Key facts
- Six Chinese AI firms are accused of industrial-scale attacks to distill US frontier AI model capabilities.
- The firms named are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
- The alleged attacks began at least in late 2024 and likely occurred with Chinese government awareness.
- Methods include exploiting AI model inference APIs with fake accounts and prompt injection to reveal reasoning.
- US agencies recommend firms subtly alter responses, switch suspected attackers to inferior models without notice, and share information.
The United States has identified six Chinese artificial intelligence firms accused of conducting industrial-scale attacks to distill capabilities from US frontier AI models, potentially saving billions in development costs. In a joint release, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) alleged that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been engaged in these activities since at least late 2024.
Agencies stated that these Chinese companies likely acted with "Chinese government awareness" when extracting proprietary functionalities and capabilities from US models, including variants of Claude, GPT, Gemini, and Grok. The methods employed reportedly include exploiting AI model inference APIs by using bulk-purchased fake accounts that execute highly coordinated queries. Another technique involves prompt injection to force models to reveal their internal reasoning processes, such as DeepSeek allegedly instructing models to articulate step-by-step reasoning.
To combat these alleged thefts, US agencies recommended that AI firms improve detection of sophisticated campaigns, which often use thousands of accounts routed through proxies to evade geographical restrictions. They also advised firms to monitor for anomalous prompts, accounts, and behaviors, and to flag suspicious subscription usage patterns. A key recommendation is for US firms to subtly alter model responses when suspected distillation attacks are flagged, such as by presenting correct information with different reasoning or reducing reasoning depth. Firms were also encouraged to secretly switch malicious accounts to inferior models without prior notification, though agencies acknowledged this could be technically challenging and potentially impact legitimate users.
Agencies stressed the importance of balancing security with user experience, accepting that some trade-offs in prediction precision might be necessary. They also urged AI firms and allied governments to share information to track evolving attack methods and prevent isolated research. Previous accusations against DeepSeek, Google, and Anthropic regarding cloning attacks were noted, with the joint statement representing the Trump administration's most detailed accusation to date.

Discussion