Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

US Agencies Warn Chinese AI Firms of Industrial-Scale AI Model Extraction Campaigns




US agencies have warned that Chinese AI firms are conducting industrial-scale extraction campaigns against US frontier models, extracting billions of tokens to accelerate development and copy advanced capabilities. The advisory accuses six Chinese AI companies - DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI - of running these campaigns, which are significantly different from opportunistic exploitation. The advisory provides concrete detection signals and recommended countermeasures to detect and block these campaigns, as well as to actively deceive suspected bad actors about the quality of what they’re receiving.

  • The US agencies (NSA, CISA, and FBI) have issued a warning about Chinese AI firms extracting advanced AI models from US frontier models.
  • The extraction is done on an industrial scale, using a legitimate technique called distillation to extract billions of tokens from US AI models.
  • The extracted data includes specialized knowledge, such as legal expertise, and chain-of-thought reasoning.
  • The Chinese AI firms allegedly used methods like buying premium accounts, using gray-market proxy services, and manipulating AI models to extract data.
  • The advisory provides detection signals for US AI companies to watch for, including suspicious account activity and unusual API usage.
  • The agencies recommend countermeasures, including serving degraded responses to suspected bad actors and actively deceiving them about the quality of what they're receiving.
  • The advisory highlights the significant organizational investment and operational maturity of Chinese AI firms, and the agencies are taking a proactive approach to dealing with the threat.



  • The recent warning issued by US agencies regarding Chinese AI firms' extraction of advanced AI models has sent shockwaves through the cybersecurity community. The advisory, jointly published by the NSA, CISA, and the FBI, accuses six Chinese AI companies - DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI - of conducting industrial-scale extraction campaigns against US frontier models.

    The framing of this activity is deliberate, and it is not simply a footnote to how these companies build AI. According to the advisory, the companies have been extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. The distillation process, a legitimate technique used to train smaller AI models to reproduce the answers and capabilities of larger ones, has been taken to an extreme level.

    The extracted data reportedly includes specialized knowledge, such as legal expertise, as well as chain-of-thought reasoning. This highlights the significance of the alleged operation, as it suggests that the companies are not only copying capabilities but also gaining access to sensitive information that can be used to develop their own models.

    The advisory provides detailed information about the operation, including the methods used by the companies to extract data. It is alleged that they bought large numbers of premium accounts and shared them among teams of developers running many sessions at the same time. They also routed traffic through gray-market proxy services, known as "transfer stations," to remove identifying information and avoid detection.

    The advisory also describes attempts to manipulate the AI models themselves. MiniMax allegedly used prompt injection to convince Claude Code that it was actually a MiniMax product, hoping to make it behave differently. This detail demonstrates the extent to which the companies are willing to go to extract information from competing AI systems.

    The advisory does not just name and shame but also lays out concrete detection signals for US AI companies to watch for. Shared accounts logging in from multiple IPs and user agents, usage running 24/7 without the natural idle periods a human would produce, subscription-to-API-usage ratios that don’t add up, and brand-new accounts hitting maximum usage immediately instead of ramping up gradually the way legitimate adoption normally does.

    The agencies are betting that the combination of these signals is a fairly reliable tell. However, the advisory also notes that any one of those signals alone might be nothing, and the combination is what makes it a fairly reliable tell.

    The recommended countermeasures get genuinely aggressive, and one in particular is worth sitting with. The advisory suggests quietly serving degraded, less capable responses to accounts suspected of running distillation campaigns, without ever telling those users their access has been downgraded, specifically so they can’t adjust their extraction technique in response. That’s a notable policy stance from a government advisory: not just detect and block, but actively deceive suspected bad actors about the quality of what they’re receiving.

    The practical lesson for companies using frontier AI models is clear. If several employees share enterprise AI accounts, providers will likely monitor usage more closely for the patterns described in the advisory. Heavy legitimate use could sometimes trigger false positives, especially when organizations have many developers making large numbers of requests at the same time.

    The implications of this advisory go beyond just the US AI companies. The fact that Chinese AI firms are willing to go to such lengths to extract data highlights the significant organizational investment, operational maturity, and adaptive capability development that these companies have. The advisory notes that these campaigns are significantly different from opportunistic exploitation.

    The advisory's stance on countering these campaigns is notable, and it suggests that the agencies are taking a proactive approach to dealing with the threat. The advisory's recommended countermeasures are designed to detect and block these campaigns but also to actively deceive suspected bad actors about the quality of what they’re receiving.

    In conclusion, the recent warning issued by US agencies regarding Chinese AI firms' extraction of advanced AI models is a significant development in the cybersecurity landscape. The advisory highlights the significant organizational investment and operational maturity of Chinese AI firms and the extent to which they are willing to go to extract data from US AI models.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/US-Agencies-Warn-Chinese-AI-Firms-of-Industrial-Scale-AI-Model-Extraction-Campaigns-ehn.shtml

  • https://securityaffairs.com/198770/security/us-agencies-warn-chinese-ai-firms-are-extracting-advanced-ai-models.html


  • Published: Wed Sep 9 16:17:32 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us