English

SecurityAnthropic

China-based AI firms accused of industrial-scale knowledge distillation and unauthorized data routing

Anthropic and U.S. security agencies have detailed widespread campaigns by China-based AI companies to extract proprietary capabilities from frontier models through industrial-scale knowledge distillation—a technique used to transfer the behavior of a large model to a smaller one.

In a September 2026 threat intelligence report, Anthropic identified that Moonshot AI, the developer of Kimi, allegedly routed customer requests to Anthropic's Claude model without user knowledge. Anthropic claims that approximately 300,000 requests, primarily for Claude Opus, were redirected through proxy networks to extract reasoning patterns and conversational data. This process potentially exposes sensitive user data, including communications from Chinese government and military-linked users, to unauthorized infrastructure.

Simultaneously, a joint cybersecurity advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the FBI, and the NSA warned that several Chinese AI companies—including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—have been conducting systematic extraction of proprietary functionalities from U.S. frontier models, such as Claude, GPT, Gemini, and Grok, since at least late 2024.

The agencies stated that these companies use knowledge distillation as a critical core of their AI development strategy, allowing them to significantly reduce development timelines and research costs. To evade detection and bypass geographic restrictions, these companies utilize multiple pathways, including native APIs, remote cloud providers, and "transfer stations"—a gray market of API proxies used to obfuscate user metadata.

DeepSeek has been conducting organized campaigns since at least 2024 targeting reasoning capabilities to train its R1 and V3 models. Alibaba has also leveraged these methods to improve its Qwen family of models. In response to these threats, U.S. agencies recommended that AI developers implement stricter identity verification and technical mitigations, such as varying response depth or employing differential privacy, to increase the difficulty of malicious distillation campaigns.

Sources

  1. 中国当局がKimiやDeepSeek調査 AnthropicのAIに機密情報転送疑い - 日本経済新聞 (編集部依頼: 中国当局がKimiとDeepSeekを機密漏洩疑いで調査開始。Anthropicの報告書により、ユーザー要求をClaudeへ転送し監視データや機密情報を収集していた疑いが浮上。CISAも産業規模の蒸留キャンペーンを非難。, 日付不明)
  2. Anthropic、MoonshotのKimiがユーザー要求をClaudeへ転送し監視データが流出したと告発 - AlphaMatch (編集部依頼: 中国当局がKimiとDeepSeekを機密漏洩疑いで調査開始。Anthropicの報告書により、ユーザー要求をClaudeへ転送し監視データや機密情報を収集していた疑いが浮上。CISAも産業規模の蒸留キャンペーンを非難。, 日付不明)
2 more sourcesHide sources
  1. Anthropic Threat Intelligence Report
  2. China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies | CISA (編集部依頼: 中国当局がKimiとDeepSeekを機密漏洩疑いで調査開始。Anthropicの報告書により、ユーザー要求をClaudeへ転送し監視データや機密情報を収集していた疑いが浮上。CISAも産業規模の蒸留キャンペーンを非難。, 日付不明)