US Accuses Chinese AI Firms of Mass Model Distillation — SkimNews

Get the Tech newsletter
Daily tech — startups, AI labs, chips, the launches that shape the next decade. Free.
- NSA, CISA, and FBI jointly accused six China-based AI companies of running "industrial-scale" distillation attacks on U.S. frontier models since late 2024, extracting billions of tokens across millions of exchanges with likely Chinese government backing.
- DeepSeek ran organized campaigns from late 2024 to mid-2025 to train its R1 and V3 models; Moonshot AI extracted Claude Fable 5 data for Kimi-K3 and GPT-4o data for Kimi-K2.
- Alibaba distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 in late 2025 to improve software engineering, customer service dialogue, image/character creation, and RL/SFT/distillation integration in its own models.
- MiniMax pulled CoT reasoning and software engineering capabilities from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro, and Gemini 3 Pro to improve its M2 model; StepFun targeted Claude Opus 4.1/4.5, Sonnet 4.5, Haiku 4.5, and multiple GPT-5 variants for coding and agentic functions in Step 4.
- Z.AI distilled billions of tokens of GPT-5.5 and Claude Opus 4.8 data as of mid-2026 to develop chain-of-thought reasoning capabilities.
- Chinese firms achieved cost savings through bulk procurement of premium U.S. AI subscriptions shared across developer teams, routing requests through APIs, remote cloud providers, third-party aggregators, VPNs, obfuscated accounts, and proxy services marketed on Taobao and Xianyu.
- Anthropic flagged DeepSeek, Moonshot AI, and MiniMax for similar campaigns back in February; Google Threat Intelligence Group separately reported a recent spike exceeding 100 million prompts targeting Google's visual, audio, image, and video generation capabilities.
Why it matters: This bulletin formalizes individual vendor complaints — Anthropic in February, Google this week — into a coordinated U.S. government position, giving frontier AI companies political cover to implement stricter detection, response manipulation, and cross-provider correlation. The named tactics, including bulk subscription purchases and proxy markets on Taobao and Xianyu, translate a terms-of-service violation into a documented national security threat with specific companies and model versions attached.
Ask SkimNews




