ZeroHour
Story · 1 source · 1 articlefirst updated ()

NSA, CISA, and FBI Accuse Six Chinese AI Firms of Industrial-Scale Distillation of US Frontier Models

mediumAI safety & securityexploited in the wildimportance 78
What's new: This is the first merged summary of the story: US agencies (NSA, CISA, and FBI) have publicly issued a joint advisory accusing named Chinese AI firms of industrial-scale distillation of US frontier models and urging coordinated defensive countermeasures across the US AI ecosystem.
Merged summary · glm-5.3-flash · rewritten as coverage arrives

A joint NSA, CISA, and FBI advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as having covertly extracted capabilities from US frontier models, including Claude, GPT, Gemini, and Grok, since at least late 2024, via fraudulent accounts,…

A joint advisory from the NSA, CISA, and FBI accuses six Chinese AI firms — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — of industrial-scale distillation of US frontier models, including Claude, GPT, Gemini, and Grok, dating back to at least late 2024, likely with Chinese government awareness. Dark Reading reports that billions of tokens were allegedly extracted to shortcut the firms' own model development costs; Ars Technica adds that the agencies say distillation shortens Chinese development timelines and cuts frontier training costs. Alleged tactics include bulk procurement of premium subscriptions using fraudulent accounts, proxy routing to evade geo-restrictions, and prompt injection designed to force models to reveal hidden chain-of-thought reasoning. The agencies recommend stronger identity verification, monitoring of anomalous usage, and quietly downgrading or adding noise to responses for suspected distillers, while warning that these mitigations could frustrate legitimate users. The US government is pushing coordinated defenses across the AI ecosystem.

  • Six Chinese firms named: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
  • Targeted US frontier models are described slightly differently by the sources: Dark Reading lists OpenAI, Anthropic, Google Gemini, and Grok; Ars Technica lists Claude, GPT, Gemini, and Grok.
  • The alleged extraction has occurred since at least late 2024 and was likely conducted with Chinese government awareness.
  • Dark Reading reports billions of tokens were allegedly extracted to reduce Chinese model development costs; the agencies say distillation shortens development timelines and cuts frontier training costs.
  • Alleged methods include bulk procurement of premium subscriptions with fraudulent accounts, proxy routing to evade geo-restrictions, and prompt injection to extract hidden chain-of-thought reasoning.
  • Recommended mitigations: stronger identity verification, detection of anomalous usage, and silent downgrading or noise added to responses for suspected distillers, with an acknowledged risk of frustrating legitimate users.

Coverage timeline

  1. · 7d ago
    Dark Reading· 72
    US Government Accuses Chinese AI Firms of Distilling Frontier Models

    US agencies allege Chinese AI firms covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and Grok models to cut development costs.