US accuses DeepSeek and Alibaba of copying frontier models
Three US intelligence and security agencies have accused six Chinese AI companies of executing industrial-scale distillation attacks to copy proprietary capabilities from leading American models.

The National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation issued a joint warning naming six Chinese AI developers: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies allege these firms have targeted US frontier models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. According to US officials, these companies likely acted with government awareness to extract proprietary functionalities, potentially saving billions of dollars in development costs.
The alleged distillation methods involve exploiting model inference APIs by purchasing swarms of fraudulent accounts to execute highly coordinated queries, sometimes numbering from thousands to millions on similar topics. Attackers also utilize prompt injection techniques to bypass safety guardrails, forcing models to reveal their hidden chain-of-thought reasoning. For instance, DeepSeek reportedly instructed US models to articulate their internal step-by-step reasoning. The agencies noted that some Chinese firms can automatically detect when a superior model is available and adapt their extraction pipelines within 24 hours.
To counter these activities, the government recommended that US AI providers implement aggressive mitigation strategies. These include flagging accounts with suspicious subscription-to-usage ratios, tracking gray-market proxies, and subtly degrading model outputs when distillation is suspected. However, these defense mechanisms present significant challenges for practitioners. Legitimate users risk experiencing degraded performance, shorter responses, or restricted capabilities without warning if they are mistakenly flagged by automated detection systems.
The accusations highlight a growing conflict over intellectual property in the AI sector. While Chinese officials have dismissed the allegations as groundless smears, this dispute occurs as China plans to sharply expand its intelligent computing capacity over the next five years. US developers must now navigate the difficult balance between securing their proprietary architectures and maintaining a seamless user experience for legitimate global customers.
This is our own summary of reporting by Ars Technica AI

