NSA, CISA and FBI warn Chinese AI firms, including DeepSeek, of industrial‑scale distillation campaigns
deepseek
| Source: Techmeme | Original article
The NSA, CISA and FBI warned that Chinese AI firms, including DeepSeek, are running industrial‑scale model‑distillation campaigns to illicitly copy technology.
The U.S. National Security Agency, the Cybersecurity and Infrastructure Security Agency and the Federal Bureau of Investigation released a joint advisory on Tuesday warning that several Chinese artificial‑intelligence firms, among them DeepSeek, are running “industrial‑scale” model‑distillation campaigns. According to the alert, the actors are systematically copying proprietary large‑language models by extracting them from publicly available services and re‑hosting the distilled versions on their own platforms. The agencies describe the activity as malicious and state‑sponsored, aimed at harvesting intellectual property and potentially repurposing the stolen models for espionage or other hostile operations.
The advisory matters because model distillation can reproduce much of a source model’s capabilities while requiring far less compute, making the stolen assets easy to weaponise or commercialise. If Chinese firms can mass‑produce replicas of U.S. and allied AI systems, the competitive edge of domestic developers erodes and the risk of AI‑enabled cyber‑attacks rises. The warning dovetails with recent alerts about AI‑generated exploit scripts targeting industrial control systems, underscoring a broader trend of adversaries leveraging generative AI to amplify threat vectors.
What to watch next includes possible regulatory or punitive steps from the U.S. government, such as export controls, sanctions on the identified companies, or coordinated legal actions to protect AI intellectual property. Industry observers will also monitor whether affected AI providers tighten access controls, watermark outputs, or adopt detection tools to spot illicitly distilled models. As we reported on self‑distillation techniques in early September, the same technology that can improve model efficiency also creates a dual‑use dilemma; this advisory marks the first high‑profile government response to its malicious exploitation on a large scale.
Sources
Back to AIPULSEN