The US National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) have issued a joint warning stating that China-based AI companies are conducting large-scale "distillation" to extract knowledge from cutting-edge American AI models.

According to US authorities, Chinese companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.ai may have extracted billions of tokens through millions of requests targeting derivative models such as Claude, GPT, Gemini, and Grok since at least late 2024. The authorities pointed out that these activities violate the terms of service of the respective companies and undermine the technical superiority of the United States.

Furthermore, it was revealed that Chinese companies have been accessing APIs while bypassing regional restrictions by utilizing a gray market of proxies known as "transfer stations." Evidence has also been confirmed that attack methods, such as prompt injection, are being used to extract the Chain-of-Thought (CoT) of the models.

In response, US authorities are recommending that American AI companies implement measures such as monitoring for abnormal usage patterns and subtly altering response content to reduce the utility of distillation attempts.


Source: