The NSA, CISA, and FBI issued a joint warning alleging that six major Chinese AI entities—including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—have systematically extracted capability from U.S. frontier AI models since late 2024. Federal authorities claim these firms acted with Chinese government awareness, leveraging model distillation techniques to cut training costs and shorten development timelines for domestic models.
According to the advisory, the firms executed campaigns targeting variants of Claude, GPT, Gemini, and Grok by utilizing swarms of fraudulent API accounts bought on gray-market proxies. Attack vectors included high-volume query prompts and advanced jailbreaking techniques, such as forcing underlying models to reveal hidden step-by-step chain-of-thought reasoning.
U.S. agencies called on domestic AI providers to step up account verification, flag anomalous API usage patterns, and implement defensive mitigations. Recommended countermeasures include subtly altering model responses when automated distillation campaigns are detected to degrade the utility of extracted training data.
Why it matters
Frontier model providers face increased national security pressure to audit API access, implement strict KYC controls, and obfuscate model outputs.
Distillation threats could force cloud providers to restrict API access parameters, adding operational friction for legitimate international developers.
Heightened regulatory focus on model IP theft signals imminent export controls and security compliance standards targeting AI API infrastructure.
Source: arstechnica.com



