A Joint Cybersecurity Advisory issued by the US Cybersecurity & Infrastructure Security Agency (CISA), FBI and National Security Agency (NSA), warns that China-based AI platforms including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024.
DeepSeek has conducted organized campaigns since at least 2024 targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models. Alibaba leveraged industrial-scale distillation to improve the company’s Qwen family of AI models. Moonshot AI, MiniMax, Stepfun, and Z.AI also engaged in malicious knowledge distillation of U.S. AI companies’ models.
Extraction and obfuscation tactics
China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use. These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection.
Further, China-based AI companies use a gray market of proxies known as “transfer stations” to bypass U.S. AI companies’ geographic restrictions, breach terms of use, evade safeguards, and undermine traceability. China-based AI companies achieve cost savings for their industrial-scale distillation campaigns through bulk procurement of the U.S. AI companies’ premium subscriptions shared across teams of developers.

Advanced industrial-scale distillation tactics include chain-of- thought (CoT) reasoning extraction, automated failover between pathways during blocking attempts, and sophisticated quality evaluation frameworks to detect defensive countermeasures. China-based AI companies that conduct industrial-scale distillation against U.S. AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model.
China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection. They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China- based AI models.
This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations.
A range of MITRE ATLAS threat categories, and several novel techniques used by China-based actors, are identified in this Advisory
Recommended best practices
The agencies recommend U.S. AI companies take three immediate actions:
- Implement comprehensive detection and mitigation: Detect anomalous and malicious prompts, accounts, networks, and behaviors. Additionally, monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.
- Deploy targeted response changes: Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.
- Establish cross-organization intelligence sharing: Correlate activity across model providers, cloud platforms, and API aggregators to reveal distributed campaigns.
To help mitigate the identified threats, the report cites about a dozen MITRE ATLAS mitigation guidelines, as well as mitigations in NIST’s “Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations” (NIST AI 100-2e2025) which apply to malicious distillation, including differential privacy, pre- and post-training interventions, and prompt instruction / formatting.
[ Note: This article quotes directly from the CISA/FBI/NSA advisory document ]
Why it matters
The agencies warned that “China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy.
“China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection. They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership. Addressing industrial-scale distillation merits a coordinated response across the AI ecosystem, including effective information-sharing, spanning the U.S. Government, private industry, and allied nations.”
The agencies believe that the Chinese government may be aware of the activities.
Further reading
China-based Artificial intelligence companies conducting industrial-scale distillation cmpaigns against US AI companies. Cybersecurity Advisory. September 8, 2026. Issued jointly by the US Cybersecurity & Infrastructure Security Agency (CISA), FBI and National Security Agency (NSA)
NIST AI 100-2 E2025 Adversarial machine learning: A taxonomy and terminology of attacks and mitigations. Guideline document. Published March 24, 2025. by Computer Security Resource Center, National Institute of Standards and Technology
[Note: The CISA/FBI/NSA advisory document is marked TLP:CLEAR. Recipients may share this information without restriction. Information is subject to standard copyright rules. U/OO/6059854-26 | PP-26-3853 | September 2026 Ver 1.0 ]









