news.mlab.sh
Back to the feed
threat-intel

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

High
Summary

U.S. cybersecurity agencies have issued a joint advisory accusing Chinese AI firms of systematically extracting proprietary capabilities from American frontier AI models through a process called "distillation." These firms, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, are using various methods – APIs, cloud providers, and proxies – to bypass restrictions and train their own models, often with the blessing of the Chinese government. The agencies recommend enhanced detection and mitigation measures to combat these widespread and sophisticated attacks, highlighting the potential for misuse of model access and broader security risks.

The National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) have jointly warned about a concerning trend: Chinese artificial intelligence (AI) companies are aggressively extracting proprietary functionalities and capabilities from U.S. frontier AI models through a process known as "distillation." This activity is occurring at an industrial scale and is considered a core part of China-based AI firms’ development strategy.

These companies, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, are circumventing geographic restrictions and terms of use by utilizing various methods to gain unauthorized access to models like Claude, GPT, Gemini, and Grok. They achieve this through APIs, remote cloud providers, and a gray market of proxies hosted on platforms like Taobao and Xianyu.

Specifically, DeepSeek has conducted campaigns targeting reasoning capabilities, while Moonshot AI and MiniMax have extracted data from Claude and Gemini to improve their own models. Alibaba is distilling Claude-4, Claude Opus, and GPT-5, and StepFun is extracting data from Claude Opus 4.1 and 4.5, among others. Z.AI is developing CoT reasoning capabilities using GPT-5.5 and Claude Opus 4.8 data.

To obscure their operations and evade detection, these companies distribute their activities across multiple providers and platforms, focusing on distilling the most valuable features of each U.S. model. The agencies emphasize that this is not a new issue, with Anthropic previously identifying similar campaigns involving these same companies. Google Threat Intelligence Group has also recently observed a spike in distillation campaigns targeting Google’s AI models.

To combat this threat, the agencies recommend that U.S. AI companies implement comprehensive detection and mitigation measures, subtly alter responses to suspected malicious distillation attempts, and correlate activity across model providers, cloud platforms, and API aggregators. Ismael Valenzuela, vice president of Labs, Threat Research and Intelligence at Arctic Wolf, notes that this represents a sophisticated form of abuse of legitimate access, requiring a coordinated response due to the potential for misuse of model access and broader security risks, including influence campaigns and autonomous tooling.

Read the full article at The Hacker News