Home Economy China’s AI Firms vs. U.S. Frontier Models: What You Need to Know...

China’s AI Firms vs. U.S. Frontier Models: What You Need to Know About the Distillation Controversy

0
Image created by AI tool related to article content / ChatGPT
Image created by AI tool related to article content / ChatGPT

The U.S. government has revealed that six Chinese artificial intelligence (AI) companies, including DeepSeek, Moonshot AI, and Alibaba, systematically extracted billions of tokens from leading U.S. AI models such as GPT and Claude to train their own systems. Washington warns that this large-scale AI distillation by China could have profound implications for national security, extending beyond the ongoing U.S.-China AI technology race.

On Tuesday, the National Security Agency (NSA), Federal Bureau of Investigation (FBI), and Cybersecurity and Infrastructure Security Agency (CISA) jointly issued a cybersecurity advisory titled, Chinese AI Companies Conducting Industrial-Scale Distillation Campaigns Targeting U.S. AI Firms.

The U.S. government asserts that Chinese AI companies are engaged in extensive distillation activities, methodically extracting capabilities and functions from U.S. frontier AI models to enhance their own systems.

Distillation is a technique where one AI system learns en masse from the responses of a high-performing AI model to improve its own capabilities. This method allows for learning from advanced models with relatively lower computational resources and costs, making it a widely adopted practice in the AI industry.

While the U.S. government acknowledges distillation as a legitimate and valuable AI development method, it emphasizes that the actions of Chinese companies – circumventing usage restrictions and regional blocks to extract proprietary functions and capabilities of U.S. models on an industrial scale – deviate significantly from standard technological practices.

The advisory specifically names six Chinese AI companies: DeepSeek, Moonshot AI, Alibaba, Minimax, StepFun, and Z.ai. It further states that the U.S. government believes Beijing is aware of these activities and estimates that these companies have likely extracted billions of tokens from U.S. AI models including Claude, GPT, Gemini, and Grok since late 2024.

The report details the methods employed by these companies. U.S. officials assess that Chinese AI firms utilized various channels, including application programming interfaces (APIs) and remote cloud services, to bypass the terms of service and regional restrictions imposed by U.S. AI companies.

The advisory also highlights instances where these firms concealed user information to evade detection or employed a proxy black market known as Transfer Station to complicate tracking efforts. They reportedly extracted the chain-of-thought (CoT) reasoning capabilities of AI models and implemented systems to automatically switch to alternative pathways when specific access routes were blocked.

The U.S. government views this large-scale AI distillation by Chinese companies as a direct national security concern, transcending mere technology or intellectual property issues.

The NSA emphasized that the U.S.-China frontier AI competition carries significant national security implications, warning that advanced AI models could pose serious risks to critical infrastructure, military operations, economic stability, and technological supremacy.

In response, the U.S. government has advised domestic AI companies to implement measures to detect and block distillation attempts.

Recommendations include strengthening systems to identify and prevent abnormal or malicious prompts, accounts, networks, and usage patterns. Special attention should be given to monitoring unusual activity, such as maximum usage levels immediately following new account creation.

For requests suspected of distillation, officials suggest subtly altering AI response methods to reduce the value of potentially extracted information. They also advocate for establishing a collaborative system among AI model providers, cloud platforms, and API intermediaries to share intelligence on suspicious accounts and attack methodologies.

NO COMMENTS

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Exit mobile version