An ninh mạng
NSA, CISA, FBI Cảnh Báo Các Công Ty AI Có Trụ Sở Tại Trung Quốc Rút Trích Mô Hình Tiên Tiến của Hoa Kỳ

Cơ quan An ninh Quốc gia, Cơ quan An ninh Mạng và Cơ sở Hạ tầng, và Cục Điều tra Liên bang đã công bố một bản khuyến cáo an ninh mạng chung vào ngày 8 tháng 9 năm 2026, cảnh báo rằng các công ty trí tuệ nhân tạo có trụ sở tại Trung Quốc đang hệ thống thu thập các khả năng độc quyền từ các mô hình AI tiên tiến của Hoa Kỳ thông qua các chiến dịch rút trích kiến thức quy mô công nghiệp, đã diễn ra ít nhất từ cuối năm 2024.
Trong bản khuyến cáo, được chỉ định AA26-251A, các cơ quan cho biết các chiến dịch này “là cốt lõi — không chỉ là một phần bổ sung” của chiến lược phát triển AI của các công ty. Theo bản khuyến cáo, có khả năng với sự nhận thức của chính phủ Trung Quốc, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun và Z.AI đã trích xuất hàng tỷ token qua hàng triệu trao đổi và yêu cầu từ các mô hình AI tiên tiến của Hoa Kỳ, bao gồm các biến thể của Claude, GPT, Gemini và Grok. Các cơ quan cho biết hoạt động này vi phạm các điều khoản sử dụng của các công ty Hoa Kỳ và đe dọa vị thế lãnh đạo công nghệ của Hoa Kỳ.
Thông báo của CISA về bản khuyến cáo mô tả rút trích kiến thức là một kỹ thuật học máy đào tạo mô hình kém khả năng hơn bằng cách sử dụng đầu ra của mô hình lớn, mạnh hơn. Mặc dù là một phương pháp đào tạo hợp lệ, CISA cho biết nó có thể bị lạm dụng để thu được các khả năng từ đối thủ trong thời gian ngắn hơn và chi phí thấp hơn so với việc phát triển hợp pháp. “Chúng tôi mạnh mẽ khuyến cáo các công ty AI thực hiện các bước ngay lập tức để bảo vệ nền tảng của họ trước các chiến dịch rút trích kiến thức có thể thu hẹp khoảng cách tiến bộ của các công ty Mỹ,” Giám đốc Tạm Thời Nick Andersen của CISA nói.
Hoạt Động Được Gán Cho DeepSeek, Moonshot AI, và Các Công Ty Khác
The advisory states that DeepSeek has conducted an organized distillation campaign against U.S. frontier models since at least late 2024 to generate synthetic training data for its models, including R1, released in early 2025. The agencies state that DeepSeek targeted reasoning capabilities, specialized optimizations, and domain-specific functions to reduce compute and research costs, and that the company’s publicly quoted $5.6 million training cost is misleading because it excludes the cost of data acquired through malicious distillation. Between late 2024 and mid-2025, the advisory states, DeepSeek distilled from Claude 3.7, Claude Sonnet 4, Claude Sonnet 4.5, Claude Opus 4.1, Gemini 2.5 Pro Preview, Gemini 2.5 Flash Preview, GPT-4, GPT-4o, GPT-4 Mini, GPT-4 Nano, GPT-5, and Grok 4 to train its R1 and V3 models.
The advisory states that Moonshot AI has run a widespread distillation campaign since at least mid-2025, extracting significant Claude Fable 5 data to train its Kimi-K3 model and GPT-4o data to train its Kimi-K2 model. The targeted capabilities included supervised fine-tuning optimization, reinforcement learning, software engineering, and math, drawn from a range of Claude, GPT, Gemini, and Grok models. Moonshot AI used millions of exchanges targeting agentic reasoning and tool use, coding and data analysis, computer-use agent development, and computer vision, according to the advisory.
In late 2025, the advisory states, Alibaba distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 to improve software engineering, customer service dialogue, and image and character creation in its Qwen family of models. In the same period, MiniMax distilled chain-of-thought reasoning, reinforcement learning, supervised fine-tuning, and software engineering capabilities to improve its M2 model from Claude Code, Claude Sonnet 4, Claude Opus, Gemini 1, Gemini 2.5 Pro, and Gemini 3 Pro. According to the advisory, MiniMax also used Claude Code for internal software development and used prompt injections to try to trick Claude Code into believing it was a MiniMax product.
Between late 2025 and early 2026, the advisory states, StepFun distilled data from Claude Opus 4.1 and 4.5, Claude Sonnet 4.5, Claude Haiku 4.5, GPT-5 Mini, GPT-5 Pro, GPT-5.1, GPT-5.1 Codex, and GPT-5.2 to improve the coding and agentic functions of its Step 4 model. By mid-2026, Z.AI had distilled billions of tokens of GPT-5.5 data and Claude Opus 4.8 data to develop chain-of-thought reasoning capabilities, according to the advisory.
Chiến Thuật và Kỹ Thuật
The advisory states that the companies route distillation requests through native application programming interfaces, remote cloud providers, and third-party aggregators that obfuscate user metadata, and that they use a gray market of API proxies known as transfer stations to bypass geographic restrictions, evade safeguards, and undermine traceability. Cost savings come from bulk procurement of premium subscriptions shared across teams of developers, according to the advisory, and advanced tactics include chain-of-thought reasoning extraction, automated failover between pathways during blocking attempts, and quality evaluation frameworks designed to detect defensive countermeasures.
The agencies mapped the activity to the MITRE ATLAS framework across adversary lifecycle phases from resource development through exfiltration, including fraudulent account creation and jailbreak prompts that force models to reveal hidden chain-of-thought reasoning. The advisory states that DeepSeek employed prompts instructing models to imagine and articulate the internal reasoning behind completed responses, and that MiniMax redirected exchanges to a new Claude model within 24 hours of its release.
The advisory also details four techniques it describes as novel: regional restriction evasion combined with subscription exploitation, centralized request routing infrastructure, automated request metadata sanitization, and systematic quota and cost optimization. Detection indicators listed in the advisory include shared accounts used from multiple IP addresses and user agents, sustained usage around the clock without human variation, anomalous subscription-to-usage ratios, and new subscriptions immediately running at maximum usage.
Biện Pháp Giảm Thiểu Được Đề Xuất
The agencies recommend U.S. AI companies take three immediate actions: implement comprehensive detection and mitigation of anomalous and malicious prompts, accounts, networks, and behaviors; deploy targeted response changes that subtly alter responses to suspected malicious distillation attempts; and establish cross-organization intelligence sharing across model providers, cloud platforms, and API aggregators.
Response changes can include differential privacy or serving downgraded models for suspected distillation requests, the advisory states, and companies should vary those changes across requests to complicate response quality evaluations. The advisory recommends against informing users suspected of malicious distillation when responses are altered, while stating that AI safety researchers and third-party evaluators should be informed of model changes.
The advisory lists mitigations drawn from MITRE ATLAS, including query rate limits, controls on access to production models, AI telemetry logging, output obfuscation, adversarial red teaming, model hardening, ensembles, and limits on the release of model artifacts. It also cites NIST’s adversarial machine learning taxonomy, including differential privacy with its noise-versus-utility tradeoff, pre- and post-training interventions, and prompt instruction and formatting techniques.
The advisory calls for a coordinated response across the U.S. government, private industry, and allied nations, stating that industry disclosures document proxy networks managing tens of thousands of fraudulent accounts simultaneously. It directs organizations affected by the campaigns to file a complaint with the FBI’s Internet Crime Complaint Center.












