US Agencies Warn of Systematic AI Intelligence Extraction by China
Share
The NSA, CISA and FBI have warned that Chinese AI companies are employing distillation attacks to systematically extract intelligence from US frontier AI models. This process involves capturing model outputs and reasoning processes to train alternative models, effectively capturing the capabilities of US-developed technology.
Intelligence agencies identified several Chinese-based organisations involved in these activities, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. Since at least late 2024, these entities have allegedly extracted billions of tokens through millions of individual exchanges with prominent US models, including variants of Claude, GPT, Gemini, and Grok.
The agencies noted that between late 2024 and mid-2025, DeepSeek specifically used distilled data from Claude, Gemini, GPT-4, GPT-5, and Grok 4 to train its R1 and V3 models. The extracted knowledge included API rule-driven tasks, agentic functions, and optimisation for supervised fine-tuning and creative writing. Moonshot AI conducted similar large-scale operations to improve its Kimi-K3 and Kimi-K2 models using data from Claude and GPT-4o.
Strategic Economic and National Security Threats
The intelligence community has categorised these activities as a planned, well-resourced national-level action rather than opportunistic exploitation. The tactics used by these organisations include sophisticated methods to evade regional restrictions and subscription limits, centralised request routing infrastructure, and automated metadata sanitisation to hide the origin of the requests.
The impact of these campaigns extends beyond intellectual property theft. The agencies warned that such extraction represents a strategic economic threat to fair technological competition and undermines US technological leadership. While the threat is not directed at individual enterprise AI use, it poses a significant risk to the broader US economy and national security.
To mitigate these risks, the agencies recommend a coordinated defence across the AI ecosystem, involving cloud providers, API aggregators, and infrastructure providers. Suggested defensive actions include:
- Behavioural detection and monitoring: Identifying patterns and metadata characteristics associated with malicious distillation requests.
- Differential privacy: Implementing calibrated noise in model outputs to prevent actors from reconstructing sensitive training data or decision boundaries.
- Targeted response degradation: Making changes to model responses in response to high-confidence malicious requests to increase the cost of distillation campaigns.
- Information sharing: Correlating activity across multiple sources to improve attribution and justify response actions with minimal risk to legitimate users.
The agencies stressed that effective defence requires multi-source correlated activity to allow for confident attribution of these campaigns while maintaining service for legitimate users.




Leave a Reply