Download Privacy Needle App

Type to search

Cybersecurity

US Agencies Warn of Systematic AI Intelligence Extraction by China

Share

The NSA, CISA and FBI have warned that Chinese AI companies are employing distillation attacks to systematically extract intelligence from US frontier AI models. This process involves capturing model outputs and reasoning processes to train alternative models, effectively capturing the capabilities of US-developed technology.

Intelligence agencies identified several Chinese-based organisations involved in these activities, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. Since at least late 2024, these entities have allegedly extracted billions of tokens through millions of individual exchanges with prominent US models, including variants of Claude, GPT, Gemini, and Grok.

The agencies noted that between late 2024 and mid-2025, DeepSeek specifically used distilled data from Claude, Gemini, GPT-4, GPT-5, and Grok 4 to train its R1 and V3 models. The extracted knowledge included API rule-driven tasks, agentic functions, and optimisation for supervised fine-tuning and creative writing. Moonshot AI conducted similar large-scale operations to improve its Kimi-K3 and Kimi-K2 models using data from Claude and GPT-4o.

Strategic Economic and National Security Threats

The intelligence community has categorised these activities as a planned, well-resourced national-level action rather than opportunistic exploitation. The tactics used by these organisations include sophisticated methods to evade regional restrictions and subscription limits, centralised request routing infrastructure, and automated metadata sanitisation to hide the origin of the requests.

The impact of these campaigns extends beyond intellectual property theft. The agencies warned that such extraction represents a strategic economic threat to fair technological competition and undermines US technological leadership. While the threat is not directed at individual enterprise AI use, it poses a significant risk to the broader US economy and national security.

To mitigate these risks, the agencies recommend a coordinated defence across the AI ecosystem, involving cloud providers, API aggregators, and infrastructure providers. Suggested defensive actions include:

  • Behavioural detection and monitoring: Identifying patterns and metadata characteristics associated with malicious distillation requests.
  • Differential privacy: Implementing calibrated noise in model outputs to prevent actors from reconstructing sensitive training data or decision boundaries.
  • Targeted response degradation: Making changes to model responses in response to high-confidence malicious requests to increase the cost of distillation campaigns.
  • Information sharing: Correlating activity across multiple sources to improve attribution and justify response actions with minimal risk to legitimate users.

The agencies stressed that effective defence requires multi-source correlated activity to allow for confident attribution of these campaigns while maintaining service for legitimate users.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.