Chinese AI Firms Engage in Industrial-Scale Knowledge Distillation Against US Competitors
US agencies warn that China-based AI companies are systematically extracting proprietary functionalities from US AI models through large-scale knowledge distillation campaigns, posing a threat to US technological leadership.

A coordinated alert from the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) has exposed a significant threat to the US artificial intelligence (AI) sector: industrial-scale knowledge distillation campaigns orchestrated by Chinese AI companies. These campaigns are not merely supplementing AI development but are the core strategy for entities like DeepSeek, Alibaba, and Moonshot AI, aiming to extract proprietary functionalities and capabilities from leading US AI models.
The primary objective of these operations is to accelerate the development of Chinese AI models by illicitly acquiring the advanced features and performance characteristics of US-based frontier models, including variants of OpenAI's GPT, Google's Gemini, and Anthropic's Claude. This systematic extraction significantly reduces the research and development timelines and financial expenditures required for Chinese companies to train competitive AI models, thereby undermining US technological leadership in the field.
Evidence suggests that since at least late 2024, companies such as DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun, and Z.AI have collectively extracted billions of tokens through millions of requests directed at US AI models. DeepSeek, for instance, has been actively targeting reasoning capabilities and specialized domain functions to enhance its own R1 and V3 models, with publicly stated training costs that appear to omit the substantial expenses incurred through these malicious distillation efforts.
To circumvent detection and bypass terms of use, Chinese AI firms employ sophisticated tactics. They route distillation requests through multiple obfuscated pathways, including native APIs, remote cloud providers, and third-party aggregators that mask user metadata. Furthermore, a gray market of proxies, referred to as "transfer stations," is utilized to bypass geographic restrictions and evade safeguards, making traceability difficult.
Advanced techniques observed in these campaigns include chain-of-thought (CoT) reasoning extraction, automated failover mechanisms to counter blocking attempts, and robust quality evaluation frameworks designed to assess and adapt to defensive countermeasures. These methods highlight the organized and resource-intensive nature of the distillation operations.
The implications of these activities extend beyond competitive disadvantage. By reducing the need for original research and development, these campaigns could stifle innovation within the US AI ecosystem and create dependencies on stolen intellectual property. The scale and systematic nature of the extraction suggest a potential awareness or tacit approval from the Chinese government, further amplifying concerns about national security and economic competitiveness.
In response, the authoring agencies recommend a multi-pronged approach for US AI companies. This includes implementing comprehensive detection and mitigation strategies to identify anomalous prompts, accounts, and network behaviors, alongside monitoring for unusual subscription-to-usage ratios and enterprise-scale throughput. Targeted response changes, such as subtly altering responses to suspected malicious distillation attempts, are also advised to reduce the payoff for attackers.
Finally, the agencies emphasize the critical need for cross-organization intelligence sharing. By correlating activity across model providers, cloud platforms, and API aggregators, the AI ecosystem can better reveal and counter these distributed, industrial-scale campaigns. This collaborative effort is deemed essential to protecting the integrity and leadership of the US AI industry.
This new advisory from the NSA, CISA, and FBI provides specific details on the tactics employed by Chinese AI firms, including DeepSeek, Moonshot AI, and Alibaba. It outlines how these companies used millions of queries and billions of tokens across various U.S. models like Claude, ChatGPT, and Gemini to train their domestic models, and details sophisticated methods used to obfuscate metadata and bypass restrictions.