AI Stealing AI? The U.S. Government Warns of China's Model Distillation Campaigns

A technical abstract image visualizing data being extracted and moving through a complex digital network
AI Summary

U.S. intelligence agencies and the FBI have warned that major Chinese AI companies are systematically stealing the capabilities of leading U.S. AI models to utilize in their own technology development.

Imagine this: You have spent years and hundreds of thousands of dollars creating the world’s most delicious secret sauce. Then, one day, someone starts visiting your shop every day to buy a little bit of the sauce, only to analyze it and start making and selling a sauce that tastes exactly the same. How would you feel? This is exactly what is happening in the global AI industry right now.

Recently, U.S. intelligence agencies and the Federal Bureau of Investigation (FBI) released a shocking report stating that major Chinese AI companies are systematically stealing advanced U.S. AI technology. Beyond mere rumors, they are abusing a technology called “distillation” to extract the intellectual property of their competitors in industrial settings Reference 1, Reference 9.

Why does this matter?

AI models are not just a few lines of code. They are “digital assets” that require billions of dollars and elite research teams working for several years to create Reference 2. If such technology can be replicated in an instant without legitimate effort, companies that invest in technological innovation will suffer a major blow. Furthermore, this is intertwining with the tech hegemony competition between nations, escalating beyond a mere business dispute into a national security issue Reference 10.

Easy understanding: What is model distillation?

“Knowledge Distillation” is originally a very useful research technique. It involves extracting only the core knowledge from a very large, intelligent AI model (which is too big to run on personal computers) and transferring it to a small, lightweight model Reference 7, Reference 9. It is similar to summarizing the vast knowledge of a university professor into a reference book that even an elementary school student can understand. Metaphorically, it is like analyzing the core techniques of a masterpiece painting by a master to create a forgery.

However, when used maliciously, it becomes “theft.” Attackers send millions of queries to U.S. AI models (e.g., Anthropic’s Claude) that are currently in service. They then analyze how the AI responds to mimic its internal logic and performance Reference 4, Reference 7.

The data stolen in this way amounts to billions of tokens (the smallest unit of text that AI reads) Reference 3. Through this process, Chinese companies are making the completed, advanced intelligence of the U.S. their own without having to develop models from scratch Reference 3.

Where and how is it happening?

U.S. authorities specifically named six Chinese companies: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI Reference 2, Reference 5. In particular, Anthropic claimed that they launched a large-scale extraction campaign targeting its AI model, “Claude” Reference 4.

To evade monitoring, they showed sophistication by distributing tasks across multiple cloud platforms and mobilizing numerous accounts to appear as legitimate users Reference 8. It is like a thief splitting up into different alleyways to avoid security cameras. The Chinese government and the companies in question have dismissed these U.S. claims as groundless accusations Reference 11.

What will happen in the future?

The U.S. government views this situation seriously and is expected to strengthen legal and technical responses to prevent it Reference 6. Technical measures such as restricting API access to AI models or detecting abnormal bulk requests in real-time will likely increase. It is expected that “security competition to protect technology” will become as fierce as the competition for AI development. Establishing global guidelines for protecting intellectual property in the AI era is more urgent than ever.

References

  1. [US claims Chinese AI firms are carrying out ‘industrial-scale’ theft of trade secrets CNN Politics](https://edition.cnn.com/2026/09/08/politics/us-accuses-china-of-stealing-ai-technology)
  2. [Feds accuse China of ‘systematic’ distillation of U.S. AI models CyberScoop](https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/)
  3. [CISA, NSA and FBI Warn of China-Based AI Companies Targeting US AI Models with Industrial-Scale Knowledge Distillation Campaigns to Shortcut AI Development CISA](https://www.cisa.gov/news-events/news/cisa-nsa-and-fbi-warn-china-based-ai-companies-targeting-us-ai-models-industrial-scale-knowledge)
  4. [TopAIFirm SaysChineseLabs StoleU.S. Tech Using… SGT Report](https://www.sgtreport.com/2026/02/top-ai-firm-says-chinese-labs-stole-u-s-tech-using-24000-fake-accounts/)
  5. [US Names SixChineseAIFirms Accused of Stealing… IBTimes UK](https://www.ibtimes.co.uk/us-agencies-accuse-chinese-ai-firms-extracting-us-ai-model-capabilities-1818601)
  6. OpenAI accuses DeepSeek of modeldistillationin memo to Co
  7. [Alibaba Ran Largest KnownAITheftCampaignAgainstClaude… TechTimes](https://www.techtimes.com/articles/319105/20260625/alibaba-ran-largest-known-ai-theft-campaign-against-claude-anthropic-tells-senate.htm)
  8. [China’s$5.6 MillionAIMiracle Just Got a Lot Less Miraculous PJ Media](https://pjmedia.com/david-manney/2026/09/08/chinas-56-million-ai-miracle-just-got-a-lot-less-miraculous-n4957022)
  9. [China-Based Artificial Intelligence Companies Conducting … CISA](https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-251a)
  10. [US claims Chinese AI companies’ core AI strategy is … The Register](https://www.theregister.com/ai-and-ml/2026/09/09/us-claims-chinese-ai-companies-core-ai-strategy-is-distilling-american-models/5295171)
  11. [US accuses China AI developers DeepSeek and Alibaba of … NBC News](https://www.nbcnews.com/tech/tech-news/us-accuses-china-ai-developers-deepseek-alibaba-copying-american-ai-rcna596696)
AD
Test Your Understanding
Q1. What is the negative usage of the 'model distillation' technology mentioned in the article?
  • Collecting data to train AI models
  • Extracting outputs from unauthorized API access to replicate model capabilities
  • Removing AI models from servers
While model distillation is originally a research technique for creating efficient models, it can be abused as an 'adversarial distillation attack' to secretly steal the capabilities of other models.
Q2. Which of the following is NOT one of the Chinese companies targeted by the U.S. government regarding this campaign?
  • DeepSeek
  • Alibaba
  • Google
The U.S. government named DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI.
Q3. What method are Chinese AI companies known to have used to evade security monitoring?
  • Performing all tasks on a single server
  • Using thousands of fake accounts
  • Distributing operations across multiple model providers and cloud platforms
It is reported that Chinese AI companies used a method of distributing tasks across multiple cloud platforms and AI model providers to avoid tracking.
AI Stealing AI? The U.S. Go...
0:00