US accuses Alibaba, DeepSeek of stealing from its AI companies for years
China has targeted Claude, Grok, ChatGPT, and Gemini.

Image by Cybernews
- CISA says major Chinese AI companies stole knowledge from US AI models at scale.
- The alleged campaign used distillation, a method that trains smaller AI models on larger models’ outputs.
- US officials say the activity helped train Chinese models, including DeepSeek R1 and Qwen V3.
- CISA, the NSA, and the FBI urge US AI firms to detect and limit suspicious requests.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
China’s biggest AI companies have allegedly been stealing proprietary knowledge from US tech companies for years, in what the US top cybersecurity agency calls a full-scale distillation campaign.
The US Cybersecurity and Infrastructure Security Agency (CISA) released a report accusing major Chinese AI companies of siphoning knowledge from the US to help iterate its nation’s AI models.
Companies like DeepSeek, Moonshot AI, Alibaba, MiniMa, StepFun, and Z.AI stole information from US models like Claude, ChatGPT, Gemini, and Grok, the US alleges.
This activity has allegedly been ongoing since at least 2024, with China stealing reasoning capabilities, specialized optimizations, and domain-specific functions from the US to train its DeepSeek RI and Qwen V3 models.
It’s also likely that the Chinese government knew that its AI companies were extracting “billions of tokens” from US frontier AI models.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
What is distillation?
Knowledge distillation is a research technique in which a smaller, more efficient model is trained on the outputs of a larger, more complex model.
The US alleges that companies like Alibaba, the creator of Qwen, have turned knowledge distillation into an industrial-sized campaign to fine-tune its family of AI models.
This is being called a “distillation campaign,” in which a “legitimate and useful” AI research technique is turned into an “aggressive, malicious, and targeted” attack on restricted proprietary information belonging to the US.
China has allegedly done this by routing distillation requests through multiple pathways to gain unauthorized access to US models.
In essence, China has used proxies and or disguised the origins of these requests to distill information from US companies at scale.
Furthermore, companies behind major US AI models like Claude, ChatGPT, and Gemini are closed companies, meaning they have different rules around how proprietary information is handled.
US companies should be on high alert
The US government is taking this situation seriously, as evidenced by its collaborative report by CISA, the National Security Agency (NSA), and the FBI, which urge AI companies to keep a watchful eye on distillation requests.
To stay competitive in the AI race, US companies should take steps to detect and mitigate distillation attacks.
The government recommends that AI companies “subtly alter their response” to potentially malicious distillation attempts and communicate with other AI providers across the US.
While this doesn’t necessarily mean providing potential attackers with blatantly incorrect outputs, it may mean that AI companies will start dumbing down responses to prompt queries from suspected attackers.