started · updated
U.S. agencies warn of Chinese AI firms using knowledge distillation to extract model logic
U.S. intelligence agencies, including the FBI, CISA, and the NSA, have issued a joint cybersecurity advisory identifying an industrial-scale campaign by Chinese AI firms to extract proprietary capabilities from U.S. frontier models. The firms are reportedly using “knowledge distillation,” a process where a student model is trained on the outputs of a high-performing teacher model to mimic its logic, reasoning, and functionality.
The advisory names six Chinese companies—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—as participants in this effort. These entities have allegedly used millions of requests to harvest billions of tokens from models such as Claude, GPT-4, Gemini, and Grok. This technique allows these firms to bypass the immense computational and financial costs of primary training by harvesting model behavior and reasoning logic, such as Chain of Thought (CoT) processes.
To counter these activities, U.S. agencies recommend that AI providers implement aggressive rate-limiting, anomaly detection, and subtle response modifications. One suggested defense involves providing “less sophisticated, downgraded models” to suspicious users to reduce the training value of the output, without notifying the user of the change to prevent them from improving their evasion techniques.
Entities
Alibaba · CISA · DeepSeek · FBI · National Security Agency