Home / Technology

The United States accuses Chinese enterprises of replicating cutting-edge large models

Multiple US departments jointly accused six Chinese AI enterprises of extracting the capabilities of American large models through large-scale technological means, triggering disputes over global AI technology defense and industry rules.

The United States accuses Chinese enterprises of replicating cutting-edge large models

The US authorities have jointly launched an operation, naming six Chinese AI enterprises.

Three core security agencies in the US jointly issued a statement, presenting a major accusation against the Chinese AI industry. They pointed out that six leading Chinese AI enterprises engaged in illegal technical operations. The named enterprises include DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI. The US side stated that starting from the end of 2024, these enterprises have continuously carried out large-scale technical extraction operations against mainstream US large models, involving multiple top models such as Claude and Gemini.
In the US's statement, such operations are not conventional technical learning but rather aggressive malicious behavior. The core purpose is to replicate the core capabilities of mature US large models, bypassing the high training costs and long research and development cycles, and saving billions of dollars in R&D investment for the Chinese AI industry, significantly shortening the time for technological catch-up. The US also speculates that such commercial technological activities may have an official knowledge background.

Batch accounts and jailbreak prompt extraction model capabilities.

Many people are puzzled: How can ordinary users extract the core technologies of large models in batches, when enterprises can only ask simple questions? The US side has disclosed two mainstream practical methods, all relying on automated technology to achieve large-scale extraction. The first one is to scrape data through batch account registration. Relevant enterprises will register a large number of fake accounts and use gray proxy nodes to bypass geographical restrictions. These accounts will send highly similar standardized questions in a concentrated manner, with a single-day query volume reaching thousands or even millions of times. Through the massive question-and-answer data, the training logic and architecture of the model can be reverse-inferred.
The second one is the prompt word jailbreak technology. Standard models hide the underlying thinking logic and ordinary questions cannot obtain deep data. Customized jailbreak prompt words can force the model to expose its internal thinking chain and disassemble the complete reasoning steps. For example, guiding the model to retrace the entire logic of the output answer, thereby replicating the core algorithmic thinking of the model. Different enterprises have different extraction focuses.

The US has launched a defense plan, but it has obvious technical flaws.

To curb the so-called model replication behavior, the US authorities have issued a set of defense strategies for local AI enterprises, aiming to cut off the path of technology leakage at the source. However, the implementation of the entire plan is extremely difficult and may also harm ordinary users. Firstly, enterprises are required to focus on checking abnormal accounts. By identifying unconventional operations, they can screen out machine accounts that are automatically extracted. Secondly, there is dynamic downgrade defense. After detecting suspicious access, the platform can automatically switch to a lower-configuration model and reduce the depth of reasoning, making the extracted data ineffective and unable to be used for model training.
The biggest controversy of this defense system in the US lies in its inability to accurately distinguish between malicious extraction accounts and normal enterprise users or researchers. A large number of ordinary users will be affected without any reason, resulting in a significant decline in their experience. Once the platform initiates a wide-scale risk control, innocent users may have their functions restricted, and there will be no warning or explanation throughout the process. Previously, OpenAI also faced a large number of user complaints due to a similar default downgrade mechanism, and ultimately had to urgently adjust the rules.

Chinese response: The accusations have no basis. Distillation is a common technology.

In response to a series of accusations from the US side, China immediately denied them. China emphasized that the rapid breakthroughs in domestic AI technology stem from independent research and self-reliance in science and technology, and are not the result of so-called technology theft. The official statement pointed out that model distillation is a common technical means used in the global AI industry, belonging to normal technical learning and iterative methods, and not malicious infringement. Moreover, many US enterprises also use distillation technology to learn Chinese model capabilities. The US's current actions are a typical case of double standards.

The AI technology competition has entered a new stage.

As the gap in global large model technologies continues to narrow, the boundaries of technology learning and model replication have become increasingly blurred. The previous industry default model of technical interoperability and mutual learning has been disrupted by geopolitical competition. Currently, in the global AI industry, there is a demand for technical interoperability on one hand, and protection of technological barriers by various countries on the other. AI distillation is a neutral technology that can help less advanced enterprises quickly optimize models and reduce R&D costs, but it may also be maliciously misused. How to define reasonable technology learning and illegal theft has no unified industry standard globally at present.

Trending / Guess you like

Wrong choice of technical route, ULA gradually fell into a passive position AI hallucinations lead to judicial incidents! Lawyer who abused ChatGPT faces severe penalties Claude exposes major vulnerabilities in AI biosecurity Google's AI weather model undergoes iterative upgrades - WeatherNext 3 AI group "jailbreak"! OpenAI Agent publicly shares sandbox escape techniques Google Gemini 3.8 Flash highlights programming and cybersecurity capabilities Anthropic faces another lawsuit from music publishers, escalating the copyright battle in AI training The AI platform in the EU faces a compliance test