sakutto
Generative AI

What Is AI Distillation? Chinese Military Research on Adversarial Distillation

Knowledge DistillationAI RegulationChinese AI
What Is AI Distillation? Chinese Military Research on Adversarial Distillation

What knowledge distillation is: training a student on a teacher's outputs

Knowledge distillation is the practice of training a smaller, cheaper student model using the outputs of a larger, more expensive teacher model. In Chinese it is written 知识蒸馏.

The cooking analogy: rather than making the stock again from scratch, you taste the finished stock and reproduce the flavour. It costs orders of magnitude less than training from nothing.

About the analysis

Publisher
Jamestown Foundation, China Brief
Published
July 30, 2026
Author
Sunny Cheung
Material reviewed
Dozens of Chinese academic and industry papers published 2024–2026
Subject
Adversarial distillation and the entities involved in it
Format
An analysis piece in the Jamestown Foundation's China Brief

Distillation itself is used widely across the industry

Worth establishing first: the analysis does not treat distillation in general as bad. It states outright that the practice is used widely across the industry, is good for competition, and helps maintain an ecosystem in which less well-resourced players can benefit from AI.

What it raises as a problem is that some of it takes the form it calls adversarial distillation.

View official source →
Distillation (知识蒸馏) refers to the practice of training a smaller, cheaper “student” model by using the outputs of a larger “teacher” model. / It is a practice used widely across the industry for a variety of purposes. It is good for competition and helps maintain an ecosystem in which less well-resourced players can benefit from AI. / A review of dozens of Chinese academic and industry papers published between 2024–2026 provides evidence of how Chinese entities are approaching distillation in problematic ways. — From the definition of distillation, its general use in industry, and the body of papers the analysis reviewed

Three reasons adversarial distillation is treated as a problem

The analysis sets out three.

The three problems the analysis identifies

1. Terms violation
It violates the terms of use of Western companies' models
2. A shortcut
It helps catch up to the frontier by leveraging leading models' strengths
3. Where it goes
Models built this way are being used in military and public security applications
On top of that
Having been distilled, they may not retain the safety guardrails of the original models

The analysis treats the third as the most important. The concern is less what the capability is than where it ends up.

It also goes into what specifically is being targeted: the chain of thought, the intermediate steps through which a model breaks down a problem and tests its findings before answering. This, the analysis says, is the most expensive capability to build, which is precisely why the incentive to distil it is strong.

View official source →
First, it violates the terms of use of Western companies’ models. Second, it provides a shortcut that helps Chinese models catch up to the frontier by leveraging the strengths of leading Western models. Third, and most important, Chinese models built in part from distilling Western models are being used in military and public security applications. Moreover, because they have been distilled, they may not retain the safety guardrails of the original models. / The prize is frontier reasoning: the step-by-step “chain of thought” that is the most expensive capability to build and the one on which U.S. laboratories lead most clearly. / Adversarial distillation aims to imitate how Western frontier models reason by targeting models’ “chain of thought” (思维链). These are the intermediate steps through which models breaks down a problem and tests its findings before offering an answer. — From the three reasons, the point about inherited safety guardrails, and the targeting of the chain of thought

Evidence that Chinese models derive from Western ones

For support, the analysis draws not on outside accusations but on experimental results from Chinese researchers themselves.

Qwen-Max said it was Claude; DeepSeek-V3 said it was made by OpenAI

A team centred on researchers at the Chinese Academy of Sciences jailbroke several Chinese models — bypassing their safety mechanisms — to see how much they would disclose about their own origins.

The reported result: Qwen-Max identified itself as "Claude, an AI assistant created by Anthropic," and DeepSeek-V3 answered that it was "created by OpenAI." The team ranked models by the strength of suspicion that they had been distilled, with Qwen-Max, GLM-4-Plus, and DeepSeek-V3 near the top.

The trigger the analysis places at the start is what happened around Moonshot AI's Kimi K3. Released in July 2026 and claimed by the company to stand alongside Western frontier models such as Anthropic's Claude Fable 5, it immediately drew accusations that it had reached the frontier by distilling Western models. We cover the model itself in our explainer on Kimi K3.

That criticism did not begin with suspicion of a single company. The analysis notes that as early as April 2026, the White House Office of Science and Technology Policy was alleging "industrial-scale campaigns to distill U.S. frontier AI systems." The policy-level assessment came first, with individual cases layering onto it.

View official source →
Qwen-Max identified itself as “Claude, an AI assistant created by Anthropic,” and DeepSeek-V3 answered that it was “created by OpenAI.” / In July 2026, Chinese artificial intelligence (AI) firm Moonshot AI (月之暗面) released Kimi K3 / Moonshot AI drew accusations that it had reached the frontier by distilling Western models / As early as April 2026, the White House Office of Science and Technology Policy was alleging “industrial-scale campaigns to distill U.S. frontier AI systems” — From the models' self-identification, the criticism around Kimi K3, and the US government's assertion

Research involving PLA-affiliated institutions

This is the core of the analysis: the entities doing distillation research include the military, the defence industry, and state research institutes.

Research the analysis cites (all publicly available papers)

EntityContent
Army Engineering University of PLADistilling "attack knowledge" that breaks safety mechanisms into small, fast tools, said to work very well against strongly safety-aligned commercial models
A PLA unit that may belong to the Rocket ForceDistilling OpenAI's GPT-3.5 into a series of smaller models that summarise code
Air Force Engineering University and othersDistilling several teacher models into a proxy model, then building tools to attack it
Nanjing University of Science and TechnologyHiding written commands inside images of tanks and warships to test whether models obey
University of Science and Technology of ChinaReducing "anomalous features" and increasing stealthiness to evade detection
PLA Cyberspace Force and othersRemoving watermarks — identifying marks embedded in a model — while inheriting the teacher's capabilities
View official source →
One survey paper by academics at Army Engineering University of PLA proposes distilling a way to break a model’s safety mechanism—known as “attack knowledge” (攻击知识)—into small, fast tools that can run attacks continuously. / The authors note that these tools work very well against “strongly safety-aligned commercial models” / In a separate paper, written by members of a PLA unit that may be part of the PLA Rocket Force, the authors distill OpenAI’s GPT-3.5 to create a series of smaller models that can summarize code to almost the same standard / A group from Air Force Engineering University, PLA Information Engineering University, and an undisclosed PLA unit distilled several teacher models to construct a proxy “black box” model, then built tools to attack it — From the descriptions behind the corresponding rows: distilling attack knowledge, distilling for code summarisation, and constructing a proxy model

Evading detection and removing watermarks are research topics too

The last two rows carry the most weight. Distillation can sometimes be detected because a watermark embedded in a model persists into the student. Research exists whose stated aim is to erase that trace, the analysis says.

The Nanjing experiment is concrete. Written commands were concealed inside images of tanks and warships, and GPT-4o and two versions of Claude allegedly read the hidden text and obeyed it. That is prompt injection — a separate question from distillation, about whether a model can be driven from outside.

Chinese models being used in the cyber domain has been reported elsewhere, including DeepSeek's model being used in an autonomous cyberattack.

View official source →
They reduced the “anomalous features” (异常特征) for which a model’s defense mechanism scans and increased the tool’s “stealthiness” (隐匿性) to defeat backdoor and poisoning detectors / one paper by researchers affiliated with the PLA Cyberspace Force and PLA Information Engineering University outlines ways to remove watermarks effectively while still inheriting the teacher model’s capabilities / In an experiment, they concealed written commands inside images of tanks and warships. GPT-4o and two versions of Claude allegedly read the hidden text and obeyed it — From the evasion techniques, watermark removal, and the image-embedded command experiment

Distilled models are going into surveillance and public security

The analysis also covers where the models end up. Engineers at the state-owned China Electronics Technology Group's smart city institute distilled large security models to run on the edge processors inside street cameras, identifying individual faces in crowds under low-light conditions.

It further records that researchers at the North University of China, which has its roots in the ordnance industry, distilled Claude to create a classifier they themselves propose could be used for social media monitoring and content moderation systems.

The wording deserves care here. "Is being used" and "is proposed as usable" are different things. The analysis writes in a way that includes proposals, and does not assert actual deployment.

Every paper the analysis cites is stated to be publicly available. If you want to go to the sources, pulling the text out of the documents you have downloaded is where to start.

View official source →
engineers at the state-owned China Electronics Technology Group’s smart city institute distilled large security (安防) models to run on the edge processors inside street cameras that can identify individual faces in crowds under low-light conditions for surveillance purposes / Researchers at the North University of China (中北大学), which has its roots in the ordnance industry, distilled Claude through a “multi-objective knowledge distillation” (多目标知识蒸馏) process to create a classifier they propose could be used for “social media monitoring and content moderation systems” (社交媒体监控以及内容审核系统) — From the deployment of distilled models to street cameras and the classifier distilled from Claude

Free ToolPDF to Markdown ConverterConvert PDF content to Markdown format. Auto-detects headings, tables, and lists — ideal for RAG and AI workflows.Try it now →

Two caveats to keep in mind when reading this analysis

Everything above is the analysis's own case. Two things are worth holding onto as a reader.

Publication lag means you are seeing the floor

The first is a caveat the analysis places itself. Chinese academic and military journals have review and publication cycles, and one to two years pass between experiment and publication. So what is described are experiments conducted against the frontier models of 2023 and 2024, which shows the floor of current capabilities, not a ceiling.

That does not weaken the case so much as set how to read it. Not "this is possible now" but "at minimum, this was being done two years ago."

View official source →
This means that these studies describe experiments conducted against the frontier models of 2023 and 2024, and so only show the floor of current PRC capabilities, not a ceiling. — From the lag between experiment and publication and how the analysis says to read it

Bear in mind what kind of document this is

The second is the character of the source. This is an analysis piece in the Jamestown Foundation's China Brief, structured to read published papers and then argue about what should be done. The individual papers cited are public and anyone can go to them, but what gets read out of them carries the author's perspective. Being able to trace the sources and agreeing with the interpretation are worth keeping separate.

The analysis's own summary avoids overstatement. Distillation of Western frontier models plays an important role in the PRC's AI ecosystem; that role is not decisive; but it is problematic — three steps, in that order.

View official source →
Distillation of Western frontier models plays an important role in the PRC’s AI ecosystem. This role is not decisive, but it is problematic. — From the analysis's summary of the role distillation plays in the PRC's AI ecosystem

Conclusion: why distillation became a security question

Knowledge distillation began as a technique for making models smaller and cheaper. It became a security question because distillation can extract the capability while leaving the constraints behind.

The reason the analysis treats the third problem as heaviest is that models built this way are actually being used in military and public security applications. Layered on top of that is the safety point. The original models have mechanisms for refusing dangerous uses built in, but copying only the outputs to train another model carries no guarantee those mechanisms come along. The capability moves somewhere consequential, and the brakes may be thinner — that overlap is the issue.

Step back further and this connects to compute. Distillation is attractive as a shortcut precisely because training head-on demands enormous compute. How Chinese AI companies secure that compute is covered in reporting on Moonshot AI's chip sourcing. A route to compute, and a route to capability — those are the two things being watched.

Free ToolPDF to Markdown ConverterConvert PDF content to Markdown format. Auto-detects headings, tables, and lists — ideal for RAG and AI workflows.Try it now →

FAQ

Q. What is knowledge distillation in AI?
It is the practice of training a smaller, cheaper student model using the outputs of a larger teacher model — getting close to the teacher's performance by copying how it answers, rather than training from scratch. The analysis does not treat this as bad in itself, noting it is used widely across the industry and helps maintain an ecosystem in which less well-resourced players can benefit from AI.
Jamestown Foundation — definition of distillation
Distillation (知识蒸馏) refers to the practice of training a smaller, cheaper “student” model by using the outputs of a larger “teacher” model. / It is a practice used widely across the industry for a variety of purposes. It is good for competition and helps maintain an ecosystem in which less well-resourced players can benefit from AI. Jamestown Foundation — definition of distillation
Q. How does adversarial distillation differ from ordinary distillation?
The analysis raises three problems: it violates the terms of use of Western companies' models, it provides a shortcut to the frontier, and models built partly by distilling Western models are being used in military and public security applications. It also notes that having been distilled, such models may not retain the safety guardrails of the originals.
Jamestown Foundation — three reasons adversarial distillation is a problem
First, it violates the terms of use of Western companies’ models. Second, it provides a shortcut that helps Chinese models catch up to the frontier by leveraging the strengths of leading Western models. Third, and most important, Chinese models built in part from distilling Western models are being used in military and public security applications. Moreover, because they have been distilled, they may not retain the safety guardrails of the original models. Jamestown Foundation — three reasons adversarial distillation is a problem
Q. Can't terms of service simply prohibit it?
Chinese researchers argue it is hard to stop. The analysis cites a scholar at Xiangtan University who calls distillation difficult to effectively regulate and, having reviewed the terms of service of ChatGPT, Claude, and Gemini, concludes that the anti-distillation clauses are practically unenforceable — the reasoning being that copyright protects expression, not what a model does.
Jamestown Foundation — the Chinese debate over enforceability
A scholar at Xiangtan University notes that distillation is “difficult to effectively regulate” (难以有效规制), and having reviewed the terms of service of ChatGPT, Claude, and Gemini, finds that the companies’ anti-distillation clauses are practically unenforceable. Jamestown Foundation — the Chinese debate over enforceability
Q. How current is the picture this analysis gives?
The analysis places its own caveat. Chinese academic and military journals have review and publication cycles of one to two years, so the studies describe experiments conducted against the frontier models of 2023 and 2024. On its own account, that shows the floor of current capabilities rather than the ceiling.
Jamestown Foundation — caveat on publication lag
This means that these studies describe experiments conducted against the frontier models of 2023 and 2024, and so only show the floor of current PRC capabilities, not a ceiling. Jamestown Foundation — caveat on publication lag

Related Tools

Related Tool Categories

Articles