09-09-2026, 07:08 PM
A joint cybersecurity advisory from the NSA, CISA and FBI alleges that several China-based AI companies—including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI—have used industrial-scale model distillation since at least late 2024 to extract capabilities from leading U.S. AI systems such as GPT, Claude, Gemini and Grok.
According to the report, these campaigns involved billions of generated tokens and millions of requests designed to reproduce valuable capabilities such as reasoning, coding, agentic behavior, mathematical performance and specialized task optimization; access was allegedly distributed across legitimate APIs, cloud services, third-party aggregators and gray-market proxy services called “transfer stations” to evade geographic restrictions, usage limits and detection.
The agencies argue that distillation itself is a legitimate AI technique, but characterize these particular operations as malicious because they allegedly violated providers’ terms and systematically extracted proprietary functionality, significantly reducing the cost and time required for Chinese firms to develop competitive frontier models.
The advisory recommends stronger anomaly detection, monitoring of suspicious high-volume accounts and coordinated queries, selectively degrading responses suspected of being used for distillation, and greater intelligence-sharing among AI providers, cloud platforms and governments. These are claims and assessments made by U.S. security agencies, rather than independently established findings presented in the document.
REPORT [pdf]
According to the report, these campaigns involved billions of generated tokens and millions of requests designed to reproduce valuable capabilities such as reasoning, coding, agentic behavior, mathematical performance and specialized task optimization; access was allegedly distributed across legitimate APIs, cloud services, third-party aggregators and gray-market proxy services called “transfer stations” to evade geographic restrictions, usage limits and detection.
The agencies argue that distillation itself is a legitimate AI technique, but characterize these particular operations as malicious because they allegedly violated providers’ terms and systematically extracted proprietary functionality, significantly reducing the cost and time required for Chinese firms to develop competitive frontier models.
The advisory recommends stronger anomaly detection, monitoring of suspicious high-volume accounts and coordinated queries, selectively degrading responses suspected of being used for distillation, and greater intelligence-sharing among AI providers, cloud platforms and governments. These are claims and assessments made by U.S. security agencies, rather than independently established findings presented in the document.
REPORT [pdf]
┌────────────────────────────────┐
│ KONSTANTINOS MICHAILIDIS │
└────────────────────────────────┘
│ KONSTANTINOS MICHAILIDIS │
└────────────────────────────────┘

