Tuesday, 02 January 2024 12:17 GMT

US Calls For AI Poisoning To Sabotage China's Model Distillation


(MENAFN- Asia Times) Beijing has threatened to retaliate if Washington moves to curb Chinese artificial intelligence (AI) firms over accusations that they used a technique called distillation to copy AI models, days before senior officials from both countries meet for AI safety talks.

Knowledge distillation is a technique in which a smaller“student” AI model is trained to mimic the outputs of a larger, more capable“teacher” model, allowing it to approximate the teacher's abilities at a fraction of the cost.

The dispute centers on a joint advisory from the US Federal Bureau of Investigation (FBI), the National Security Agency (NSA), and the Cybersecurity and Infrastructure Security Agency (CISA) accusing Chinese AI companies of using industrial-scale knowledge distillation to extract US intellectual property.

The advisory named six Chinese firms, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, accusing them of extracting billions of tokens from Claude, ChatGPT, Google Gemini and Grok since late 2024 through fraudulent accounts and proxy services. The agencies said the campaigns were likely carried out with the Chinese government's knowledge.

“China-based AI companies are conducting systematic extraction of proprietary functionalities and capabilities of US AI companies' models through industrial-scale knowledge distillation campaigns that form the core, not merely a supplement, of their AI development strategy,” the agencies said.

The three agencies called on US AI firms to:

    Develop strategies to detect malicious prompts and suspicious accounts. Modify or restrict the responses given to accounts suspected of running distillation campaigns. Share information about malicious actors across the industry to close gaps exploited on multiple platforms.

A less-noticed section of the advisory goes further than blocking or flagging accounts.

“Employing targeted changes in response to high-confidence malicious distillation requests can impose meaningful costs on knowledge distillation campaigns. Response changes, such as including differential privacy or using less sophisticated 'downgraded' models to respond to distillation requests, can help protect US proprietary functionalities and capabilities and reduce payoffs from distillation attempts,” the advisory says.

MENAFN10092026000159011032ID1111650321



Asia Times

Legal Disclaimer:
MENAFN provides the information “as is” without warranty of any kind. We do not accept any responsibility or liability for the accuracy, content, images, videos, licenses, completeness, legality, or reliability of the information contained in this article. If you have any complaints or copyright issues related to this article, kindly contact the provider above.



More Story