U.S. cyber and intelligence agencies have issued a joint advisory warning that China-based artificial intelligence companies are systematically extracting proprietary capabilities from U.S. frontier models through industrial-scale knowledge distillation campaigns.[1][2][14] The alert, released by CISA in coordination with NSA and FBI, says these campaigns form the core of some firms’ AI development strategies rather than a supplemental technique, raising both national security and economic espionage concerns.[1][2]
Knowledge distillation is a process in which an attacker sends large volumes of carefully engineered queries to a “teacher” model, captures the outputs—including detailed reasoning—and uses those input–output pairs to train a “student” model that mimics the original system.[5][6][11] Researchers note that adversarial distillation can replicate a frontier model’s core capabilities without reproducing its safety measures, allowing rivals to approximate benchmark performance at a fraction of the cost while sidestepping alignment mechanisms and guardrails.[6][8][13]
The joint advisory and recent industry reporting identify Chinese AI firms including DeepSeek, Moonshot AI, Alibaba’s Qwen team, MiniMax, StepFun and Z.AI as running large-scale distillation campaigns against leading U.S. models.[2][10][14] According to U.S. officials and Anthropic’s allegations, these companies have extracted billions of tokens across millions of requests from systems such as Claude, GPT, Gemini and Grok since at least late 2024, in some cases allegedly using tens of thousands of proxy accounts and jailbreaking techniques to evade detection.[2][4][10] Policy researchers warn that such campaigns could accelerate development of models with military or other dual-use applications by cheaply copying advanced capabilities from American systems.[13][15]
In April 2026, the White House Office of Science and Technology Policy issued Memorandum NSTM-4, formally classifying systematic capability extraction from frontier AI systems through adversarial distillation as a national security threat and directing federal agencies to harden AI deployments.[4][6][12] The following day, the U.S. State Department circulated a diplomatic cable instructing missions worldwide to raise concerns with foreign governments about Chinese companies’ attempts to “extract and distill” U.S. AI models, explicitly naming firms such as DeepSeek, Moonshot AI and MiniMax.[3][7] Subsequent briefings and public statements from the administration have framed these activities as deliberate, industrial-scale campaigns to steal American AI breakthroughs, with officials signaling potential trade and sanctions responses.[4][9][15]
Security researchers and industry groups warn that distillation attacks expose a hidden risk in the enterprise AI supply chain by enabling adversaries to train knockoff models that appear comparable on select benchmarks while bypassing licensing costs and safety infrastructure.[5][8][11] Because the attack relies on querying legitimate APIs rather than exploiting traditional software vulnerabilities, defenders may not see obvious indicators of compromise even as a sustained campaign quietly clones key capabilities for use in competing commercial products or state-backed systems.[5][11][13] Analysts caution that once powerful models are replicated this way, downstream misuse—such as automated vulnerability discovery, targeted disinformation or scalable social engineering—becomes harder to control across jurisdictions.[11][13][15]
In their latest advisory, U.S. agencies urge AI providers to treat anomalous access patterns—such as high-volume, systematically varied queries, bursts of activity from proxy infrastructure and extensive jailbreaking attempts—as potential indicators of adversarial distillation rather than ordinary usage.[1][2][12] Recommended countermeasures include tightening access controls around frontier models, enforcing aggressive rate limits, deploying behavioral analytics to flag model-copying campaigns, and expanding logging to support investigations and potential civil or criminal action.[1][2][9] Policymakers are also calling for greater information sharing between labs and regulators, as well as clearer contractual terms on model use, to make it easier to detect and deter cross-border attempts to siphon U.S. AI capabilities at scale.[6][9][12]
References
- China-Based Artificial Intelligence Companies Conducting …
- CISA, NSA and FBI Warn of China-Based AI Companies …
- US State Dept orders global warning about alleged AI …
- White House accuses China of ‘deliberate, industrial-scale …
- Distillation attacks expose hidden risk in enterprise AI supply chain
- [PDF] NSTM-4: US Policy Response to AI Model Distillation Attacks
- U.S. Government Flags Chinese AI Model Extraction Attempts
- [PDF] Issue Brief: Adversarial Distillation
- US Seeks to Halt US AI Model ‘Exploitation’ by Chinese Rivals
- Anthropic distillation battle turns to dark web, China concerns swell
- Securing AI Model Weights: Preventing Theft and Misuse of Frontier Models
- NSTM-4: US Policy Response to AI Model Distillation Attacks
- AI Distillation Attacks: The Case for Targeted Government …
- U.S. agencies say top Chinese AI companies systematically copied American models
- As AI grows more powerful, a US-China feud threatens safety efforts
