Chinese AI Distillation Advisory Accuses Six Firms, Maps Proxy Networks
Chinese AI distillation is the focus of a new joint U.S. cybersecurity advisory accusing six companies of systematically extracting capabilities from leading American models. The document says the campaigns consumed billions of tokens through millions of requests and used layered access routes designed to evade restrictions and scrutiny.
The advisory identifies three immediate priorities for model providers:
- Detect anomalous prompts, accounts, networks and usage patterns.
- Reduce the value of suspected malicious extraction attempts.
- Share threat intelligence across providers, clouds and API platforms.
Chinese AI Distillation Advisory Names Six Companies
The 18-page advisory, released September 8 by the National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation, names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It describes the activity as industrial-scale knowledge distillation aimed at reproducing proprietary model functionality.
Distillation itself is a standard model-development technique: a smaller model learns from outputs produced by a more capable one. The agencies draw a line between legitimate uses and campaigns that allegedly violate access rules, conceal their origin and target restricted capabilities at a scale intended to shorten development cycles.
The advisory says the six companies have, since at least late 2024, targeted variants of Anthropic’s Claude, OpenAI’s GPT, Google’s Gemini and xAI’s Grok. Those are allegations from U.S. intelligence and law-enforcement agencies, not findings issued after a public trial or regulatory proceeding.
Reuters reported that the Chinese Embassy in Washington did not immediately comment. The accusation also arrives during a broader technology dispute over advanced chips, model access and export controls, raising the prospect that model extraction will become another point of friction between Washington and Beijing.
How Transfer Stations Hid Model-Extraction Traffic
According to the advisory, the campaigns did not rely on a single route. Operators allegedly combined native model APIs, remote cloud infrastructure, third-party aggregators and gray-market intermediaries described as transfer stations. That architecture could obscure the ultimate customer and provide alternate paths when one account, network or provider was blocked.
The agencies say more advanced campaigns attempted to obtain chain-of-thought reasoning, automatically failed over between access channels and evaluated output quality to determine whether a provider had deployed countermeasures. They mapped those behaviors to the MITRE ATLAS framework for adversarial threats against machine-learning systems.
The company-specific sections describe different targets. DeepSeek allegedly pursued reasoning and specialized functions for its R1 and V3 models. Moonshot AI allegedly queried Claude and GPT variants for Kimi models, while Alibaba is accused of seeking software-engineering, agentic-workflow and conversational capabilities for Qwen.
MiniMax, StepFun and Z.AI are also named in connection with coding, agentic and reasoning functions. The document says one MiniMax technique used prompt injection to make Claude Code believe it was operating as a MiniMax product, while Z.AI allegedly consumed billions of GPT and Claude tokens.
The government report does not publish the underlying account records, prompts or network telemetry needed for outsiders to reproduce every attribution. That limits independent assessment of the company-level claims, even as the operational patterns offer providers concrete indicators to investigate in their own logs.
The Advisory’s Three Defensive Priorities
The first recommendation is broader detection. Providers are urged to correlate prompts, account creation, payment behavior, networks and usage patterns rather than judging suspicious activity from individual requests. Distillation campaigns can distribute queries across many identities, so signals that look ordinary in isolation may become distinctive when combined.
The second proposal is targeted response modification. Instead of only banning suspected accounts, a provider could subtly change answers delivered to high-confidence malicious extraction operations, reducing the usefulness of the collected training data. That tactic must be carefully governed because a false positive could degrade service for legitimate researchers or customers.
The third priority is cross-company intelligence sharing. Model developers see prompts and output patterns, cloud providers see infrastructure, and API aggregators see customer routing. The advisory argues that exchanging indicators across those layers is necessary to connect fragmented activity and prevent operators from simply moving to another intermediary.
Anthropic previously said it detected more than 24,000 fraudulent accounts and over 16 million exchanges linked to campaigns it attributed to DeepSeek, Moonshot AI and MiniMax. That company disclosure provides context for the joint advisory, but remains an interested party’s account rather than independent adjudication.
The document’s practical effect will depend on whether providers adopt common detection standards without blocking legitimate compatibility testing, research and ordinary high-volume use. For now, it shifts distillation from a model-development debate into a formal U.S. cybersecurity issue and gives vendors a shared vocabulary for investigating suspected extraction campaigns.
Related Research