344
Productivity & Workflow355
Automation & Workflow225
Software Development251
Marketing & Growth192
AI Infrastructure & MLOps175
Writing & Content Creation203
Data & Analytics142
Photography & Imaging156
Design & Creative170
Customer Support132
Sales & Outreach125
Voice & Speech135
Education & Learning131
Operations & Admin87
US agencies say six China-based AI firms copied features from US AI models and urged companies to detect and quietly limit suspected accounts.
In short: US agencies say six China-based AI companies have been copying the abilities of leading US AI models, and they want US firms to quietly block or weaken suspected copying attempts.
The National Security Agency, the FBI, and the Cybersecurity and Infrastructure Security Agency published a joint advisory naming six Chinese AI firms: DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI. The agencies say these firms have been targeting US AI systems since at least late 2024. They said the activity likely happened with awareness from the Chinese government.
The agencies described the alleged tactic as “distillation,” which is a way to learn how a model behaves by asking it huge numbers of questions, then using the answers to train a different model. It is like copying a chef by ordering almost every dish on the menu and writing down what arrives.
They said attackers used automated account swarms, including fake accounts and premium subscriptions shared across teams. The swarms sent many similar prompts, sometimes in the thousands to millions. The advisory also mentions “prompt injection,” which is a trick prompt meant to push a chatbot into revealing hidden instructions or step-by-step reasoning (like coaxing someone to explain their private notes).
If these defenses roll out, regular users could notice stricter sign-ups, more identity checks, or sudden drops in answer quality. The agencies even suggested that when copying is suspected, AI companies should quietly switch those accounts to a less capable model or subtly change answers, without telling the user. That could reduce copying, but it also risks affecting legitimate people if systems get it wrong.
Source: Arstechnica