US Accuses Six Chinese Firms of Using AI Distillation

NSA, FBI and CISA say six Chinese AI firms used distillation since at least 2024 to extract capabilities from US frontier models, naming DeepSeek, Moonshot and Alibaba.

US security agencies have accused six Chinese artificial intelligence firms of using a technical process called distillation to extract capabilities from US frontier models. The National Security Agency, the FBI and the Cybersecurity and Infrastructure Security Agency identified DeepSeek, Moonshot, Alibaba Group Holding, MiniMax, StepFun and Z.AI and said the activity began at least in 2024.

According to the agencies, the companies used large volumes of interactions with US models and routed requests through multiple pathways to bypass access controls and platform terms of use. The agencies described the campaigns as industrial-scale efforts to reproduce restricted functions of American systems.

Distillation transfers some behavior from a large, complex “teacher” model to a smaller “student” model by using the teacher’s outputs as training examples. Developers can feed many prompts to a powerful model, collect its replies and train a new model to mimic those responses. The technique was formalized in 2015 and is commonly used to make models cheaper and faster to run.

The agencies warned that unauthorized distillation can reproduce proprietary capabilities without the same investment in computing and research. Companies that build frontier models told US officials they detected extraction campaigns involving millions of exchanges. One firm reported roughly 16 million interactions and about 24,000 fake accounts in operations targeting its chatbot, with a single extractor accounting for more than 13 million of those exchanges. Other firms reported similar probe activity earlier in the year.

The advisory linked industrial-scale extraction to security concerns. The agencies wrote that faster, lower-cost access to advanced AI capabilities could accelerate development of tools for military, intelligence, surveillance and cyber operations. An analysis of Chinese-language procurement requests found the People’s Liberation Army seeking AI tools for decision support, sensor enhancement, data fusion and technologies aimed at countering perceived US advantages in space and maritime systems.

Beijing rejected the accusations. Foreign Ministry spokeswoman Mao Ning urged Washington not to make unfounded charges and described China’s AI progress as driven by self-reliance and international cooperation. A Chinese government statement in July said domestic models had achieved strong capabilities independently and accused the United States of applying a double standard because US firms also use distillation in research.

The US government has begun coordinating responses with industry. An Office of Science and Technology Policy memorandum in April directed agencies to share intelligence with domestic AI companies, help coordinate industry responses and explore accountability options. Lawmakers advanced the Deterring American AI Model Theft Act in the House Foreign Affairs Committee in April. The agencies advising developers recommended immediate steps such as altering model responses to suspected malicious probes and sharing information about extraction campaigns.

Security researchers note that distillation is a routine technique for making large models practical for specific uses. Pukar Hamal, founder of an AI security firm, offered an analogy: ‘It’s almost like someone went to the lectures, read the textbook, and did all the hard work of doing the homework.’

Industry and policymakers face questions about authorization, intellectual property and how to prevent unauthorized extraction of capabilities while allowing legitimate research and open-source work to continue.

Articles by this author