US Accuses Six Chinese AI Firms of Industrial Scale Model Copying
US agencies accuse six Chinese AI firms of distilling Claude, GPT, Gemini and Grok at scale, prompting defenses that could degrade service for legitimate users.
Summary
The NSA, CISA and FBI on September 8 accused DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of industrial-scale attacks on US frontier models since at least late 2024, likely with Chinese government awareness. They say extracted Claude, GPT, Gemini and Grok capabilities are central to China's development strategy and may save billions by shortening training. Alleged tactics include fake premium accounts, gray-market proxies, thousands to millions of coordinated API queries across tens of thousands of accounts, and jailbreaks exposing hidden chain-of-thought. DeepSeek allegedly copied agentic, assistant, writing, question-answering and reasoning functions; Moonshot targeted fine-tuning, reinforcement learning, software engineering and math; the other four focused on Anthropic and OpenAI models.
US agencies urged AI companies, Washington and allies to share intelligence, strengthen identity checks, track enterprise users and suspicious usage ratios, and monitor anomalous prompts, accounts and networks. Suspected attackers could secretly receive shallower, stylistically inconsistent answers or inferior models. Attackers can detect better models and switch within 24 hours, while automated quality checks spot degradation. Legitimate users could therefore lose precision, response length, capabilities, privacy or business utility without notice. Agencies warned that failure would bring significant economic losses and erode the US lead, but said safety researchers and third-party evaluators should be told of model changes.
OpenAI previously accused DeepSeek, Google said attackers tried cloning Gemini, and Anthropic accused Alibaba of the largest attempted Claude cloning attack; Washington warned of a crackdown in April. On September 9, Foreign Ministry spokesperson Mao Ning called the claims groundless and credited China's self-reliance, while embassy spokesperson Liu Chang called them a prejudiced smear. Beijing says US companies also distill Chinese models and startups seek their cheaper access, threatening countermeasures for material harm. China's industry ministry meanwhile unveiled a five-year computing expansion before Donald Trump meets Xi Jinping on September 24.
Positives
- Thousands to millions of similar queries per domain could give US model providers a measurable signal for detecting industrial-scale campaigns.
- NSA, CISA and FBI recommend intelligence sharing among AI companies, Washington and allied governments to track evolving attacks.
- AI safety researchers and third-party evaluators should be notified when providers alter or downgrade model behavior.
- China's industry ministry unveiled a five-year plan to sharply expand the country's intelligent computing capacity.
Risks & concerns
- Six Chinese firms allegedly extracted restricted capabilities from Claude, GPT, Gemini and Grok using tens of thousands of fraudulent accounts.
- DeepSeek allegedly copied agentic, assistant, writing and reasoning functions to reduce compute and research costs.
- Attackers can detect degraded outputs and move to a more capable model within 24 hours, weakening defensive routing.
- Legitimate users could receive inferior answers or withheld capabilities without notice while facing stronger identity checks and privacy risks.
- US agencies warn continued extraction could cause significant economic losses and erode America's lead in frontier AI.
- Beijing rejects the allegations and threatens countermeasures, raising tensions before the September 24 Trump and Xi meeting.