US Agencies Allege Chinese Firms Engaged in 'Industrial-Scale' AI Model Distillation
A joint advisory from leading U.S. cybersecurity and intelligence agencies reveals that six Chinese AI companies have been conducting extensive distillation attacks on American frontier AI models since late 2024. These operations, suspected to have Chinese government awareness, involved extracting billions of tokens through millions of requests from models developed by **Anthropic**, **OpenAI**, **Google**, and **xAI**.

U.S. cybersecurity and intelligence agencies have issued a stark warning regarding what they describe as industrial-scale distillation attacks targeting American frontier AI models. A joint advisory from **CISA**, **NSA**, and the **FBI** implicates six Chinese AI companies: **DeepSeek**, **Moonshot AI**, **Alibaba**, **MiniMax**, **StepFun**, and **Z.AI**.
### The Scope of the Operation
The advisory details that these firms have extracted billions of tokens through millions of requests from prominent AI models, including those from **Anthropic**, **OpenAI**, **Google**, and **xAI**. The scale and sophistication of these operations strongly suggest awareness and likely support from the Chinese government, positioning this approach as a core development strategy for the involved companies.
### Understanding AI Model Distillation
AI model distillation is a legitimate technique where a βstudentβ model learns from the outputs of a more powerful, well-trained βteacherβ model. This process helps developers reduce training costs and accelerate AI deployment. However, as **Google** warned in February, distillation can be abused when attackers leverage API access to extract the knowledge and logic of advanced models, enabling them to compete at a significantly lower development cost.
### Evading Detection
To bypass geographic restrictions, usage limits, and detection mechanisms, the Chinese firms distributed API requests across a complex network of fraudulent or shared accounts, APIs, cloud services, aggregators, and βtransfer stationβ proxies. Prompts used in these attacks often attempted to expose restricted chain-of-thought reasoning, with automated systems switching providers and evaluating whether defensive measures had degraded responses.
The **CISA** advisory emphasizes that βAdvanced industrial-scale distillation tactics include chain-of-thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures.β This strategy allows China-based AI companies to achieve significantly shorter AI development timelines and reduced financial expenditures.
### Key Players and Targets
**DeepSeek** and **MoonShot AI** were identified as the primary offenders, involved in distilling multiple **Claude**, **GPT**, **Gemini**, and **Grok** models. **MiniMax** subsequently targeted **Claude**, **Gemini**, and **GPT** models. **Alibaba** and **StepFun** are accused of targeting **Claude** and **GPT** models to enhance their own products, while **Z.AI** allegedly focused on **GPT-5.5** and **Claude Opus 4.8**.
### Recommendations for AI Companies
The advisory urges AI companies to enhance behavioral and infrastructure-level detection capabilities. It also recommends modifying responses when distillation operations are suspected and fostering intelligence sharing among all stakeholders regarding these campaigns.
Potential indicators of such activity include:
* New accounts immediately reaching maximum usage.
* Continuous activity without typical human idle periods.
* Shared accounts accessed from numerous IP addresses or user agents.
* Identical prompts observed across multiple providers.
* Unusually high subscription-to-usage ratios.
* Coordinated switching between access routes.
Ghost Protocol has reached out to the six Chinese AI firms for comment and will update this report should statements be provided.