US cyber and law enforcement agencies have accused China-based artificial intelligence companies of carrying out “aggressive, industrial-scale” campaigns to extract capabilities from leading American AI models.
The National Security Agency, FBI and Cybersecurity and Infrastructure Security Agency issued a joint cybersecurity advisory on Tuesday, warning that the alleged activity was being used to train Chinese AI systems while reducing the need for costly research, computing power and electricity.
The agencies said the companies were systematically targeting restricted functions and proprietary capabilities in US frontier models. They described the activity as a national security concern, saying advances obtained in this way could strengthen China’s military and cyber-attack capabilities.
Distillation is a recognised AI development technique in which the outputs of a larger, more expensive model are used to train a smaller system. The US agencies said the technique could be legitimate, but alleged that Chinese companies were using it on an industrial scale to reproduce the strongest features of American models without making equivalent investments in development.
The advisory said operations were spread across multiple AI providers, cloud platforms and infrastructure firms in an effort to avoid detection at any single point. It also outlined methods for identifying suspected distillation campaigns and recommended steps for companies to strengthen their defences.
The agencies urged organisations across the AI sector, including cloud providers and application programming interface aggregators, to share information and co-ordinate their response. They warned that the activity could affect government bodies, businesses, foreign partners and organisations supporting critical infrastructure.
