How to Detect Hidden Chinese AI Models: Cisco’s Warning on Model Lineage

www.news4hackers.com-how-to-detect-hidden-chinese-ai-models-cisco-s-warning-on-model-lineage-how-to-detect-hidden-chinese-ai-models-cisco-s-warning-on-model-lineage

{“choices”:[{“finish_reason”:”length”,”index”:0,”logprobs”:null,”message”:{“annotations”:null,”audio”:null,”content”:null,”function_call”:null,”reasoning”:”\nOkay, I need to format the user’s content into valid HTML following their strict rules. Let me start by understanding the requirements.\n\nFirst, the user specified that only certain HTML tags can be used:

,

,

,

,

    ,

  • ,
    . They also mentioned that headings must be one-liners and not shortened or misspelled. The title should be inside \n-

    Summary line here

    \n-

    Main Article Title

    \n-

    Paragraphs of the main article

    \n-

    Latest News

    \n-

      \n

    • Iran-Linked Hackers…
    • \n

    • Encrypted Prompts…
    • \n …\n

    \n-

    People on the Move

    \n-

    Content about promotions and appointments

    \n-

    Expert Insights

    \n-

      \n

    • The Future of AI-Driven Security…
    • \n

    • The MFA Identity Trap…
    • \n …\n

    \n-

    Daily Briefing Newsletter

    \n-

    Subscription info

    \n\nBut the user’s content includes some of these sections as separate paragraphs. For example, \”Latest News Tech…\” is a line, then \”People on the Move\” is another section.\n\nBut the user’s content is a continuous text. So I need to parse each section and structure them accordingly.\n\nHowever, the user’s instruction says to format the content into HTML without rephrasing or summarizing. So I need to keep the original text but wrap it in the correct tags.\n\nBut the user’s example response includes the main article, then a

      for the news items, then sections for \”People on the Move\”, \”Expert Insights\”, etc., each with their own

      and content.\n\nSo, I’ll proceed to structure the content as follows:\n\n1. Title in \n

      Summary line here.

      \n

      Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

      \n

      The U.S. government has classified Chinese-developed artificial intelligence as a national security risk, prompting some organizations to avoid AI systems associated with China. However, research from Cisco and VAIL reveals that country-specific labels on AI models do not reliably reflect their technical origins or internal composition. This finding challenges the assumption that removing AI labeled with a particular nation’s name ensures a system is free from foreign influence. Cisco’s analysis, detailed in a blog post titled “The ‘U.S. vs. China’ AI Trap: An Incomplete Proxy for AI Security,” highlights a phenomenon called provenance entanglement. Researchers used two methods to examine AI models: one analyzing internal weights and another assessing behavioral patterns during inference. Both approaches demonstrated that a model’s lineage is not always evident from its publisher’s name or country of origin. This occurs because AI models often inherit components from prior systems, including weights, biases, and behavioral traits, which may originate from unrelated models developed in different regions. For example, a model labeled as U.S.-developed could contain characteristics derived from a Chinese model, while a Chinese-labeled system might exhibit traits from U.S.-originated predecessors. While the publisher’s identity provides context about accountability, jurisdiction, and procurement processes, it does not fully capture the model’s internal dependencies. This discrepancy raises concerns about the accuracy of relying on country labels to assess security risks. The study focused on the Nemotron and Qwen model families, which are known to share foundational weights. Using Cisco’s Model Provenance Kit and VAIL’s Behavioral Fingerprinting tools, researchers found that Nemotron models trained on Qwen base weights exhibited significant similarities to Qwen models beyond random chance. This suggests that rebranding or repurposing a model does not necessarily obscure its technical connections to earlier systems. The implications of this research are critical for enterprises and regulators. If an upstream model contains vulnerabilities, biases, or malicious components, downstream systems built upon it could inherit these risks. Organizations must therefore adopt a more comprehensive approach to AI evaluation, including examining lineage, training data, and behavioral patterns rather than relying solely on publisher information. Cisco recommends three key improvements for AI adoption: 1. Enterprises should treat publisher identity as one factor among many, incorporating lineage analysis, dependency reviews, and behavioral testing into due diligence. 2. Regulators need deeper insights into model dependencies to assess risks tied to upstream systems. 3. Developers should prioritize transparency by disclosing lineage details as a standard practice. The researchers emphasize that AI models lack “passports” but operate through complex supply chains. A model bill of materials (BOM) could address this by documenting base checkpoints, derivation methods, datasets, synthetic data generators, and post-deployment access controls. Technical fingerprints could further validate these disclosures or reveal hidden relationships. The study underscores the need for industry-wide transparency to mitigate risks associated with AI’s evolving technical landscape. As geopolitical tensions influence AI adoption, understanding a model’s true lineage remains essential for secure deployment.

      \n

      Latest News

      \n

        \n

      • Iran-Linked Hackers Shut Down UK Power Plant for Four Days
      • \n

      • Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
      • \n

      • New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
      • \n

      • Surveillance – Everything You Wanted to Know, But Were Afraid to Ask
      • \n

      • CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
      • \n

      • AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
      • \n

      • Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
      • \n

      • Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
      • \n

      • Latest News Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
      • \n

      • PaperCut Releases Emergency Patch for Exploited Zero-Day
      • \n

      • Trump Order Aims to Block Foreign Backdoors in US Power Grid
      • \n

      • Gear Australia Arrests 2 Alleged TeamPCP Hackers
      • \n

      • OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
      • \n

      • Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security
      • \n

      • CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite
      • \n

      • Cyberattack Causes Global Disruption at Boston Scientific
      • \n

      \n

      Trending Daily Briefing Newsletter

      \n

      August 26, 2026 Join this live Register September 2, 2026 In this live Register

      \n

      People on the Move

      \n

      Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer. Naveen Bhateja has been appointed Chief People Officer at HackerOne. The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer. More People On The Move

      \n

      Expert Insights,

      ,

      ,

      ,

        ,

      • ,
        . They also mentioned that headings must be one-liners and not shortened or misspelled. The title should be inside \n-

        Summary line here

        \n-

        Main Article Title

        \n-

        Paragraphs of the main article

        \n-

        Latest News

        \n-

          \n

        • Iran-Linked Hackers…
        • \n

        • Encrypted Prompts…
        • \n …\n

        \n-

        People on the Move

        \n-

        Content about promotions and appointments

        \n-

        Expert Insights

        \n-

          \n

        • The Future of AI-Driven Security…
        • \n

        • The MFA Identity Trap…
        • \n …\n

        \n-

        Daily Briefing Newsletter

        \n-

        Subscription info

        \n\nBut the user’s content includes some of these sections as separate paragraphs. For example, \”Latest News Tech…\” is a line, then \”People on the Move\” is another section.\n\nBut the user’s content is a continuous text. So I need to parse each section and structure them accordingly.\n\nHowever, the user’s instruction says to format the content into HTML without rephrasing or summarizing. So I need to keep the original text but wrap it in the correct tags.\n\nBut the user’s example response includes the main article, then a

          for the news items, then sections for \”People on the Move\”, \”Expert Insights\”, etc., each with their own

          and content.\n\nSo, I’ll proceed to structure the content as follows:\n\n1. Title in \n

          Summary line here.

          \n

          Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

          \n

          The U.S. government has classified Chinese-developed artificial intelligence as a national security risk, prompting some organizations to avoid AI systems associated with China. However, research from Cisco and VAIL reveals that country-specific labels on AI models do not reliably reflect their technical origins or internal composition. This finding challenges the assumption that removing AI labeled with a particular nation’s name ensures a system is free from foreign influence. Cisco’s analysis, detailed in a blog post titled “The ‘U.S. vs. China’ AI Trap: An Incomplete Proxy for AI Security,” highlights a phenomenon called provenance entanglement. Researchers used two methods to examine AI models: one analyzing internal weights and another assessing behavioral patterns during inference. Both approaches demonstrated that a model’s lineage is not always evident from its publisher’s name or country of origin. This occurs because AI models often inherit components from prior systems, including weights, biases, and behavioral traits, which may originate from unrelated models developed in different regions. For example, a model labeled as U.S.-developed could contain characteristics derived from a Chinese model, while a Chinese-labeled system might exhibit traits from U.S.-originated predecessors. While the publisher’s identity provides context about accountability, jurisdiction, and procurement processes, it does not fully capture the model’s internal dependencies. This discrepancy raises concerns about the accuracy of relying on country labels to assess security risks. The study focused on the Nemotron and Qwen model families, which are known to share foundational weights. Using Cisco’s Model Provenance Kit and VAIL’s Behavioral Fingerprinting tools, researchers found that Nemotron models trained on Qwen base weights exhibited significant similarities to Qwen models beyond random chance. This suggests that rebranding or repurposing a model does not necessarily obscure its technical connections to earlier systems. The implications of this research are critical for enterprises and regulators. If an upstream model contains vulnerabilities, biases, or malicious components, downstream systems built upon it could inherit these risks. Organizations must therefore adopt a more comprehensive approach to AI evaluation, including examining lineage, training data, and behavioral patterns rather than relying solely on publisher information. Cisco recommends three key improvements for AI adoption: 1. Enterprises should treat publisher identity as one factor among many, incorporating lineage analysis, dependency reviews, and behavioral testing into due diligence. 2. Regulators need deeper insights into model dependencies to assess risks tied to upstream systems. 3. Developers should prioritize transparency by disclosing lineage details as a standard practice. The researchers emphasize that AI models lack “passports” but operate through complex supply chains. A model bill of materials (BOM) could address this by documenting base checkpoints, derivation methods, datasets, synthetic data generators, and post-deployment access controls. Technical fingerprints could further validate these disclosures or reveal hidden relationships. The study underscores the need for industry-wide transparency to mitigate risks associated with AI’s evolving technical landscape. As geopolitical tensions influence AI adoption, understanding a model’s true lineage remains essential for secure deployment.

          \n

          Latest News

          \n

            \n

          • Iran-Linked Hackers Shut Down UK Power Plant for Four Days
          • \n

          • Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
          • \n

          • New Phishing Toolkit Uses Passkeys to Maintain Access After Password Resets
          • \n

          • Surveillance – Everything You Wanted to Know, But Were Afraid to Ask
          • \n

          • CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW
          • \n

          • AI-Driven Vulnerability Surge Breaks the Traditional Patching Model
          • \n

          • Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
          • \n

          • Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption
          • \n

          • Latest News Tech, Cybersecurity Giants Unite Behind OpenAI-Led Cyber Defense Pledge
          • \n

          • PaperCut Releases Emergency Patch for Exploited Zero-Day
          • \n

          • Trump Order Aims to Block Foreign Backdoors in US Power Grid
          • \n

          • Gear Australia Arrests 2 Alleged TeamPCP Hackers
          • \n

          • OpenAI Agents Coordinated via Makeshift Message Board Ahead of Hugging Face Hack
          • \n

          • Okta Shares Surge on Strong Earnings, Growing Demand for AI Identity Security
          • \n

          • CISO Conversations: Chris Wheeler – Trust Is the Job, From the Navy to the C-Suite
          • \n

          • Cyberattack Causes Global Disruption at Boston Scientific
          • \n

          \n

          Trending Daily Briefing Newsletter

          \n

          August 26, 2026 Join this live Register September 2, 2026 In this live Register

          \n

          People on the Move

          \n

          Social engineering protection company Doppel has promoted Alyssa Smrekar to Chief Marketing Officer. Naveen Bhateja has been appointed Chief People Officer at HackerOne. The Department of War has appointed Sonu Shankar as Principal Deputy Chief Information Officer. More People On The Move

          \n

          Expert Insights


          Blog Image

          About Author

en_USEnglish