Feds Accuse China of 'Systematic' Distillation of US AI Models 5
The NSA, CISA, and FBI are accusing (PDF) several Chinese AI companies of carrying out "industrial-scale" distillation campaigns against leading U.S. models such as ChatGPT, Claude, Gemini, and Grok. Since at least 2024, the companies have allegedly routed millions of requests across accounts, APIs, proxies, cloud providers, and third-party aggregators to extract capabilities for their own models. "China-based artificial intelligence companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies' models through industrial-scale knowledge distillation campaigns that form the core -- not merely a supplement -- of their AI development strategy," the agencies wrote. CyberScoop reports: DeepSeek, for example, distilled frontier U.S. models to generate synthetic training data for its R1 and R3 models, including four different versions of Claude, two versions of Gemini, five versions of ChatGPT and Grok 4. Those models helped train DeepSeek's capabilities in areas like agentic functioning, question and answer optimization, creative and occupational writing and others.
Another Chinese company, Moonshot AI, allegedly distilled 18 different U.S. models -- including Fable 5, Anthropic's current, most advanced commercially available model -- to train its Kimi-K2 and Kimi K3 models. The company used millions of queries meant to extract enhanced capabilities in areas like agentic reasoning, coding and data analysis, computer vision, larger logical frameworks, visual processing and others.
Chinese AI companies manage a sophisticated set of tools and systems that route requests and prompts through multiple pathways to avoid detection. The advisory lists common tactics observed by Chinese companies, including spreading requests across different accounts, models and platforms, using native APIs, remote cloud providers, and third-party aggregators to obfuscate user metadata, and leveraging proxies and gray tech markets to get around geographic restrictions, terms of use and safeguards built into frontier models.
Another Chinese company, Moonshot AI, allegedly distilled 18 different U.S. models -- including Fable 5, Anthropic's current, most advanced commercially available model -- to train its Kimi-K2 and Kimi K3 models. The company used millions of queries meant to extract enhanced capabilities in areas like agentic reasoning, coding and data analysis, computer vision, larger logical frameworks, visual processing and others.
Chinese AI companies manage a sophisticated set of tools and systems that route requests and prompts through multiple pathways to avoid detection. The advisory lists common tactics observed by Chinese companies, including spreading requests across different accounts, models and platforms, using native APIs, remote cloud providers, and third-party aggregators to obfuscate user metadata, and leveraging proxies and gray tech markets to get around geographic restrictions, terms of use and safeguards built into frontier models.