news.mlab.sh
Back to the feed
threat-intel

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

High
Summary

The NSA, CISA, and FBI have issued a warning that Chinese AI companies are systematically extracting capabilities from leading U.S. frontier AI models, including Claude, GPT, Gemini, and Grok. This industrial-scale knowledge distillation is intended to bolster China’s AI development and represents a significant strategic economic threat to U.S. technological leadership. Agencies are urging the broader AI ecosystem to implement defensive measures and suggest targeted responses to disrupt these campaigns.

The National Security Agency (NSA), CISA (Cybersecurity and Infrastructure Security Agency), and FBI have jointly warned that Chinese AI companies are engaged in a systematic effort to steal advanced capabilities from U.S. frontier AI models. According to the agencies’ report, companies like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been extracting billions of tokens from models including Claude, GPT, Gemini, and Grok since late 2024. This process, known as ‘knowledge distillation,’ is not simply improving Chinese AI models; it directly undermines U.S. technological leadership and poses a strategic economic threat.

The agencies detailed how Chinese companies are leveraging novel techniques beyond the MITRE ATLAS framework, including regional restriction evasion and subscription exploitation, as well as centralized request routing and automated metadata sanitization. They also emphasized that this is a planned and well-resourced national-level action, not opportunistic exploitation.

Mitigations are being recommended across the entire U.S. AI ecosystem, including cloud providers, API aggregators, and infrastructure providers. These include behavioral detection and monitoring, as well as more aggressive responses such as targeted changes in response to high-confidence malicious distillation requests. Sharing information about these campaigns is also encouraged to improve attribution and justify response degradation with minimal risk to legitimate users.

Furthermore, the agencies suggest implementing differential privacy by adding calibrated noise to model outputs, preventing malicious actors from extracting training data membership information and other sensitive model details. The primary goal of this report is to alert all AI stakeholders to this ongoing and substantial threat to U.S. technological dominance and economic competitiveness.

Read the full article at SecurityWeek