NSA, CISA, FBI issue advisory to curb China-based AI distillation attacks

U.S. AI firms must adopt detection, response and intelligence-sharing measures against industrial-scale knowledge-distillation by Chinese companies, effective immediately

Three U.S. Customs and Border Protection Air and Marine Operations aircraft, distant top, conduct a flyover of the U.S. Department of Homeland Security Headquarters, St. Elizabeths

The National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation released a joint Cybersecurity Advisory that obligates U.S. artificial-intelligence providers to implement specific safeguards against industrial-scale knowledge-distillation campaigns conducted by China-based AI firms.

The advisory warns that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI have been extracting proprietary functionalities from U.S. frontier models - including variants of Claude, GPT, Gemini and Grok - through systematic, high-volume distillation since at least late 2024. These campaigns target reasoning, domain-specific optimizations, agentic functions and other capabilities that underpin the competitive edge of U.S. models.

China-based actors employ multiple pathways to bypass geographic restrictions and terms of use, routing requests through native APIs, remote cloud providers, third-party aggregators and a gray market of proxies known as "transfer stations." The advisory notes that bulk procurement of premium subscriptions enables the extraction of billions of tokens across millions of exchanges, while tactics such as chain-of-thought reasoning extraction, automated failover between pathways and sophisticated quality-evaluation frameworks further reduce detection risk.

To mitigate the threat, the agencies recommend three immediate actions. First, AI companies should deploy comprehensive detection of anomalous prompts, accounts, network behavior and usage patterns, including monitoring subscription-to-usage ratios and enterprise-scale throughput. Second, providers should subtly alter responses to suspected distillation attempts to diminish the payoff for adversaries. Third, firms must establish cross-organization intelligence-sharing mechanisms that correlate activity across model providers, cloud platforms and API aggregators.

The advisory attributes the scale and sophistication of the campaigns to likely awareness by the Chinese government, emphasizing that the systematic extraction of proprietary capabilities poses a direct challenge to U.S. technological leadership and warrants coordinated response across the AI ecosystem.

Keep reading