The NSA, CISA and FBI say that China-based AI companies are using the distillation process against US frontier models. “Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024,” they say.
The result doesn’t simply improve China’s AI models, it also threatens the existing US technology leadership. Between late 2024 and mid 2025, DeepSeek distilled training data and capabilities from Claude, Gemini, GPT-4 and GPT-5, and Grok 4 to train its R1 and V3 models.
The knowledge distilled included, but was not limited to, API rule-driven tasks, agentic functions, Q&A optimization, supervised fine-tuning optimization, and creative and occupational writing optimization.
Moonshot undertook a similar large scale distillation, including the extraction of significant Claude Fable 5 data to improve its Kimi-K3 model; and GPT-4o data to improve its Kimi-K2 model.
Such distillation was repeated across all the named Chinese AI systems and is chronicled in detail within the agencies’ report. The tactics, techniques, and procedures (TTPs) used by the Chinese organizations in their distillation are mapped to the MITRE ATLAS framework providing the TTP Title, its ID, and a description.
This mapping provides a detailed explanation of the distillation process from resource development through access, execution, discovery, AI attack staging, collection, exfiltration and impact. The impact (on US frontier model developers), for example, is described as financial harm, undermining competitive advantages, and representing “a strategic economic threat to fair technological competition and U.S. technological leadership”.
However, the authoring agencies also note the Chinese companies leverage additional techniques not present in MITRE ATLAS, thus distinguishing the process from an opportunistic exploitation. This is a planned and well-resourced national level action.
The novel TTPs are described as regional restriction evasion and subscription exploitation; centralized request routing infrastructure, automated request metadata sanitization; and systematic quota and cost optimization.
Mitigations proffered by the agencies should be coordinated across the broader US AI ecosystem, including cloud providers, API aggregators, and infrastructure providers. Recommendations include purely defensive actions (such as behavioral detection and monitoring, including examples of the behavior that could be detected), to more aggressive strike back responses. For the latter, the agencies suggest that “Employing targeted changes in response to high-confidence malicious distillation requests can impose meaningful costs on knowledge distillation campaigns.”
Sharing information about distillation campaigns is of course recommended. “Multi-source correlated activity enables more confident attribution of malicious knowledge distillation campaigns, justifying response degradation with lower-to-no legitimate user risk.”
The principle of differential privacy is also recommended. It could be implemented by “adding calibrated noise to model outputs and preventing malicious actors from extracting training data membership information and other sensitive model information, such as decision boundaries or signals that could help reconstruct private data.”
The purpose of the report is to alert all AI stakeholders that Chinese AI companies are systematically and, on an industrial scale, effectively stealing US technological leadership. The threat is not directly to the enterprise use of AI (although adversarial knowledge of how an AI defense might respond could potentially allow a more sophisticated and evasive attack). The threat is more directly to US technology leadership and consequently to the US economy and could potentially lead to a national security issue.
Related: Trump Administration Vows Crackdown on Chinese Companies ‘Exploiting’ AI Models Made in US
Related: Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini
Related: Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models
Related: Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors
