Artificial Intelligence

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

NSA cybersecurity

The NSA, CISA and FBI say that China-based AI companies are using the distillation process against US frontier models. “Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024,” they say.

The result doesn’t simply improve China’s AI models, it also threatens the existing US technology leadership. Between late 2024 and mid 2025, DeepSeek distilled training data and capabilities from Claude, Gemini, GPT-4 and GPT-5, and Grok 4 to train its R1 and V3 models.

The knowledge distilled included, but was not limited to, API rule-driven tasks, agentic functions, Q&A optimization, supervised fine-tuning optimization, and creative and occupational writing optimization.

Moonshot undertook a similar large scale distillation, including the extraction of significant Claude Fable 5 data to improve its Kimi-K3 model; and GPT-4o data to improve its Kimi-K2 model.

Such distillation was repeated across all the named Chinese AI systems and is chronicled in detail within the agencies’ report. The tactics, techniques, and procedures (TTPs) used by the Chinese organizations in their distillation are mapped to the MITRE ATLAS framework providing the TTP Title, its ID, and a description.

This mapping provides a detailed explanation of the distillation process from resource development through access, execution, discovery, AI attack staging, collection, exfiltration and impact. The impact (on US frontier model developers), for example, is described as financial harm, undermining competitive advantages, and representing “a strategic economic threat to fair technological competition and U.S. technological leadership”.

Advertisement. Scroll to continue reading.

However, the authoring agencies also note the Chinese companies leverage additional techniques not present in MITRE ATLAS, thus distinguishing the process from an opportunistic exploitation. This is a planned and well-resourced national level action.

The novel TTPs are described as regional restriction evasion and subscription exploitation; centralized request routing infrastructure, automated request metadata sanitization; and systematic quota and cost optimization.

Mitigations proffered by the agencies should be coordinated across the broader US AI ecosystem, including cloud providers, API aggregators, and infrastructure providers. Recommendations include purely defensive actions (such as behavioral detection and monitoring, including examples of the behavior that could be detected), to more aggressive strike back responses. For the latter, the agencies suggest that “Employing targeted changes in response to high-confidence malicious distillation requests can impose meaningful costs on knowledge distillation campaigns.”

Sharing information about distillation campaigns is of course recommended. “Multi-source correlated activity enables more confident attribution of malicious knowledge distillation campaigns, justifying response degradation with lower-to-no legitimate user risk.”

The principle of differential privacy is also recommended. It could be implemented by “adding calibrated noise to model outputs and preventing malicious actors from extracting training data membership information and other sensitive model information, such as decision boundaries or signals that could help reconstruct private data.”

The purpose of the report is to alert all AI stakeholders that Chinese AI companies are systematically and, on an industrial scale, effectively stealing US technological leadership. The threat is not directly to the enterprise use of AI (although adversarial knowledge of how an AI defense might respond could potentially allow a more sophisticated and evasive attack). The threat is more directly to US technology leadership and consequently to the US economy and could potentially lead to a national security issue.

Related: Trump Administration Vows Crackdown on Chinese Companies ‘Exploiting’ AI Models Made in US

Related: Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Related: Nuclear-Sabotage Malware Benchmark Trips Up Most Frontier AI Models

Related: Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors

Related Content

Artificial Intelligence

Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data.

Artificial Intelligence

Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions.

Artificial Intelligence

OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.

Artificial Intelligence

Catch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access.

Artificial Intelligence

New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.

Artificial Intelligence

The startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks.

Artificial Intelligence

The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain.

Artificial Intelligence

Anthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version