Security/ ai · security · china · distillation

CISA Says Chinese AI Labs Are Industrially Distilling US Models

A joint NSA, CISA, and FBI advisory says six Chinese AI labs systematically distilled US models like Claude and GPT to build cheaper rivals.

Six Chinese AI companies have been systematically strip-mining US models for their best features, according to a joint advisory from the NSA, CISA, and the FBI.

The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, accusing them of extracting billions of tokens across millions of exchanges from Claude, GPT, Gemini, and Grok since at least late 2024. DeepSeek allegedly targeted reasoning and domain-specific capabilities to train its R1 and V3 models, while Moonshot AI reportedly pulled Claude and GPT-4o data to build its Kimi models. The companies route requests through proxies called "transfer stations" that bypass geographic restrictions and obscure who is really asking. They also reportedly use bulk-bought premium subscriptions shared across developer teams to keep costs down.

This is not the routine kind of distillation every lab uses to compress its own models. The agencies say it is the core strategy for closing the gap with US frontier AI, not a side technique. That reframes DeepSeek's widely cited $5.6 million training cost for R1: it does not count the compute and API spend already sunk into the models it was trained to imitate.

The recommended fixes - watch for suspicious usage patterns, quietly degrade responses to suspected scrapers, share intelligence across providers - sound like the anti-scraping fight every API company already runs, just with export controls layered on top.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →