US claims Chinese AI companies’ core AI strategy is distilling American models
Spooks and CISA point to ‘industrial-scale distillation’ by DeepSeek, Alibaba, and other Chinese players
The United States, through its intelligence agencies, has accused Chinese AI firms of systematically extracting sensitive features from U.S. cutting-edge AI models through a process called distillation. This tactic, according to the National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA), is now a primary component of China's AI development strategy, not simply an ancillary use.
Distillation involves a smaller model tapping into the responses of a larger model to enhance its own performance over time. The agencies allege that this practice is being conducted at an industrial scale by a range of Chinese companies, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. Distillation is generally prohibited under commercial model providers' terms of use, as it allows for the creation of smaller, more efficient versions of large models without the need for expensive training.
The agencies believe Chinese companies circumvent these restrictions by routing requests through various channels such as native APIs, remote cloud providers, and third-party aggregators that obscure user metadata. The NSA, FBI, and CISA also claim that China employs "gray market proxies" to bypass geographic restrictions on U.S. AI models, evade detection, and undermine traceability.
These proxies, known as "transfer stations," resell access to advanced models at a lower cost, creating a pathway for circumvention of safeguards. The advisory details instances where these tactics have not only resulted in model distillation but also the creation of synthetic data used to train models, misleading claims about computational efficiency, and a direct challenge to U.S. AI firms with free-to-use models that undercut their revenue.
The agencies recommend AI companies develop methods to detect and counter such attacks, suggesting subtle response alterations and correlating activities across different platforms to uncover large-scale distillation efforts. The United States has previously made similar claims against China, with Beijing responding by accusing US companies of distilling Chinese models and threatening retaliation against potential bans on Chinese technology.
The Register has contacted Chinese AI firms for comment and will update this story if a substantial response is received.
Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.