GPT models to train its DeepSeek-R1 model, which took the AI world by storm when it offered similar capabilities at a much lower token cost.

Meta CEO Mark Zuckerberg defended distillation as a practice, saying embracing the method will help U.S. companies develop better, more capable open-source models.



Click Here For The Original Source.

——————————————————–

..........

.

.