The United States has named six Chinese companies that American intelligence agencies accuse of conducting industrial‑scale attacks to misappropriate capabilities from advanced US AI models. According to US agencies, this practice allows Chinese firms to significantly shorten their own development timelines and save billions of dollars in training costs.
In a joint statement released on Tuesday, the US National Security Agency (NSA), the Cybersecurity and Infrastructure Security Agency (CISA), and the Federal Bureau of Investigation (FBI) said that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been attacking American models since at least late 2024.
The agencies stated that these companies «likely» acted «with the knowledge of the Chinese government» to obtain capabilities from American models, including versions of Claude, GPT, Gemini, and Grok.
«Chinese AI companies that engage in the industrial‑scale distillation of US AI models gain significantly shorter development timelines and lower financial costs for training an advanced model,» the US agencies said.
They urged all American AI companies to cooperate with the US government and its allies to counter actions that, according to US authorities, threaten American leadership in artificial intelligence. The agencies noted that this requires coordinated measures across the entire AI ecosystem to combat «aggressive, malicious, and targeted industrial‑scale distillation,» which is used to obtain restricted proprietary functionalities and characteristics of advanced American models.
How Chinese companies obtain data from models
According to US agencies, one method involves using APIs to retrieve responses from AI models through the mass purchase of dummy accounts. These networks of fraudulent accounts, not registered to real users, execute «highly coordinated queries with identical or similar prompt texts». They can generate anywhere from thousands to millions of requests on related topics.
Another common method is the use of prompt injection techniques to bypass model security. Specifically, this involves creating prompts that force models to reveal their hidden chain‑of‑thought reasoning.
The US agencies cited DeepSeek as an example, saying it used prompts that compelled models to imagine and disclose the internal reasoning steps that led to their final answers.
New restrictions may affect AI users
To encourage companies to jointly counter such campaigns, US agencies recommended a series of measures they believe will make it harder for Chinese firms to obtain capabilities from American models.
In particular, companies were advised to improve detection of sophisticated campaigns that employ tens of thousands of accounts. The agencies said such operations may rely on a «gray market of proxy servers» to bypass geographic restrictions and route requests through multiple channels to gain unauthorized access.
At the same time, strengthening these security measures could impact regular users of American AI services, as companies will need to enforce stricter controls over access to their models.
Source: Ars Technica



