What knowledge distillation is: training a student on a teacher's outputs
Knowledge distillation is the practice of training a smaller, cheaper student model using the outputs of a larger, more expensive teacher model. In Chinese it is written 知识蒸馏.
The cooking analogy: rather than making the stock again from scratch, you taste the finished stock and reproduce the flavour. It costs orders of magnitude less than training from nothing.
About the analysis
Distillation itself is used widely across the industry
Worth establishing first: the analysis does not treat distillation in general as bad. It states outright that the practice is used widely across the industry, is good for competition, and helps maintain an ecosystem in which less well-resourced players can benefit from AI.
What it raises as a problem is that some of it takes the form it calls adversarial distillation.
Distillation (知识蒸馏) refers to the practice of training a smaller, cheaper “student” model by using the outputs of a larger “teacher” model. / It is a practice used widely across the industry for a variety of purposes. It is good for competition and helps maintain an ecosystem in which less well-resourced players can benefit from AI. / A review of dozens of Chinese academic and industry papers published between 2024–2026 provides evidence of how Chinese entities are approaching distillation in problematic ways. — From the definition of distillation, its general use in industry, and the body of papers the analysis reviewed
Three reasons adversarial distillation is treated as a problem
The analysis sets out three.
The three problems the analysis identifies
The analysis treats the third as the most important. The concern is less what the capability is than where it ends up.
It also goes into what specifically is being targeted: the chain of thought, the intermediate steps through which a model breaks down a problem and tests its findings before answering. This, the analysis says, is the most expensive capability to build, which is precisely why the incentive to distil it is strong.
First, it violates the terms of use of Western companies’ models. Second, it provides a shortcut that helps Chinese models catch up to the frontier by leveraging the strengths of leading Western models. Third, and most important, Chinese models built in part from distilling Western models are being used in military and public security applications. Moreover, because they have been distilled, they may not retain the safety guardrails of the original models. / The prize is frontier reasoning: the step-by-step “chain of thought” that is the most expensive capability to build and the one on which U.S. laboratories lead most clearly. / Adversarial distillation aims to imitate how Western frontier models reason by targeting models’ “chain of thought” (思维链). These are the intermediate steps through which models breaks down a problem and tests its findings before offering an answer. — From the three reasons, the point about inherited safety guardrails, and the targeting of the chain of thought
Evidence that Chinese models derive from Western ones
For support, the analysis draws not on outside accusations but on experimental results from Chinese researchers themselves.
Qwen-Max said it was Claude; DeepSeek-V3 said it was made by OpenAI
A team centred on researchers at the Chinese Academy of Sciences jailbroke several Chinese models — bypassing their safety mechanisms — to see how much they would disclose about their own origins.
The reported result: Qwen-Max identified itself as "Claude, an AI assistant created by Anthropic," and DeepSeek-V3 answered that it was "created by OpenAI." The team ranked models by the strength of suspicion that they had been distilled, with Qwen-Max, GLM-4-Plus, and DeepSeek-V3 near the top.
The trigger the analysis places at the start is what happened around Moonshot AI's Kimi K3. Released in July 2026 and claimed by the company to stand alongside Western frontier models such as Anthropic's Claude Fable 5, it immediately drew accusations that it had reached the frontier by distilling Western models. We cover the model itself in our explainer on Kimi K3.
That criticism did not begin with suspicion of a single company. The analysis notes that as early as April 2026, the White House Office of Science and Technology Policy was alleging "industrial-scale campaigns to distill U.S. frontier AI systems." The policy-level assessment came first, with individual cases layering onto it.
Qwen-Max identified itself as “Claude, an AI assistant created by Anthropic,” and DeepSeek-V3 answered that it was “created by OpenAI.” / In July 2026, Chinese artificial intelligence (AI) firm Moonshot AI (月之暗面) released Kimi K3 / Moonshot AI drew accusations that it had reached the frontier by distilling Western models / As early as April 2026, the White House Office of Science and Technology Policy was alleging “industrial-scale campaigns to distill U.S. frontier AI systems” — From the models' self-identification, the criticism around Kimi K3, and the US government's assertion
Research involving PLA-affiliated institutions
This is the core of the analysis: the entities doing distillation research include the military, the defence industry, and state research institutes.
Research the analysis cites (all publicly available papers)
| Entity | Content |
|---|---|
| Army Engineering University of PLA | Distilling "attack knowledge" that breaks safety mechanisms into small, fast tools, said to work very well against strongly safety-aligned commercial models |
| A PLA unit that may belong to the Rocket Force | Distilling OpenAI's GPT-3.5 into a series of smaller models that summarise code |
| Air Force Engineering University and others | Distilling several teacher models into a proxy model, then building tools to attack it |
| Nanjing University of Science and Technology | Hiding written commands inside images of tanks and warships to test whether models obey |
| University of Science and Technology of China | Reducing "anomalous features" and increasing stealthiness to evade detection |
| PLA Cyberspace Force and others | Removing watermarks — identifying marks embedded in a model — while inheriting the teacher's capabilities |
One survey paper by academics at Army Engineering University of PLA proposes distilling a way to break a model’s safety mechanism—known as “attack knowledge” (攻击知识)—into small, fast tools that can run attacks continuously. / The authors note that these tools work very well against “strongly safety-aligned commercial models” / In a separate paper, written by members of a PLA unit that may be part of the PLA Rocket Force, the authors distill OpenAI’s GPT-3.5 to create a series of smaller models that can summarize code to almost the same standard / A group from Air Force Engineering University, PLA Information Engineering University, and an undisclosed PLA unit distilled several teacher models to construct a proxy “black box” model, then built tools to attack it — From the descriptions behind the corresponding rows: distilling attack knowledge, distilling for code summarisation, and constructing a proxy model
Evading detection and removing watermarks are research topics too
The last two rows carry the most weight. Distillation can sometimes be detected because a watermark embedded in a model persists into the student. Research exists whose stated aim is to erase that trace, the analysis says.
The Nanjing experiment is concrete. Written commands were concealed inside images of tanks and warships, and GPT-4o and two versions of Claude allegedly read the hidden text and obeyed it. That is prompt injection — a separate question from distillation, about whether a model can be driven from outside.
Chinese models being used in the cyber domain has been reported elsewhere, including DeepSeek's model being used in an autonomous cyberattack.
They reduced the “anomalous features” (异常特征) for which a model’s defense mechanism scans and increased the tool’s “stealthiness” (隐匿性) to defeat backdoor and poisoning detectors / one paper by researchers affiliated with the PLA Cyberspace Force and PLA Information Engineering University outlines ways to remove watermarks effectively while still inheriting the teacher model’s capabilities / In an experiment, they concealed written commands inside images of tanks and warships. GPT-4o and two versions of Claude allegedly read the hidden text and obeyed it — From the evasion techniques, watermark removal, and the image-embedded command experiment
Distilled models are going into surveillance and public security
The analysis also covers where the models end up. Engineers at the state-owned China Electronics Technology Group's smart city institute distilled large security models to run on the edge processors inside street cameras, identifying individual faces in crowds under low-light conditions.
It further records that researchers at the North University of China, which has its roots in the ordnance industry, distilled Claude to create a classifier they themselves propose could be used for social media monitoring and content moderation systems.
The wording deserves care here. "Is being used" and "is proposed as usable" are different things. The analysis writes in a way that includes proposals, and does not assert actual deployment.
Every paper the analysis cites is stated to be publicly available. If you want to go to the sources, pulling the text out of the documents you have downloaded is where to start.
engineers at the state-owned China Electronics Technology Group’s smart city institute distilled large security (安防) models to run on the edge processors inside street cameras that can identify individual faces in crowds under low-light conditions for surveillance purposes / Researchers at the North University of China (中北大学), which has its roots in the ordnance industry, distilled Claude through a “multi-objective knowledge distillation” (多目标知识蒸馏) process to create a classifier they propose could be used for “social media monitoring and content moderation systems” (社交媒体监控以及内容审核系统) — From the deployment of distilled models to street cameras and the classifier distilled from Claude
Two caveats to keep in mind when reading this analysis
Everything above is the analysis's own case. Two things are worth holding onto as a reader.
Publication lag means you are seeing the floor
The first is a caveat the analysis places itself. Chinese academic and military journals have review and publication cycles, and one to two years pass between experiment and publication. So what is described are experiments conducted against the frontier models of 2023 and 2024, which shows the floor of current capabilities, not a ceiling.
That does not weaken the case so much as set how to read it. Not "this is possible now" but "at minimum, this was being done two years ago."
This means that these studies describe experiments conducted against the frontier models of 2023 and 2024, and so only show the floor of current PRC capabilities, not a ceiling. — From the lag between experiment and publication and how the analysis says to read it
Bear in mind what kind of document this is
The second is the character of the source. This is an analysis piece in the Jamestown Foundation's China Brief, structured to read published papers and then argue about what should be done. The individual papers cited are public and anyone can go to them, but what gets read out of them carries the author's perspective. Being able to trace the sources and agreeing with the interpretation are worth keeping separate.
The analysis's own summary avoids overstatement. Distillation of Western frontier models plays an important role in the PRC's AI ecosystem; that role is not decisive; but it is problematic — three steps, in that order.
Distillation of Western frontier models plays an important role in the PRC’s AI ecosystem. This role is not decisive, but it is problematic. — From the analysis's summary of the role distillation plays in the PRC's AI ecosystem
Conclusion: why distillation became a security question
Knowledge distillation began as a technique for making models smaller and cheaper. It became a security question because distillation can extract the capability while leaving the constraints behind.
The reason the analysis treats the third problem as heaviest is that models built this way are actually being used in military and public security applications. Layered on top of that is the safety point. The original models have mechanisms for refusing dangerous uses built in, but copying only the outputs to train another model carries no guarantee those mechanisms come along. The capability moves somewhere consequential, and the brakes may be thinner — that overlap is the issue.
Step back further and this connects to compute. Distillation is attractive as a shortcut precisely because training head-on demands enormous compute. How Chinese AI companies secure that compute is covered in reporting on Moonshot AI's chip sourcing. A route to compute, and a route to capability — those are the two things being watched.



