NSA Flags Industrial Distillation of Frontier Models
NSA, CISA, and the FBI said China-based AI companies have been running industrial-scale distillation campaigns against U.S. frontier model providers since at least late 2024. The advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, and says they extracted billions of tokens across millions of requests from models including Claude, GPT, Gemini, and Grok.
The pattern is simple: the attacker treats the model like a teacher, sends huge volumes of ordinary-looking prompts, and trains a cheaper copy from the answers. The groups hid that traffic behind native APIs, cloud providers, third-party aggregators, and proxy “transfer stations,” so the requests could look like normal usage while evading geographic restrictions and terms of use.
For any public AI API or assistant, the exposure is not just theft of data or weights. A provider can lose proprietary behavior, reasoning patterns, and domain-specific functions even when the training environment stays untouched, and access control alone does not stop capability extraction at scale.