{"data":{"id":"25404fb3-bddb-403f-9cc9-544ae51d6f4d","title":"US says Chinese firms extracted billions of tokens from frontier AI models","summary":"U.S. intelligence agencies report that six Chinese AI companies conducted large-scale distillation attacks (a technique where a 'student' model learns from outputs of a powerful model) on American AI systems from companies like OpenAI and Google since late 2024, extracting billions of tokens through millions of requests. The attackers used sophisticated methods like distributing requests across fake accounts and proxy services to bypass detection and usage limits, allowing them to develop competitive AI models much faster and cheaper than normal training would require.","solution":"The advisory recommends that AI companies improve behavioral and infrastructure-level detection, modify responses when distillation operations are suspected, and share intelligence about these campaigns with stakeholders. Potential warning signs to watch for include new accounts immediately reaching maximum usage, continuous activity without normal human idle periods, shared accounts accessed from many different IP addresses or user agents, identical prompts across multiple providers, unusually high subscription-to-usage ratios, and coordinated switching between access routes.","labels":["security"],"sourceUrl":"https://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extracted-billions-of-tokens-from-frontier-ai-models/","publishedAt":"2026-09-09T16:48:33.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"high","attackType":["model_theft","data_extraction"],"issueType":"news","affectedPackages":null,"affectedVendors":["Anthropic","OpenAI","Google","xAI"],"affectedVendorsRaw":["Anthropic","OpenAI","Google","xAI","DeepSeek","Moonshot AI","Alibaba","MiniMax","StepFun","Z.AI"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"patchAvailable":null,"disclosureDate":"2026-09-09T16:48:33.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"advanced","impactType":["confidentiality","integrity"],"aiComponentTargeted":"model","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}