Skip to content
News

US Names Six Chinese AI Firms Over Model Distillation Claims

US Names Six Chinese AI Firms Over Model Distillation Claims - Chinese AI model distillation
US agencies name six Chinese AI firms, including DeepSeek and Alibaba, accused of industrial-scale distillation of American frontier models since late

The United States has named six Chinese artificial intelligence firms accused of conducting industrial-scale efforts to distil the capabilities of American frontier AI models, potentially saving billions in Chinese development costs.

In a joint release, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation alleged that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI had been targeting US models since at least late 2024. The agencies said the firms had “likely” acted with “Chinese government awareness” while extracting capabilities from US systems, including variants of Claude, GPT, Gemini and Grok.

According to the agencies, China-based companies carrying out industrial-scale distillation against American AI models benefit from significantly shorter development timelines and reduced financial expenditure when training a frontier model. They called on all American AI firms to work alongside the government and US allies to halt the alleged theft, which they described as a threat to the country’s lead in the AI race.

How the alleged attacks were carried out

The agencies outlined several methods said to be in use. One involved exploiting AI model inference APIs by bulk-buying fraudulent accounts not registered to legitimate users. These accounts were said to execute highly coordinated queries featuring identical or similar prompt texts, ranging from thousands to millions on similar topics.

A second method involved prompt injection techniques used to jailbreak models, including prompts designed to force systems to reveal their hidden chain-of-thought reasoning. As an example, the agencies said DeepSeek used prompts instructing models to imagine and articulate the internal reasoning behind completed responses and to write it out step by step.

The agencies indicated that such campaigns span days to months, with query volumes reaching thousands to millions per domain, far exceeding what would be expected from legitimate research or development activity.

Recommended mitigations for US firms

To help companies act together, the agencies set out measures intended to make theft from American models more difficult. First, AI firms were urged to improve detection of sophisticated campaigns said to use tens of thousands of accounts drawing on a grey market of proxies to evade geographical restrictions and route distillation requests through multiple pathways for unauthorised access.

More broadly, the agencies recommended increased monitoring for anomalous and malicious prompts, accounts, networks and behaviours. Because Chinese firms are said to rely on bulk procurement of premium subscriptions shared across teams of developers, that effort should also include flagging accounts with suspicious subscription-to-usage ratios, as well as new accounts that immediately reach maximum usage. Both patterns were described as indicators of bulk deployment using pre-engineered templates.

US firms were also advised to strengthen identity verification of users and to track individual account activity more closely. The agencies acknowledged that such fixes could affect legitimate AI users in the United States.

The six named firms are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.

Source
Image: arstechnica.com

The UK tech briefing

Smartphones, AI, computing and deals — the essential stories without the noise.

Mailing provider can be connected when your UK list is ready.

Shop on Amazon UK — Discover deals Shop on Amazon UK — Discover deals