US Intelligence Warns of Large‑Scale Token Theft by Chinese AI Firms
U.S. cybersecurity and intelligence agencies have revealed that six Chinese artificial‑intelligence companies have carried out industrial‑scale distillation attacks on American frontier AI models, siphoning billions of tokens from the systems at least since late 2024.
The attacks rely on a technique known as model distillation, where adversaries repeatedly query a target model, collect its responses, and use the amassed data to train a copycat version. By reproducing the behavior of the original, the illicit replica can operate independently, effectively stealing the intellectual property embedded in the source model.
Frontier AI models—those that push the limits of size, capability, and generality—represent significant commercial and strategic assets for U.S. firms and research institutions. Their outputs power applications ranging from advanced language services to scientific discovery tools, making the underlying data and training processes highly valuable and sensitive.
According to the agencies, the Chinese operators executed the attacks at a scale that suggests a coordinated, commercial effort rather than isolated hacking incidents. The volume of extracted tokens indicates that the operation was sustained over months, allowing the perpetrators to amass a dataset large enough to approximate the performance of the original models.
Officials warned that such systematic theft could erode the competitive advantage of U.S. AI developers and potentially enable the creation of near‑identical models that could be deployed without oversight. The breach raises concerns about national security, as advanced AI capabilities can be repurposed for malicious activities, and about economic loss, given the billions of dollars invested in developing these systems.
In response, U.S. authorities are urging AI companies to adopt stronger protective measures, including watermarking model outputs, tightening access controls, and monitoring for anomalous query patterns. The disclosure also signals that policymakers may consider additional regulatory or diplomatic actions to address cross‑border AI espionage, as part of a broader effort to safeguard emerging technologies from illicit exploitation.
Comments (0)
Be the first to comment.
Join the discussion