The U.S. government officially announced that DeepSeek, Alibaba and other Chinese artificial intelligence (AI) corporations bypassed access to AI models such as OpenAI and Anthropic to collect answers in bulk and used them to develop their own models. It said Chinese corporations conducted "distillation" activities targeting advanced U.S. AI to cut the expense and time required for research and development.
The National Security Agency (NSA), the Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) issued a joint report on the 8th, local time, saying that "Chinese AI corporations are carrying out aggressive and malicious distillation activities at an industrial scale."
Distillation is a technique that uses a high-performing large AI as a "teacher model" to train a smaller or lower-performing "student model." It presents numerous problems to the teacher model and uses the answers and solution steps obtained as training data for the student model. The technique is widely used to make AI models smaller and cheaper, but the U.S. government noted that Chinese corporations collected answers in bulk without permission from U.S. AI corporations and used them to train their own models.
The corporations named by the U.S. government are six in total: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. It was found that since late 2024 they sent millions of queries to OpenAI's GPT, Anthropic's Claude, Google's Gemini and xAI's Grok, collecting billions of tokens. The U.S. government judged that they used the collected answers and problem-solving steps as training data to boost the performance of their own AI models.
In particular, in China, models from OpenAI and Anthropic cannot be used officially. U.S. authorities explained that Chinese AI corporations even mobilized relay networks known as "transfer stations" to circumvent this. When a Chinese user sends a request to an overseas transfer station such as Singapore, local servers and fake accounts access U.S. AI on their behalf, receive answers and relay them back. It was found that they distributed requests across multiple accounts and cloud providers, and concealed the actual user by automatically switching to other routes when a specific account was blocked.
The U.S. government argued that distillation is not merely an auxiliary means for Chinese AI corporations but a core foundation of model development. With computing resources reduced by export controls on advanced AI Semiconductor chips, Chinese corporations used the outputs of U.S. AI models developed at massive expense to cut trial-and-error and training expense. The report analyzed that these activities were likely carried out with the Chinese government's awareness.
U.S. authorities advised domestic AI corporations to strengthen fake account detection and usage limits. For accounts suspected of engaging in malicious distillation, they also proposed providing answers from lower-performing models or mixing noise into responses. The idea is to reduce the effectiveness of distillation by causing attackers to mistake low-quality data for legitimate answers and train on it.