
CISA, the NSA, and the FBI warn that several China-based artificial intelligence companies have run industrial-scale campaigns to extract proprietary capabilities from leading US AI models.
The agencies say the activity, underway since at least late 2024, involved billions of tokens and millions of requests targeting models from Anthropic, OpenAI, Google, and xAI.
The joint advisory attributes the activity to DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, likely with the Chinese government's awareness. According to the agencies, these companies used knowledge distillation not merely as a research aid but as a central development strategy for improving their own models while reducing training costs and development time.
Knowledge distillation is a legitimate machine-learning technique in which a smaller “student” model learns from the outputs of a more capable “teacher” model. The agencies allege that the Chinese firms crossed into malicious activity by systematically extracting restricted functionality at massive scale, violating providers’ terms of service and bypassing access controls.
The companies named in the alert are among China’s most prominent AI developers. DeepSeek gained international attention with its R1 and V3 model families, while Alibaba develops the Qwen series. Moonshot AI operates the Kimi family, MiniMax develops general-purpose and coding models, and StepFun and Z.AI are also building frontier-class systems for reasoning, coding, and agentic tasks.
DeepSeek allegedly began organized distillation campaigns in late 2024, collecting synthetic training data from models including GPT-4, GPT-4o, GPT-5, Claude Sonnet and Opus variants, Gemini 2.5, and Grok 4. The extracted capabilities included chain-of-thought-style reasoning, legal specialization, agentic functions, API-driven tasks, supervised fine-tuning optimization, and writing capabilities.

Moonshot AI is accused of conducting similar campaigns from mid-2025, including extracting data from Claude and GPT models for its Kimi systems. Alibaba, MiniMax, StepFun, and Z.AI allegedly targeted capabilities including software engineering, reinforcement learning, coding agents, customer-service dialogue, and reasoning. CISA says Z.AI alone had distilled billions of tokens from GPT-5.5 and Claude Opus 4.8 by mid-2026.
To evade detection, the companies allegedly spread requests across native APIs, cloud providers, third-party aggregators, account pools, and gray-market API proxies known as “transfer stations.” These services can obscure origin information and bypass geographic restrictions. Operators also reportedly used automated metadata sanitization, centralized request-routing systems, bulk premium subscriptions, and automatic failover when providers blocked an access path.
The advisory highlights attempts to extract hidden reasoning through jailbreak-style prompts, as well as quality-control pipelines designed to detect when providers had degraded or altered responses. MiniMax reportedly redirected activity to a newly released Claude model within 24 hours, illustrating how quickly these operations could adapt.
CISA, the NSA, and the FBI recommend that AI providers monitor for enterprise-scale traffic from consumer subscriptions, newly created accounts immediately hitting usage limits, round-the-clock automated activity, shared accounts across multiple IP addresses, and coordinated behavior spanning different access routes.
Providers are also advised to consider subtly degrading responses for high-confidence distillation activity, including reducing reasoning depth or routing suspicious requests to less capable models. The agencies say greater intelligence sharing between model developers, cloud platforms, and API aggregators will be critical for connecting activity that may otherwise appear as isolated abuse.







Leave a Reply