US Accuses China AI Firms of Industrial Distillation — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- NSA, CISA, and FBI issued a joint advisory accusing six China-based AI companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—of 'industrial-scale' distillation attacks that extracted 'billions of tokens across millions of exchanges' from Claude, GPT, Gemini, and Grok since late 2024, likely with Chinese government backing.
- DeepSeek ran organized distillation campaigns from late 2024 through mid-2025 targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models.
- Alibaba distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 in late 2025 to improve software engineering, customer service dialogue, and image/character creation, while StepFun pulled data from Claude Opus 4.1/4.5, Sonnet 4.5, Haiku 4.5, and multiple GPT-5 variants through early 2026 for Step 4's coding and agentic functions.
- Chinese firms cut costs via bulk procurement of U.S. premium subscriptions shared across developer teams, routing requests through APIs, cloud providers, and obfuscating proxies—including relay services marketed on Chinese marketplaces Taobao and Xianyu.
- Anthropic flagged similar industrial-scale campaigns by DeepSeek, Moonshot AI, and MiniMax in February, and Google Threat Intelligence Group this week reported distillation surges exceeding 100 million prompts targeting Gemini's visual/audio understanding, image generation, and video generation.
- Arctic Wolf VP Ismael Valenzuela compared the distributed evasion tactics to credential stuffing and payment fraud schemes, warning that defenders will struggle to distinguish illicit activity from legitimate platform use.
Why it matters: The advisory reframes routine model distillation as a national-security threat when conducted at industrial scale without legal compliance, with Valenzuela warning defenders will struggle to separate replicated frontier capabilities from legitimate platform use. U.S. AI firms are formally urged to subtly alter outputs for suspected malicious actors and correlate activity across providers, cloud platforms, and API aggregators to expose distributed campaigns.
Ask SkimNews




