Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Artificial Intelligence

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

NSA

The NSA, CISA and FBI say that China-based AI companies are using the distillation process against US frontier models. “Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024,” they say.

The result doesn’t simply improve China’s AI models, it also threatens the existing US technology leadership. Between late 2024 and mid 2025, DeepSeek distilled training data and capabilities from Claude, Gemini, GPT-4 and GPT-5, and Grok 4 to train its R1 and V3 models.

The knowledge distilled included, but was not limited to, API rule-driven tasks, agentic functions, Q&A optimization, supervised fine-tuning optimization, and creative and occupational writing optimization.

Moonshot undertook a similar large scale distillation, including the extraction of significant Claude Fable 5 data to improve its Kimi-K3 model; and GPT-4o data to improve its Kimi-K2 model.

Such distillation was repeated across all the named Chinese AI systems and is chronicled in detail within the agencies’ report. The tactics, techniques, and procedures (TTPs) used by the Chinese organizations in their distillation are mapped to the MITRE ATLAS framework providing the TTP Title, its ID, and a description.

This mapping provides a detailed explanation of the distillation process from resource development through access, execution, discovery, AI attack staging, collection, exfiltration and impact. The impact (on US frontier model developers), for example, is described as financial harm, undermining competitive advantages, and representing “a strategic economic threat to fair technological competition and U.S. technological leadership”.

Advertisement. Scroll to continue reading.

However, the authoring agencies also note the Chinese companies leverage additional techniques not present in MITRE ATLAS, thus distinguishing the process from an opportunistic exploitation. This is a planned and well-resourced national level action.

The novel TTPs are described as regional restriction evasion and subscription exploitation; centralized request routing infrastructure, automated request metadata sanitization; and systematic quota and cost optimization.

Mitigations proffered by the agencies should be coordinated across the broader US AI ecosystem, including cloud providers, API aggregators, and infrastructure providers. Recommendations include purely defensive actions (such as behavioral detection and monitoring, including examples of the behavior that could be detected), to more aggressive strike back responses. For the latter, the agencies suggest that “Employing targeted changes in response to high-confidence malicious distillation requests can impose meaningful costs on knowledge distillation campaigns.”

Sharing information about distillation campaigns is of course recommended. “Multi-source correlated activity enables more confident attribution of malicious knowledge distillation campaigns, justifying response degradation with lower-to-no legitimate user risk.”

The principle of differential privacy is also recommended. It could be implemented by “adding calibrated noise to model outputs and preventing malicious actors from extracting training data membership information and other sensitive model information, such as decision boundaries or signals that could help reconstruct private data.”

The purpose of the report is to alert all AI stakeholders that Chinese AI companies are systematically and, on an industrial scale, effectively stealing US technological leadership. The threat is not directly to the enterprise use of AI (although adversarial knowledge of how an AI defense might respond could potentially allow a more sophisticated and evasive attack). The threat is more directly to US technology leadership and consequently to the US economy and could potentially lead to a national security issue.

Related: Trump Administration Vows Crackdown on Chinese Companies ‘Exploiting’ AI Models Made in US

Related: Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Related: Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

Related: Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Frank Verdecanna has been appointed Chief Financial Officer at Armadin.

Keeper Security has named Jessica Krowel and Bill Grabner as SVPs of sales for North America.

Skyhigh Security has named Anthony Palladino as Chief Operating Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.