VMTech
Discuss a project

US Agencies Detail Alleged AI Model Distillation Campaigns

US Agencies Detail Alleged AI Model Distillation Campaigns

The National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation have accused China-based AI companies of systematically extracting proprietary capabilities from U.S. frontier AI models. Their joint bulletin says the activity has involved billions of tokens and millions of exchanges or requests since at least late 2024.

The agencies named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The alleged targets include variants of Anthropic Claude, OpenAI GPT, Google Gemini and SpaceXAI Grok. U.S. frontier models are officially restricted and unavailable in China, the advisory said.

Distillation cited as abuse of model access

Distillation can be a legitimate research technique, but the agencies characterized the reported activity as aggressive, malicious and targeted extraction of restricted proprietary functionality at industrial scale. They said the campaigns form a core part of the companies' AI development strategy and can shorten development timelines while reducing the cost of training frontier models.

The bulletin describes bulk procurement of premium subscriptions shared among developer teams as one way to reduce costs. It also identifies chain-of-thought reasoning extraction, automated failover when blocking occurs, and quality-evaluation frameworks intended to identify defensive countermeasures as advanced tactics.

The agencies alleged that DeepSeek ran organized campaigns from late 2024 to mid-2025 targeting reasoning, specialized optimizations and domain-specific functions for its R1 and V3 models. They said Moonshot AI extracted Claude Fable 5 data for Kimi-K3 and GPT-4o data for Kimi-K2. Other allegations concern Alibaba's use of Claude and GPT models, MiniMax's work on M2, StepFun's work on Step 4, and Z.AI's extraction of billions of tokens from GPT-5.5 and Claude Opus 4.8.

Distributed access complicates detection

Requests were allegedly routed through APIs, remote cloud providers and third-party aggregators that obscured user metadata. The advisory also points to virtual private networks, obfuscated accounts and automated agents used to bypass geographic controls, alongside a gray market of relay services using servers outside mainland China. Such services have been marketed through Taobao and Xianyu, it said.

Google Threat Intelligence Group separately reported a recent rise in campaigns against Google's AI models, including some exceeding 100 million prompts. Google said attackers rotate queries through proxy infrastructure, compromised credentials and fraudulent accounts across product channels to obscure their origin and bypass standard controls.

What organizations should do

The U.S. agencies recommend comprehensive detection and mitigation measures, subtle response changes for suspected malicious distillation, and correlation across model providers, cloud platforms and API aggregators. The objective is to expose campaigns deliberately distributed across services.

For businesses using frontier AI services, API keys and service accounts deserve the same protection as other high-value credentials. Access should be limited, usage should be monitored across providers, and unusually large or automated request patterns should be investigated because abuse may otherwise resemble legitimate platform traffic.

#aisecurity#apisecurity#modelsecurity#cybersecurity
Open analytics
On the site 0 views
min read 4 09.09.2026
Instagram

US Agencies Detail Alleged AI Model Distillation Campaigns

Open the post on Instagram ↗