U.S. cybersecurity and intelligence agencies on Tuesday issued a joint advisory accusing six China-based artificial intelligence companies of conducting industrial-scale campaigns to extract proprietary features from leading American AI models.
The Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and Federal Bureau of Investigation (FBI) named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI in the alert. Officials alleged the companies, likely with Chinese government awareness, pulled billions of tokens across millions of requests from U.S. AI systems, including variants of Claude, GPT, Gemini, and Grok. The activity dates back to at least late 2024.
CISA Acting Director Nick Andersen stated the agency is committed to promoting secure AI use. “We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies,” Andersen said.
The advisory distinguished between legitimate research and aggressive, malicious, and targeted distillation activities at an industrial scale. It noted the firms routed traffic through native APIs, remote cloud providers, and third-party aggregators that strip user metadata. A gray market of proxies, referred to as “transfer stations,” helped them bypass geographic blocks and terms of use. Bulk premium subscriptions, shared across developer teams, reduced costs.
DeepSeek, formally Hangzhou DeepSeek Artificial Intelligence Basic Technology Research Co. Ltd., has run an organized campaign since at least late 2024 to feed synthetic training data into its R1 and V3 models, according to the agencies.
What is Knowledge Distillation?
Knowledge distillation is a standard AI research method where a smaller model learns from the outputs of a larger one. While widely used in the industry, the U.S. agencies allege the Chinese firms engaged in systematic, large-scale extraction of proprietary features, often in violation of terms of service.
The advisory described the scale as “not a supplement but the critical core” of the companies’ AI model development, citing distillation of specific capabilities such as legal specialization optimization, agentic functions, and coach/assistant features from American models.
Chinese Embassy Responds
A spokesperson for China’s embassy in Washington did not immediately reply to a request for comment. The White House has framed U.S.-China AI competition as a race for cutting-edge development, with officials trading accusations over alleged intellectual property theft.
Broader Cybersecurity Concerns
Separately, Google reported on Tuesday that Chinese hackers are increasingly using stolen networks to run open-source AI models, avoiding detection. The Google Threat Intelligence Group stated hacker groups, including those linked to Chinese intelligence, have shifted from basic AI prompting to automated intrusion campaigns that can be completed in less than six hours.
Google noted one group, tracked since 2023, has targeted academic, medical, and military research organizations in North America, focusing on proprietary AI research. The company did not name victims but described the tactic as compromising third-party cloud networks to install open-source models, bypassing commercial AI guardrails.
John Hultquist, chief analyst at Google’s Threat Intelligence Group, said running models on hacked systems allows hackers to avoid monitoring and circumvent restrictions imposed by commercial chatbots.
A spokesperson for China’s Embassy in Washington, Liu Chang, denied the claims. “China opposes hacking activities and fights such activities in accordance with the law,” Chang said. “That said, we firmly reject vilification and smears under the pretext of cybersecurity.”