{"id":16328,"date":"2026-09-09T20:06:28","date_gmt":"2026-09-09T20:06:28","guid":{"rendered":"https:\/\/demo.tcjhomeaccents.com\/wp\/2026\/09\/09\/six-chinese-ai-firms-accused-of-aggressively-copying-us-frontier-models\/"},"modified":"2026-09-09T20:06:28","modified_gmt":"2026-09-09T20:06:28","slug":"six-chinese-ai-firms-accused-of-aggressively-copying-us-frontier-models","status":"publish","type":"post","link":"https:\/\/demo.tcjhomeaccents.com\/wp\/2026\/09\/09\/six-chinese-ai-firms-accused-of-aggressively-copying-us-frontier-models\/","title":{"rendered":"Six Chinese AI firms accused of aggressively copying US frontier models"},"content":{"rendered":"<p>Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only \u00a0\u00a0Learn more Minimize to nav The United States has now named six Chinese AI firms accused of waging industrial-scale attacks distilling US frontier AI model capabilities and perhaps sparing billions in Chinese development costs. In a joint release Tuesday, the National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) alleged that DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI have been attacking US models since at least late 2024. The firms \u201clikely\u201d acted with \u201cChinese government awareness\u201d when extracting capabilities from US models, including variants of Claude, GPT, Gemini, and Grok, agencies said. \u201cChina-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines and reduced financial expenditures in training a frontier model,\u201d agencies said. All American AI firms must work with the government and US allies to end the alleged theft threatening the US lead in the AI race, the agencies said.<\/p>\n<p>That will require coordinated action across the AI ecosystem to combat the \u201caggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of US frontier AI models.\u201d Attack methods include \u201cexploiting AI model inference APIs\u201d by bulk-buying fake accounts, agencies said. Not registered to legitimate users, these swarms of fraudulent accounts execute \u201chighly coordinated queries featuring identical or similar prompt texts,\u201d which range \u201cfrom thousands to millions on similar topics.\u201d Another common method is using prompt injection techniques to jailbreak models, including crafting \u201cprompts forcing models to reveal their hidden [chain-of-thought] reasoning,\u201d agencies said. For example, \u201cDeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses and write it out step by step.\u201d Fixes may frustrate AI users in US To encourage firms to work together, agencies recommended mitigations that would supposedly make it harder for Chinese firms to steal from US models. First, AI firms must improve detection of sophisticated campaigns that allegedly use tens of thousands of accounts relying on \u201ca gray market of proxies\u201d to evade geographical restrictions and \u201croute distillation requests through multiple pathways to gain unauthorized access.\u201d Flagging this activity should be somewhat easy, agencies suggested, since \u201ccampaigns span days to months with query volumes in the thousands to millions per domain, far exceeding legitimate research or development use cases.\u201d Generally, they\u2019ve recommended stepping up monitoring for \u201canomalous and malicious prompts, accounts, networks, and behaviors.\u201d Because Chinese firms rely on \u201cbulk procurement of the US AI companies\u2019 premium subscriptions shared across teams of developers,\u201d that effort should also include flagging accounts with suspicious subscription-to-usage ratios, as well as any new accounts immediately hitting maximum usage, agencies said.<\/p>\n<p>Both indicate \u201cbulk deployment with pre-engineered templates,\u201d agencies said. US firms should also be strengthening \u201cidentity verification\u201d of users and more closely tracking individuals using enterprise subscriptions (both of which potentially raise privacy red flags for legitimate users). Next, agencies asked firms to start dumbing down model responses when suspected distillation attacks are flagged. By \u201csubtly\u201d altering responses\u2014such as by \u201cpresenting correct information with different reasoning,\u201d adding stylistic inconsistencies, or reducing reasoning depth\u2014firms can decrease the payoff for Chinese firms.<\/p>\n<p>US firms could also secretly switch malicious accounts to an inferior model, and they should do so without providing any notice, agencies suggested. That particular mitigation step will likely be technically challenging. Agencies acknowledged, for example, that Chinese firms \u201cemploy aggressive, adaptive discovery to systematically identify valuable extractable data,\u201d which they then collect to generate synthetic training datasets. Some firms can automatically detect when a smarter model is available and switch within 24 hours.<\/p>\n<p>They also have automated quality assurance systems that detect when outputs are degraded and can otherwise differentiate ordinary \u201cservice issues from defensive data degradation,\u201d agencies said. Also problematic: if US firms aren\u2019t careful with targeting, any legitimate users perhaps caught up in the policing frenzy might be switched to a dumber model without receiving any alert. Or they could suddenly receive shorter responses or experience withheld capabilities, agencies acknowledged. Additionally, firms may possibly add \u201cnoise\u201d to the output that restricts further queries.<\/p>\n<p>Users will likely notice if outputs degrade, just like Chinese systems attacking models would. Last year, OpenAI quickly made changes to its automatic routing system after facing swift backlash when that system \u201cconsistently defaulted to less capable variants unless users explicitly added phrases like \u2018think harder\u2019 to their prompt,\u201d Ars reported. Still, agencies think it\u2019s best practice to \u201cavoid informing China-based AI company users suspected of distillation campaigns of a switch to a downgraded model.\u201d Acknowledging that such steps could frustrate users, agencies said that firms should try to \u201cbalance security with user experience\u201d while accepting that some trade-offs, like \u201clower prediction precision and business usefulness,\u201d may be inevitable to keep China from copying US capabilities. However, US firms should strive to ensure that \u201cAI safety researchers and third-party evaluators\u201d are \u201cinformed of model changes,\u201d agencies suggested.<\/p>\n<p>Finally, and seemingly most critical to the defense strategy long-term, agencies want AI firms and allied governments to share information to help leading firms track how distillation attacks evolve and avoid wasting time researching isolated anomalies. Cooperation is critical, the US thinks. If everyone cannot work together, then the US will face ongoing financial harm \u201cthrough systematic extraction of proprietary functionality and capabilities, causing significant economic losses,\u201d agencies warned. What did Chinese firms do?<\/p>\n<p>AI firms have been warning about distillation attacks since last year. OpenAI accused DeepSeek of using data improperly, Google claimed attackers tried to clone Gemini, and Anthropic suggested that Alibaba should be criminally punished for allegedly launching the largest-ever cloning attack on Claude. Very quickly, the government got behind them, in April warning China that a crackdown was coming. The joint statement released on Tuesday, though, was the Trump administration\u2019s \u201cmost detailed accusation yet,\u201d NBC News noted.<\/p>\n<p>In it, agencies claimed that stolen AI model capabilities \u201cform the core\u2014not merely a supplement\u201d\u2014of China\u2019s AI development strategy. DeepSeek was accused of \u201cextensive malicious distillation\u201d on Claude, Gemini, GPT, and Grok models in efforts to \u201creduce its compute and research costs.\u201d The Chinese firm allegedly took specialized training data and a range of capabilities, including agentic functions, assistant capabilities, writing optimization, question-and-answer optimization, and chain-of-thought reasoning. Moonshot AI took a similar approach, switching between models from leading US firms to distill fine-tuning techniques, reinforcement learning, software engineering, and math capabilities. Other firms, including Alibaba, MiniMax, StepFun, and Z.AI, seemed focused on copying particular models from Anthropic and OpenAI, agencies said.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only \u00a0\u00a0Learn more Minimize to nav The United States has now named six Chinese AI firms accused of\u2026<\/p>\n","protected":false},"author":1,"featured_media":16329,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[],"class_list":["post-16328","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/posts\/16328","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/comments?post=16328"}],"version-history":[{"count":0,"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/posts\/16328\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/media\/16329"}],"wp:attachment":[{"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/media?parent=16328"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/categories?post=16328"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/demo.tcjhomeaccents.com\/wp\/wp-json\/wp\/v2\/tags?post=16328"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}