US Agencies Identify Large-Scale AI Distillation Attacks by Chinese Firms
Share
US cybersecurity and intelligence agencies have identified six Chinese artificial intelligence firms conducting industrial-scale distillation attacks against American frontier AI models.
A joint advisory from the Cybersecurity and Infrastructure Security Agency (CISA), the National Security Agency (NSA), and the FBI states that the operations have been ongoing since at least late 2024. The agencies allege that companies including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have extracted billions of tokens through millions of requests directed at models from Anthropic, OpenAI, Google, and xAI.
Industrial-Scale Data Extraction
AI model distillation is a technique where a “student” model learns from the outputs of a highly trained “teacher” model. While used legitimately by researchers to reduce training costs and deployment times, these firms are allegedly abusing API access to extract the underlying logic and knowledge of powerful models.
The agencies assess that the scale and sophistication of these operations suggest Chinese government awareness, noting that this approach likely serves as a core development strategy for the offending firms. By leveraging extracted knowledge, these companies can significantly shorten AI development timelines and reduce the massive financial expenditures typically required to train frontier models.
The advisory identified specific targeting patterns. DeepSeek and Moonshot AI were noted as primary offenders targeting multiple models including Claude, GPT, Gemini, and Grok. MiniMax was also accused of targeting Claude, Gemini, and GPT models, while Z.AI allegedly targeted GPT-5.5 and Claude Opus 4.8.
Sophisticated Evasion Tactics
To bypass geographic restrictions, usage limits, and detection mechanisms, the Chinese firms reportedly distribute API requests across fraudulent or shared accounts, cloud services, aggregators, and “transfer station” proxies.
The attacks involve advanced tactics such as extracting chain-of-thought (CoT) reasoning and using automated systems to switch providers if a defender attempts to block a specific pathway. These systems include sophisticated quality evaluation frameworks designed to detect and circumvent defensive countermeasures.
CISA and its partners recommend that AI developers improve behavioural and infrastructure-level detection. Recommended mitigations include modifying model responses when distillation operations are suspected and sharing intelligence regarding these campaigns with industry stakeholders. Potential indicators of such attacks include new accounts reaching maximum usage immediately, continuous activity without normal human idle periods, and identical prompts being used across multiple providers.




Leave a Reply