U.S. Agencies Warn of Chinese Distillation Campaigns Targeting Leading AI Models
The advisory names six China‑based companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—as actors that have engaged in “aggressive, malicious, and targeted distillation” since 2024. The agencies say the operations have extracted billions of tokens from U.S. models, and they likely involve Chinese‑government awareness.
Distillation, a common training method in which a smaller “student” model learns from the outputs of a larger “teacher,” can reduce costs and speed development. However, the advisory explains, the technique can become a vehicle for intellectual‑property theft when performed without authorization.
According to the warning, the firms route requests through multiple pathways—native APIs, remote cloud providers, and third‑party aggregators that obscure user metadata—to evade detection. Their targets include Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini, and SpaceXAI’s Grok. The goal, the agencies say, is to capture proprietary functionalities and capabilities from these frontier models, thereby threatening U.S. technological leadership.
To counter the threat, the advisory recommends three concrete actions for developers: 1. Deploy comprehensive detection and mitigation systems that can spot unauthorized distillation traffic. 2. Tighten API access controls and monitor usage patterns for anomalies. 3. Foster cross‑organization intelligence sharing to coordinate defenses across the AI ecosystem.
The warning echoes earlier accusations. In February, Anthropic publicly alleged that Moonshot AI, DeepSeek, and MiniMax had attacked its Claude models. In July, White House Office of Science and Technology Director Michael Kratsios highlighted Moonshot AI’s attempts to siphon proprietary functions from Anthropic’s Fable model.
Advocacy groups have called on the White House to impose stricter export controls, specifically banning the sale of AI system components such as semiconductor chips to China. They argue that hardware restrictions could curb the technical capabilities that enable large‑scale distillation.
While the advisory does not detail the exact mechanisms used by the Chinese firms, it stresses that the campaigns involve systematic extraction of model knowledge through repeated, high‑volume queries. The operations are coordinated across multiple providers and platforms to slip past single‑point detection.
Developers are urged to review their API usage policies, monitor for anomalous traffic patterns that could signal distillation, and collaborate with industry peers to share threat intelligence and best practices.
The joint warning underscores the growing tension in the global AI race, where intellectual property and model capabilities are increasingly contested. Although the agencies do not confirm direct involvement of the Chinese government, they imply that state awareness is likely given the scale and sophistication of the campaigns.
No new sanctions or export‑control measures specifically targeting the firms listed in the advisory have been announced. The agencies’ call for tighter detection and cross‑organization intelligence sharing marks a shift toward more proactive defense of AI intellectual property.
As of now, the advisory remains the most detailed U.S. government statement on industrial‑scale distillation attacks. It highlights the need for robust monitoring, policy updates, and industry cooperation to safeguard the proprietary technologies that underpin U.S. AI leadership.
The situation continues to evolve as developers assess the threat and adapt their security posture. No further regulatory actions or policy changes have been announced beyond the advisory’s recommendations.