China is trying to steal US AI models' secrets, intel agencies warn情报机构警告:中国正试图窃取美国人工智能模型的秘密
NSA, FBI, and CISA cite “aggressive, malicious, and targeted" distillation tactics.

akinbostanci/Getty Images
NSA, FBI, and CISA cite “aggressive, malicious, and targeted" distillation tactics.
China is trying to glean the secrets of U.S. artificial-intelligence models by using simpler AI models to query more advanced American ones, national-security and intelligence agencies warned on Tuesday.
In a joint advisory , the National Security Agency, Cybersecurity and Infrastructure Security Agency and Federal Bureau of Investigation said that Chinese companies DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI used “aggressive, malicious, and targeted distillation ” tactics to extract billions of tokens from the exchanges within U.S. frontier AI models since 2024, likely with Chinese government awareness.
Distillation is used to reduce the time and money needed to create a new model.
“China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use,” the advisory said. “These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate user metadata to avoid detection.”
It said the distillation campaigns targeted variants of Anthropic’s Claude, OpenAI’s ChatGPT, Google’s Gemini, and SpaceXAI’s Grok.
“China-based AI companies deliberately distribute operations across multiple providers, platforms, and pathways to avoid single-point detection,” the advisory said. “They also attempt to distill the best capabilities and proprietary features of each U.S. frontier model to train their China-based AI models. This represents systematic extraction of proprietary functionalities and capabilities threatening U.S. technological leadership.”
The agencies recommended three steps for U.S. AI developers: implement comprehensive detection and mitigation, deploy targeted response changes, and establish cross-organization intelligence sharing.
White House Office of Science and Technology Director Michael Kratsios in July said Chinese distillation efforts — specifically ones by Moonshot AI — have sought to steal proprietary functions from Anthropic’s advanced Fable model. Anthropic made the same accusations in February .
Advocacy groups have also requested the White House take stronger action to keep Chinese companies from importing advanced semiconductor chips .
NEXT STORY: July’s breakout at OpenAI was far more complex than initially realized
akinbostanci/Getty Images
美国国家安全局、联邦调查局和网络安全与基础设施安全局都提到了“激进、恶意和有针对性的”信息提炼策略。
国家安全和情报机构周二警告称,中国正试图通过使用更简单的AI模型来查询更先进的美国AI模型,从而获取美国人工智能模型的秘密。
美国国家安全局、网络安全和基础设施安全局以及联邦调查局在一份联合咨询报告中指出,自 2024 年以来,中国公司 DeepSeek、Moonshot AI、阿里巴巴、MiniMax、StepFun 和 Z.AI 使用“激进、恶意和有针对性的提炼”策略,从美国前沿人工智能模型交易所中窃取了数十亿代币,而中国政府可能对此知情。
蒸馏法用于减少创建新模型所需的时间和金钱。
该咨询报告指出:“总部位于中国的AI公司通过多种途径发送数据提炼请求以获取未经授权的访问权限,从而违反了美国AI公司的使用条款。这些途径包括原生应用程序编程接口(API)、远程云服务提供商以及会自动混淆用户元数据以逃避检测的第三方聚合器。”
报告称,此次提炼活动的目标是 Anthropic 的 Claude、OpenAI 的 ChatGPT、Google 的 Gemini 和 SpaceXAI 的 Grok 的变体。
该咨询报告指出:“总部位于中国的AI公司故意将运营分散到多个供应商、平台和渠道,以避免被单一检测点发现。他们还试图提炼美国前沿模型的最佳功能和专有特性,用于训练其在中国的AI模型。这代表着对专有功能和能力的系统性窃取,威胁着美国的科技领先地位。”
这些机构建议美国人工智能开发人员采取三项措施:实施全面的检测和缓解措施、部署有针对性的响应变更以及建立跨组织的情报共享。
白宫科技办公室主任迈克尔·克拉齐奥斯 (Michael Kratsios) 在 7 月份表示,中国的人工智能蒸馏项目——特别是 Moonshot AI 的项目——试图窃取 Anthropic 公司先进 Fable 模型中的专有功能。Anthropic 公司在 2 月份也提出了同样的指控。
倡导团体还要求白宫采取更有力的措施,阻止中国公司进口先进的半导体芯片。
下一篇报道:7 月份 OpenAI 的突破性进展远比最初预想的要复杂得多。