CISA Warns: Chinese AI Firms Siphon Capabilities from U.S. Models
Chinese AI firms are exploiting U.S. models through large-scale knowledge extraction, according to a joint warning from U.S. cybersecurity authorities.
Joint Warning from U.S. Cybersecurity Authorities
A collaborative advisory from the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) reveals that Chinese artificial intelligence companies have implemented industrial-scale knowledge distillation operations to replicate advanced features from leading American AI systems.
The process involves leveraging outputs from high-capacity models to train alternative systems, with the agencies noting its strategic integration into the development pipelines of multiple Chinese entities.
Key Participants and Methods
The report identifies DeepSeek, Moonshot AI, Alibaba Group, MiniMax, StepFun, and Z.AI as key participants in these activities. Since late 2024, these organizations have accessed U.S. frontier AI models such as Claude, GPT, Gemini, and Grok through billions of requests, extracting data to enhance their own systems.
DeepSeek and Moonshot AI
DeepSeek has utilized U.S. model outputs to refine its DeepSeek R1 and V3 platforms, focusing on reasoning, writing, and specialized tasks like legal analysis. The advisory disputes the company’s claimed $5.6 million training cost, arguing it fails to account for the extensive data acquisition through distillation.
Moonshot AI has engaged in similar practices since mid-2025, leveraging U.S. models to improve software engineering and mathematical capabilities in its Kimi series.
Alibaba and Other Entities
Alibaba, MiniMax, StepFun, and Z.AI have similarly accessed U.S. models to develop functions spanning coding, customer service, and AI agent development. By mid-2026, Z.AI had distilled billions of tokens from GPT-5.5 and Claude Opus 4.8 to build chain-of-thought reasoning capabilities.
Systematic Operations and Tactics
The agencies describe these operations as systematic, employing tactics aligned with the MITRE ATLAS framework, which covers resource development, model access, execution, and data exfiltration. Additional techniques outside this framework include the use of API proxy networks known as “transfer stations” to circumvent geographic restrictions, obscure origins, and evade detection.
Technical Strategies
These campaigns rely on premium account pools to distribute requests and avoid usage caps, while centralized systems route traffic through APIs, cloud services, and aggregators based on availability. Operators anonymize requests and optimize account usage to minimize costs.
Indicators of Compromise
The advisory outlines indicators of compromise, including sustained 24/7 activity without typical human patterns, abnormal subscription-to-API usage ratios, and rapid subscription growth reaching maximum limits. Coordinated behavior across account groups and sudden metadata changes also signal potential distillation efforts.
Recommended Countermeasures
To counter these threats, the agencies recommend enhanced account verification, monitoring for enterprise-scale throughput, and detecting deviations from legitimate usage. Providers can mitigate risks by varying model responses, limiting reasoning depth, and introducing stylistic inconsistencies.
Advanced Mitigation Techniques
Routing suspected operators to less capable models without notification is another strategy. For confirmed malicious activity, providers can alter responses discreetly while informing AI safety researchers of model changes. Differential privacy, which adds controlled noise to outputs, can further hinder extraction but may reduce model accuracy.
Combining this with rate limits and monitoring offers a balanced approach. Sharing threat intelligence such as IP addresses, domains, and query patterns can help identify coordinated campaigns. Safety training and adversarial techniques can also strengthen defenses against prompt injection and jailbreak attempts.
Conclusion
The advisory underscores the need for continuous adaptation to evolving tactics, emphasizing collaboration across the AI industry to safeguard critical technologies.
