Illustration of U.S. and Chinese AI chips exchanging data through a funnel representing AI model distillation.

China Pushes Back on U.S. AI Model Extraction Claims

U.S. agencies accuse Chinese AI firms of mass model extraction. Beijing calls it standard practice.

China rejected U.S. accusations Wednesday that six of its leading artificial intelligence companies conducted industrial-scale campaigns to extract capabilities from American frontier models, opening a fight over where legitimate AI distillation ends and model theft begins.

China’s Commerce Ministry said the allegations were unsupported by fact or law and accused Washington of turning a normal AI-development practice into a security issue. Beijing said distillation is widely used by model developers worldwide, including U.S. companies, and warned it would respond if the accusations are used to restrict Chinese AI firms.

Beyond the Break weekly cybersecurity newsletter — Subscribe

The response came a day after the NSA, CISA and FBI accused DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of extracting billions of tokens through millions of requests from U.S. frontier models since at least late 2024. The agencies said the activity occurred “likely with Chinese government awareness.”

At the center of the dispute is knowledge distillation, a legitimate technique in which outputs from a more capable model are used to help train another. U.S. officials argue the Chinese campaigns crossed into malicious activity because of their scale and alleged use of proxy networks, account pools and other techniques to circumvent geographic restrictions, safeguards and detection.

China says the United States is moving that line.

Its Commerce Ministry accused Washington of applying a double standard and using security agencies to protect U.S. advantages in AI and computing power. Foreign Ministry spokesperson Mao Ning separately said China’s AI advances resulted from technological development and openness and urged the United States to stop making what Beijing called false accusations.

“Nobody in the research community is surprised that distillation is happening,” said Joe Brinkley, head of offensive security at Cobalt. “Every frontier lab knows inference data feeds competing pipelines.”

What stands out, Brinkley said, is the government treating aggressive extraction and quota evasion as an adversarial attack.

“A Terms of Service agreement is not an access control,” he said. “When you expose your core asset over a public HTTP endpoint, relying on billing tiers and naive IP bans to protect model capability was always an engineering blind spot.”

Distillation at Scale

The joint CISA advisory alleges the Chinese companies sought capabilities including chain-of-thought reasoning, coding, software engineering, reinforcement learning and agentic functions.

Requests were routed through model APIs, cloud providers, third-party aggregators and gray-market proxies known as “transfer stations,” according to the agencies. Operators allegedly distributed traffic across accounts and providers and shifted pathways when access was blocked.

CISA argues those behaviors distinguish the campaigns from ordinary development. The agencies mapped the activity to MITRE ATLAS, a framework for tracking adversarial behavior against AI systems.

DeepSeek allegedly targeted reasoning and domain-specific capabilities for its R1 and V3 models. Alibaba used distillation to improve its Qwen family, while Moonshot AI, MiniMax, StepFun and Z.AI targeted various coding, reasoning and agentic capabilities, according to CISA.

The government warning builds on evidence previously published by Anthropic.

In February, Anthropic said DeepSeek, Moonshot and MiniMax generated more than 16 million Claude exchanges through approximately 24,000 fraudulent accounts. MiniMax accounted for more than 13 million exchanges and Moonshot more than 3.4 million.

Anthropic said the campaigns used proxy services and coordinated accounts to distribute traffic and avoid detection. One proxy network managed more than 20,000 fraudulent accounts simultaneously.

The individual prompts were not necessarily malicious. The signal emerged when similar requests appeared tens of thousands of times across coordinated accounts targeting capabilities useful for training competing models.

That is also what makes the problem difficult to defend against: the same API designed to expose a model’s capabilities to paying customers can be used to systematically study and reproduce them.

APIs Become the Security Boundary

Brinkley said AI providers need to treat inference APIs as production attack surfaces rather than relying primarily on terms of service and geographic restrictions.

“If providers want to protect their models from extraction, they need to defend them at the application layer with real behavioral telemetry, sybil defenses, and output controls,” he said.

CISA recommends monitoring coordinated accounts and infrastructure, abnormal usage patterns and new accounts immediately consuming maximum quotas. The agencies also recommend sharing intelligence across AI providers, cloud platforms and API aggregators.

For high-confidence extraction attempts, CISA suggests providers could quietly reduce reasoning depth, alter responses or route suspected operators to less capable models.

Bri Frost, director of product management at Cloud Range, said frontier models should be treated as strategic assets, with security built around model access, APIs, identities, behavioral monitoring and testing. “We cannot assume a model is secure because it sits behind an API or because a policy says certain behavior isn’t allowed,” he said.

For security teams, the U.S.-China argument over whether the activity constitutes theft may be less immediate than the technical reality underneath it. A frontier model’s inference endpoint is both its front door for customers and a potential pathway for competitors trying to extract what makes the model valuable.

Total
0
Shares
Previous Article
Pink bar of soap embossed with "Redis Botnet Club," representing a cryptomining botnet exposed by its own operator

Oops: Botnet Operator Botches Crypto Campaign

Next Article
Cisco logo displayed against a red-toned cybersecurity threat graphic

Critical Cisco Firewall Bug Under Attack by Sandworm APT

Related Posts

Discover more from Security Point Break

Subscribe now to keep reading and get access to the full archive.

Continue reading