US Accuses Six Chinese AI Firms of Mass Distillation Attacks

Federal agencies claim Chinese tech companies are using fake accounts and prompt injections to steal capabilities from leading US AI models.

Sep 9, 2026

10 cards · 2 min · tap to begin

From · · 2 min

US Accuses Six Chinese AI Firms of Mass Distillation Attacks

Federal agencies claim Chinese tech companies are using fake accounts and prompt injections to steal capabilities from leading US AI models.

In brief

Federal agencies claim Chinese tech companies are using fake accounts and prompt injections to steal capabilities from leading US AI models. US intelligence agencies want tech companies to join forces and aggressively monitor accounts to stop Chinese firms from distilling US frontier AI models. Originally reported by…

US accuses Chinese AI firms

The NSA, CISA, and FBI released a joint statement accusing six Chinese AI companies of conducting industrial-scale attacks to copy US frontier AI models.

China-based AI companies that conduct industrial-scale distillation against US AI models see significantly shorter AI development timelines

Swarms of fake accounts execute queries

Attackers bulk-buy fraudulent accounts and route requests through proxy networks. They run thousands to millions of coordinated queries featuring identical prompts to extract model capabilities.

Prompt injection forces step-by-step reasoning

Prompt injection forces step-by-step reasoning

Chinese developers use prompt injection techniques to jailbreak US models. DeepSeek instructed models to articulate their internal reasoning step by step.

DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses

Government urges aggressive account monitoring

Federal agencies recommend that US AI companies flag suspicious accounts hitting maximum usage immediately. They also suggest tracking subscription usage ratios and strengthening identity checks.

Dumbing down model responses defensively

Agencies suggest subtly altering outputs for flagged accounts, such as reducing reasoning depth or presenting different logic. US firms could secretly switch malicious users to inferior models without warning.

Legitimate users risk collateral damage

Legitimate users risk collateral damage

Secretly downgrading accounts could inadvertently hurt real customers. Legitimate users might experience degraded output quality, shorter answers, or restricted follow-up queries.

Attackers quickly adapt to degraded outputs

Chinese companies run automated quality assurance to distinguish service glitches from deliberate data degradation. Some automated systems detect smarter models and switch targets within 24 hours.

Targeted models and stolen capabilities

The report highlights DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. Targeted capabilities include software engineering, math, writing optimization, and agentic functions.

Beijing calls US claims groundless

Photo of Ashley Belanger

A Chinese Ministry of Foreign Affairs spokesperson dismissed the accusations, attributing China's AI growth to technological self-reliance. Officials accused the US of running a smear campaign.

Cross-border AI ties and political pressure

Chinese officials noted that US startups also rely on affordable Chinese models. The dispute comes as China expands its computing power and leaders prepare for bilateral talks.

Here's the gist

US intelligence agencies want tech companies to join forces and aggressively monitor accounts to stop Chinese firms from distilling US frontier AI models.

Read the original on Ars Technica

React

Sign in to react and comment.

Comments (0)

Life is short. Keep it sweet. Respect others' opinions and be kind!

    Recommended next

    More decks on artificial intelligence and related topics.