CISA, NSA and FBI Warn of China-Based AI Companies Targeting US AI Models with Industrial-Scale Knowledge Distillation Campaigns to Shortcut AI Development
WASHINGTON – The Cybersecurity and Infrastructure Security Agency (CISA), in collaboration with the National Security Agency (NSA) and Federal Bureau of Investigation (FBI), released a joint cybersecurity advisory today warning of China-based artificial intelligence (AI) companies targeting U.S. AI companies to systematically extract proprietary models through knowledge distillation campaigns. Knowledge distillation is a machine learning technique that involves training a less capable AI model using the outputs of a larger, more capable one. While it’s a valid training method, it can be misused to attempt to acquire capabilities from competitors in less time and with less cost than developing them legitimately. The malicious campaigns described in this advisory form the core of China’s AI development strategy.
Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. The distillation tactics used by China-based AI companies violate the U.S. companies’ terms of service and shorten AI research development for the China-based companies, undermining fair competition.
“CISA is committed to promoting the secure use of AI while fostering the innovation crucial to America’s global competitiveness,” said CISA Acting Director Nick Andersen. “We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies.”
The advisory recommends U.S. frontier companies take three immediate actions:
- Implement comprehensive detection and mitigation: Detect anomalous and malicious prompts, accounts, networks, and behaviors. Additionally, monitor subscription-to-usage ratios, immediate maximum usage from new accounts, and enterprise-scale throughput patterns.
- Deploy targeted response changes: Subtly alter responses for suspected malicious distillation attempts to attenuate the payoffs to companies conducting industrial-scale distillation campaigns.
- Establish cross-organization intelligence sharing: Correlate activity across model providers, cloud platforms, and API aggregators to reveal distributed campaigns.
###
About CISA
As the nation’s cyber defense agency and national coordinator for critical infrastructure security, the Cybersecurity and Infrastructure Security Agency leads the national effort to manage, uncover, and reduce risk to our digital and physical infrastructure Americans rely on every hour of every day.
Visit CISA.gov for more information and follow us on X, Facebook, LinkedIn, Instagram.
Fuente:
Leer la noticia original