China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies
China-based artificial intelligence companies are conducting large-scale, systematic knowledge distillation campaigns against U.S. AI companies to rapidly improve their own AI models. These campaigns involve extracting proprietary functionalities and capabilities from leading U.S. models like Claude, GPT-4, and Gemini, using techniques such as bypassing regional restrictions and utilizing proxy networks. The campaigns are driven by a strategic goal of bridging the technological gap between Chinese and U.S. AI, with significant investment and operational maturity demonstrated by these companies. The U.S. government is issuing a cybersecurity advisory and recommending immediate actions for U.S. AI companies to detect and mitigate these threats.
The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) have jointly released a Cybersecurity Advisory warning of systematic knowledge distillation campaigns being conducted by China-based artificial intelligence (AI) companies against U.S. AI models. These campaigns represent a strategic effort to rapidly improve Chinese AI capabilities by extracting proprietary functionalities and reasoning capabilities from U.S. frontier AI models, including Claude, GPT-4, and Gemini. Since late 2024, companies like DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been systematically extracting billions of tokens across millions of exchanges/requests.
China-based AI companies employ sophisticated techniques to bypass restrictions and maximize efficiency. They use a gray market of API proxies known as ‘transfer stations’ to circumvent regional restrictions and evade safeguards. They also structure access around pools of accounts with employees running multiple concurrent sessions to prevent quota depletion. These campaigns are driven by a strategic goal of bridging the technological and performance gap between Chinese and U.S. AI models, with significant investment and operational maturity demonstrated by these companies.
DeepSeek, for example, has been conducting an organized distillation campaign since late 2024, targeting specific knowledge domains to reduce its compute and research costs. They extracted data from models like Claude 3.7, Claude Sonnet 4, and Gemini 2.5 Pro Preview. Moonshot AI has similarly extracted data from Claude Opus 4.1, Claude Sonnet 3.7, and GPT-4o. Other companies, including Alibaba, MiniMax, and StepFun, have leveraged distillation to improve their AI models’ software engineering skills, customer service dialogue functionality, and integration of RL, SFT, and distillation capabilities.
These campaigns involve a range of advanced tactics, including regional restriction evasion, subscription exploitation, and automated metadata sanitization. China-based AI companies use centralized request routing infrastructure to manage and scale these operations, ensuring efficient data extraction and minimizing operational costs. The U.S. government recommends that U.S. AI companies take immediate action, including implementing comprehensive detection and mitigation, deploying targeted response changes, and establishing cross-organization intelligence sharing to combat these threats effectively.