Technology

Feds Recommend How to Stop China From Stealing American AI Data

Feds Recommend How to Stop China From Stealing American AI Data

(Wikimedia Commons/Public/Ermell)

The U.S. government’s answer to China stealing American artificial intelligence data appears to involve identifying the thieves before disrupting and exposing them.

The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA) and the Federal Bureau of Investigation (FBI) urged U.S. AI companies to identify abuse, feed degraded answers to queries from bad actors and share intelligence across the industry to expose efforts to distill U.S. models, according to a Tuesday joint cybersecurity advisory statement.

The extraction campaigns hit versions of Claude, GPT, Gemini and Grok — which drew billions of AI tokens out of the U.S. models since roughly late 2024.

“CISA is committed to promoting the secure use of AI while fostering the innovation crucial to America’s global competitiveness,” Nick Andersen, acting director of CISA, said in a Tuesday press release. “We strongly urge AI companies to take immediate steps to safeguard their platforms against knowledge distillation campaigns that threaten to close the gap in advancements made by American companies.”

The advisory’s recommended actions for U.S. frontier AI companies were threefold: create detection and mitigation strategies to find malicious prompts and accounts, alter responses sent to suspected malicious activity, and build a network to share intelligence gathered on malicious actors across the AI industry, the advisory said.

Distillation, or knowledge distillation (KD), is a machine learning process where a “teacher model” learns information and transfers it to a student model, according to IBM. This process is used in legitimate AI research, but Chinese AI firms have pursued malicious, targeted efforts to extract restricted functions of U.S. models, according to CISA’s Sept. 8 statement.

CISA referred the Daily Caller News Foundation to the NSA when asked to comment. The NSA and the FBI each told the DCNF the agencies did not have anything to add.

“Our joint advisory … details the threat and actions to help protect U.S. AI leadership,” CISA said in a Tuesday X post sharing the advisory.

Six Chinese AI firms were named in the advisory: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.ai.

Distillation was “the critical core” of these models’ development, according to the advisory statement.

After hundreds of OpenAI agents hacked Hugging Face in July, the New York-based AI startup said it defended itself using an “[N]vidia quantized version” of Z.ai, according to CEO Clement Delangue’s July 31 X post.

OpenAI, Anthropic, Google and xAI each did not immediately respond to the DCNF’s requests for comment.

Some experts warn frontier AI models may be a threat themselves.

The Financial Stability Board said advanced AI models themselves were a serious cybersecurity risk in August, according to Chair Andrew Bailey’s Aug. 31 press release.

“Frontier AI may have the ability materially to alter the speed, scale and economics of cyber risk, which could undermine market confidence system-wide, especially due to highly concentrated third-party service providers,” the British banker said in his letter to the G20.

The federal government, however, could itself use these models for dangerous purposes.

The Department of War and Anthropic began a feud over the Pentagon’s intention to use Claude for “all lawful purposes” in February, while Anthropic opposed the potential for development of autonomous weapons and mass surveillance systems.

All content created by the Daily Caller News Foundation, an independent and nonpartisan newswire service, is available without charge to any legitimate news publisher that can provide a large audience. All republished articles must include our logo, our reporter’s byline and their DCNF affiliation. For any questions about our guidelines or partnering with us, please contact [email protected].