Skip to main content
Emerging Threats

China Exploits US AI Models with Aggressive Distillation Tactics

Server room interior with rows of equipment and a central workstation.

“China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use,” the National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation said in a joint advisory.

NSA, CISA and FBI: a joint advisory on model theft

The agencies issued a joint advisory warning that China-based firms have employed “aggressive, malicious, and targeted distillation” campaigns to extract proprietary capabilities from U.S. frontier AI models. The advisory names six China-based companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI — and says those firms have extracted “billions of tokens from the exchanges within U.S. frontier AI models” since 2024. The advisory adds that these efforts were carried out “likely with Chinese government awareness.”

Distillation: the tactic and the pathways cited

The advisory describes distillation as a technique “used to reduce the time and money needed to create a new model.” According to the agencies, the accused companies conduct distillation by querying advanced U.S. models using simpler models, then capturing the outputs to train their own systems. To evade detection, the advisory says, they route distillation requests “through multiple pathways,” including native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that “automatically obfuscate user metadata to avoid detection.” The agencies say operators deliberately distribute activity across providers and platforms “to avoid single-point detection.”

Targets: Claude, ChatGPT, Gemini, and Grok (and allegations against Moonshot AI)

The advisory identifies the specific U.S. frontier models targeted: variants of Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini, and SpaceXAI’s Grok. Separately, the White House Office of Science and Technology Director Michael Kratsios is quoted as saying in July that Moonshot AI’s distillation efforts sought to steal proprietary functions from Anthropic’s advanced Fable model. Anthropic itself made the same accusations in February, according to the advisory and related comments included in the public record.

Recommended mitigations for U.S. AI developers

The three U.S. agencies set out three discrete recommendations for developers of U.S. models:

  • Implement comprehensive detection and mitigation — increase monitoring for distillation-pattern queries, and deploy technical measures aimed at identifying model-extraction activity.
  • Deploy targeted response changes — adapt access controls, rate limits, or API behavior where appropriate to slow or stop extraction attempts.
  • Establish cross-organization intelligence sharing — coordinate among firms and with government entities to surface and respond to distributed, multi-provider campaigns.

The advisory frames these steps as a combined operational response to “systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership.”

How technologists, policymakers, and U.S. vendors are responding

  • Technologists and security teams: The advisory urges detection and mitigation — in practice that means monitoring for coordinated, high-volume querying routed through aggregators or cloud providers and adjusting API or service responses when patterns match distillation behavior.
  • Policymakers and regulators: The advisory and related public comments prompted advocacy groups to press the White House for stronger action, including requests to restrict Chinese companies’ ability to import advanced semiconductor chips.
  • U.S. AI vendors and procurement leaders: The agencies’ characterization that terms of use were violated by routing requests through obfuscated pathways underscores a near-term imperative to tighten contractual and technical controls around access to frontier models.

The advisory paints a picture of deliberate, distributed campaigns that aim to combine the strengths of multiple U.S. models while avoiding detection. It names companies, methods, targets, and a three-part defensive prescription — and it closes by linking the technical problem to policy pressure, noting advocacy requests to the White House regarding semiconductor imports. The central, open question the advisory leaves for industry and government is whether tighter detection, coordinated sharing, and potential trade or export measures will be sufficient to stem extraction efforts that the agencies say have already harvested “billions of tokens.”

Original reporting