Back to articles
Policy & Regulation

US Accuses Six Chinese AI Firms of Large-Scale Model Distillation

3 min read

The US government is turning the dispute over large language model distillation into a broader national-security and industrial-policy issue. In a joint statement, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation accused DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting capabilities from US frontier models since at least late 2024. The agencies said the companies likely acted with Chinese government awareness. The material, however, presents these points as government allegations rather than findings established through a court process.

Key points

  • Multiple US model providers were allegedly targeted. The agencies referenced variants of Claude, GPT, Gemini, and Grok. DeepSeek was accused of seeking a broad range of capabilities, while Moonshot AI was said to have switched among leading models to study fine-tuning, reinforcement learning, software engineering, and mathematics. Other firms were described as focusing on selected capabilities from Anthropic and OpenAI systems.
  • Scale is central to the allegation. Investigators say the campaigns may rely on bulk purchases or shared premium subscriptions, large numbers of fraudulent accounts, and proxy services that bypass geographic restrictions. Coordinated prompts can then generate thousands to millions of responses for synthetic training datasets, reducing the time and expense of developing a frontier system from scratch.
  • Prompt injection is another alleged technique. The statement says attackers used jailbreak-style prompts to make models reveal hidden step-by-step reasoning or explain how an answer was produced. The source material does not include an independent technical audit, so these details should be treated as official claims.
  • Providers are being urged to harden access controls. Recommendations include stronger identity verification, monitoring unusual accounts and networks, and checking for suspicious gaps between subscription levels and usage patterns.

The controversial defense: silent downgrades

The agencies recommend that providers alter responses when they detect suspected distillation. They could preserve the answer while changing the reasoning style, reduce reasoning depth, add controlled inconsistencies, or silently route the account to a less capable model. The goal is to reduce the value of harvested outputs as training data.

Such defenses may be difficult to apply accurately. The agencies say Chinese firms can use automated quality checks to detect capability changes quickly. A false positive could also leave legitimate researchers, developers, or business customers with shorter answers or missing functions without notice. The agencies acknowledge that these measures may reduce prediction accuracy, usefulness, and user satisfaction, and call for a balance between security and service quality. They separately suggest that safety researchers and independent evaluators should be informed about model changes.

Why it matters

The episode shows that competition over frontier models is moving beyond algorithms and computing capacity. API governance, account verification, data provenance, and cross-company intelligence sharing are becoming part of the competitive landscape. For model providers, an inference API is not only a product interface but also a possible channel for systematic capability extraction. For users, tighter identity checks and undisclosed routing changes raise questions about privacy, transparency, and accountability.

The US agencies want companies and allied governments to share indicators of abuse so that isolated incidents are not mistaken for ordinary service failures. At the same time, the Chinese firms named in the allegation and the US model providers whose systems were reportedly targeted had not responded at the time covered by the source. The extent of any unauthorized, coordinated distillation—and whether government coordination occurred—therefore remains subject to further evidence and independent verification.

Source: Ars Technica AI

Comments

Checking sign-in status...

Loading comments...

Related articles