China AI Firms Scale Knowledge Distillation to Target U.S. Frontier Models
An NSA/CISA/FBI cyber advisory warns that China-based AI firms are conducting industrial-scale knowledge distillation to extract proprietary capabilities from U.S. frontier models (e.g., Claude, GPT-4/5, Gemini, Grok), using multiple access routes, proxies, and gray-market APIs to bypass restrictions and safeguards. Campaigns involving DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI since 2024–2026 target reasoning, SFT, coding, and agentic functions, with sophisticated routing, QA, and prompt-injection techniques. The agencies call for rapid detection (anomalous prompts/accounts, subscription abuse, throughput anomalies), targeted response changes to raise attacker costs, and cross‑organization intel sharing, guided by MITRE ATLAS and NIST AI mitigations (e.g., differential privacy, pre/post-training interventions, and safe prompt practices).
