US calls for AI poisoning to sabotage China’s model distillation
The US Federal Bureau of Investigation, National Security Agency, and Cybersecurity and Infrastructure Security Agency have accused six Chinese AI firms of using knowledge distillation to extract US intellectual property. These firms, including DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, are alleged to have extracted billions of tokens from models like Claude, ChatGPT, Google Gemini, and Grok since late 2024. This activity, suspected to be government-backed, involves training smaller AI models to mimic larger ones at lower cost. The US agencies are advising American AI firms to employ tactics like 'AI poisoning' by altering responses to suspected malicious distillation requests, without informing the Chinese users. This development comes days before senior US and Chinese officials are scheduled to meet for AI safety talks, with Beijing threatening retaliation against any US curbs.
The US is quietly advocating for 'AI poisoning' tactics against Chinese firms suspected of intellectual property theft through knowledge distillation. This strategy involves US AI companies subtly altering responses to suspected malicious queries, effectively feeding 'bad data' to Chinese AI models without their knowledge. The advisory from the FBI, NSA, and CISA specifically names six Chinese companies, including Alibaba and Moonshot AI, accusing them of extracting billions of tokens from leading US models since late 2024. For Asian AI development, this represents a significant escalation in the US-China tech rivalry, moving beyond export controls to active sabotage of AI training data. While Beijing views distillation as a neutral practice and accuses Washington of protectionism, the US sees it as a direct threat to its AI leadership. The risk for Chinese AI firms is a potential degradation of their models if they unknowingly incorporate poisoned data, impacting their competitive edge and the reliability of their AI products across the region. The thing to watch is how this covert tactic impacts the quality and trustworthiness of AI models developed in China, particularly those from firms like Moonshot AI, which has been explicitly mentioned in past US accusations. This could force Chinese developers to invest more heavily in data verification and alternative training methodologies, potentially slowing their progress or increasing costs.
Related reading
6 stories
AI enters War as Claude being used to Build Ballistic Missiles, Lethal Weapons
This article details how AI models are being used in military applications, a stark contrast to the 'poisoning' discussed here.

People’s Daily rejects US claims of malicious AI distillation, warns of countermeasures

Databricks to Invest Over US$350 Million in Singapore, Double Its Workforce

ByteDance’s AI-enhanced short-drama app eclipses China’s Netflix rivals combined

Personetics Launches AI Banking Console for Relationship Managers

