www.securityweek.com 9 Sept 2026, 12:32 UTC

US agencies warn Chinese AI firms are distilling frontier models at scale

US agencies warn Chinese AI firms are distilling frontier models at scale
CyberSIXT Evidence Panel Source marked as original reporting

THE NSA, CISA and FBI warn that Chinese AI firms are systematically “distilling” outputs from US frontier AI models to train their own systems. In a report cited by the agencies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z[.]AI are said to have extracted billions of tokens across millions of exchanges from US frontier models, including variants of Claude, GPT, Gemini and Grok, since at least late 2024.

The disclosure suggests this activity is more than opportunistic exploitation and constitutes a coordinated national‑level effort, likely with government awareness.

The agencies map the distillation techniques to the MITRE ATLAS framework, detailing the process from resource development through access, execution, discovery, AI attack staging, collection, exfiltration and impact. Reported impacts on US frontier model developers include financial harm and a threat to US technological leadership.

The article notes that Chinese adversaries reportedly employ additional techniques not present in ATLAS, such as regional restriction evasion, subscription exploitation, centralised request routing, automated metadata sanitisation and systematic quota optimisation. Distillation has reportedly been used to improve models such as DeepSeek’s R1 and V3, Moonshot’s Kimi series and Claude Fable 5 data feeding into other variants.

Mitigations recommended by the agencies span defensive measures—such as behavioural detection and monitoring—to more assertive responses like cost‑imposing actions against high‑confidence malicious requests. The report advocates cross‑sector information sharing, multi‑source attribution, and applying differential privacy to limit data extraction. The threat is framed as a strategic economic and national security issue rather than mere enterprise risk.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline