Cybersecurity

U.S. Agencies Accuse Six Chinese Companies of Extracting Billions of Tokens from Advanced AI Models

CISA, NSA, and the FBI said that six Chinese artificial intelligence companies carried out extensive operations to extract outputs from advanced U.S. models through billions of tokens and millions of requests since late 2024. The agencies recommend improving monitoring of API abuse and sharing indicators of these campaigns among companies.

2026-09-09
4 min read
8 views
فريق تحرير certi.news
U.S. Agencies Accuse Six Chinese Companies of Extracting Billions of Tokens from Advanced AI Models

U.S. cybersecurity and intelligence agencies said that six Chinese artificial intelligence companies had carried out large-scale operations, since at least late 2024, to extract knowledge from advanced U.S. artificial intelligence models. According to a joint warning issued by CISA, NSA, and the FBI, the operations involved billions of tokens generated by millions of requests directed at models from Anthropic, OpenAI, Google, and xAI.

The companies named in the warning are DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies say that the scale and complexity of the operations indicate Chinese government awareness of them, and that this approach may represent a fundamental part of the development strategy of the companies involved. The published material did not include responses from these companies; BleepingComputer said it had contacted them for comment.

What Are Model-Distillation Attacks?

Model distillation is a legitimate technique in which a “student” model learns from the outputs of a more extensively trained model, with the aim of reducing training costs and accelerating the deployment of a new system. However, the U.S. agencies distinguish between controlled research use and what they described as distillation attacks that exploit APIs to extract a model’s knowledge and reasoning outside the environment controlled by its owner.

CISA explains that the companies attributed to the operations distributed requests across fraudulent or shared accounts, APIs, cloud services, aggregators, and “transfer-station” agents. These routes enabled attempts to circumvent geographic restrictions, usage limits, and monitoring systems. Some prompts also included attempts to extract prohibited chain-of-thought reasoning, while automated systems switched service providers and tested whether responses had degraded after defensive measures were applied.

What Did the Agencies Observe?

The warning classified DeepSeek and Moonshot AI as the most prominent entities targeting multiple models from Claude, GPT, Gemini, and Grok. It said that MiniMax targeted Claude, Gemini, and GPT models, while Alibaba and StepFun were accused of targeting Claude and GPT to improve their products. Z.AI was also attributed with targeting GPT-5.5 and Claude Opus 4.8.

The agencies believe that this approach may reduce the time and expense required to develop an advanced model because the operator benefits from the output of a ready-made model rather than bearing the cost of training a competing model from scratch. In the available material, this remains an assessment issued by the agencies, not an independent judicial finding.

What Does This Mean for Model Providers?

CISA, NSA, and the FBI recommend that artificial intelligence companies develop behavioral and infrastructure-level detection methods, modify responses when distillation operations are suspected, and share information about campaigns with relevant parties. Suggested indicators include new accounts reaching their usage limit immediately after creation, continuous activity without normal human idle periods, shared accounts being accessed from many IP addresses or browser identifiers, the same prompts being repeated across multiple providers, and coordinated switching between access routes.

Editorial analysis: The importance of the warning lies not only in its accusations against specific companies, but also in showing that protecting models is no longer limited to preventing server breaches. Authorized access to an API can become a channel for extracting a model’s capabilities if usage patterns across accounts, providers, and different routes are not analyzed. At the same time, the full technical evidence and the companies’ responses, as well as the practical boundaries between legitimate distillation and hostile extraction, remain open questions in the available material.

News source
BleepingComputer
Open original source ↗
ف
Author

فريق تحرير certi.news

In the same category

You may also like

View all news