Skip to content
World AI Conference

Chinese Research Details Distillation for Military Use

Technology Publication

07.30.2026 Sunny Cheung

Chinese Research Details Distillation for Military Use

Executive Summary:

  • Distillation has become essential to the rise of Chinese artificial intelligence (AI) models. Chinese academic and industry papers published in the period 2024–2026 detail how distillation takes place—including adversarial distillation—and provides insight into the kinds of entities involved in the work of using leading models to build capabilities that rival the world’s best models.
  • The prize is frontier reasoning: the step-by-step “chain of thought” that is the most expensive capability to build and the one on which U.S. laboratories lead most clearly. The Chinese research literature documents a deliberate, premeditated effort to distill that capability.
  • Some published Chinese research also focuses on engineering distillation techniques to evade detection. Much of this work is conducted by researchers affiliated with the People’s Liberation Army, the defense industry, and the Chinese Academy of Sciences.
  • Distilled models are either already being used, or are proposed to be used, for public security applications such as surveillance and monitoring systems, and for military and cyber operations.

In July 2026, Chinese artificial intelligence (AI) firm Moonshot AI (月之暗面) released Kimi K3, a model it claims is on par with leading Western models such as Anthropic’s Claude Fable 5. Instantly, Moonshot AI drew accusations that it had reached the frontier by distilling Western models (The Hill, July 22). The charge has an official pedigree. As early as April 2026, the White House Office of Science and Technology Policy was alleging “industrial-scale campaigns to distill U.S. frontier AI systems” (White House, April 23). Leading Western AI firms have also accused Chinese competitors of distilling their models (OpenAI, February 12; Anthropic, February 23).

Distillation (知识蒸馏) refers to the practice of training a smaller, cheaper “student” model by using the outputs of a larger “teacher” model. It is a practice used widely across the industry for a variety of purposes. It is good for competition and helps maintain an ecosystem in which less well-resourced players can benefit from AI. In some cases, however, distillation is abused, with certain labs in the People’s Republic of China (PRC) the most prominent practitioners. These actors engage in what is known as adversarial distillation, and it is problematic for three main reasons. First, it violates the terms of use of Western companies’ models. Second, it provides a shortcut that helps Chinese models catch up to the frontier by leveraging the strengths of leading Western models. Third, and most important, Chinese models built in part from distilling Western models are being used in military and public security applications. Moreover, because they have been distilled, they may not retain the safety guardrails of the original models.

A review of dozens of Chinese academic and industry papers published between 2024–2026 provides evidence of how Chinese entities are approaching distillation in problematic ways. First, a portion of PRC research targets the acquisition of Western models’ frontier reasoning capabilities and develops techniques to obscure evidence of copying. Second, researchers working on adversarial distillation have ties to the People’s Liberation Army (PLA), the PRC’s defense-industrial base, and state-owned research academies. Third, distilled models are being developed for use in surveillance, public security, and cyber operations.

The papers reviewed here are all accessible in the open domain. Although they provide strong evidence for PRC research programs focused on adversarial distillation, they likely represents just the tip of the iceberg and some lagging examples. (Similar to Western academic publishing, Chinese academic and military journals run on internal review and publication cycles that puts 1–2 years between the work itself and the publication of the results. This means that these studies describe experiments conducted against the frontier models of 2023 and 2024, and so only shows the floor of current PRC capabilities, not a ceiling.) For Chinese entities, the case for concealing information around distillation is strong: beyond any potential legal or ethical concerns, an admission that leading Chinese models are developed in part by stealing from Western capabilities undermines PRC narratives of technological self-reliance in emerging domains.

Chinese Research is Explicit About Adversarial Distillation

Adversarial distillation aims to imitate how Western frontier models reason. It targets models’ “chain of thought” (思维链), the intermediate steps through which it breaks down a problem and tests its findings before offering an answer. Research has shown that such step-by-step reasoning substantially improves performance in mathematics, logic, and coding (Google, May 11, 2022). The temptation to distill is strong. Reasoning is not just key to model performance, but among the most expensive capabilities to develop (OpenAI, September 12, 2024). Distillation offers a shortcut. By collecting a frontier model’s reasoning traces, developers can train a smaller model to imitate the results of that investment as much as possible without repeating the original training process.

Chinese researchers’ own work has shown that Chinese models have been distilled from Western ones. A team led by academics at the Chinese Academy of Sciences (CAS) jailbroke various Chinese models to bypass their self-awareness and then scored them on how readily each betrayed a foreign origin. Qwen-Max identified itself as “Claude, an AI assistant created by Anthropic,” and DeepSeek-V3 answered that it was “created by OpenAI.” The researchers developed a scale to rank each of the models based on the suspicion that they had been distilled: Qwen-Max, GLM-4-Plus, and DeepSeek-V3 came out at or near the top (Sunbowen Lee et al., 2026). [1] This corroborates comments by U.S. Treasury Secretary Scott Bessent stating that the U.S. government has found watermarks from U.S. models in many Chinese models (CNBC, July 21).

These particular instances of distillation may not all have been adversarial, but that does not necessarily mean that they were legitimate. Using OpenAI’s InstructGPT, researchers at Xidian University—working alongside a People’s Armed Police counterterrorism laboratory—were able to “greatly improve” (大大提高) model performance. Their process involved generating eight different responses for each question asked of OpenAI’s model and manually correcting weaker outputs (Li Ronghan et al., 2024). [2] InstructGPT is accessible through an API, but OpenAI’s current policies prohibit its use for national security- or intelligence-related use cases without the firm’s approval, and prohibit using its outputs to “develop models that compete with OpenAI” (OpenAI, January 27, 2022, October 29, 2025, January 1).

PLA-linked entities intentionally abuse distillation. Although APIs like InstructGPT allow for developers to distill closed-weight models, some research details attempts not just to move beyond this, but to defeat the teacher model host’s ability to detect adversarial distillation and to conceal distillation in the student model once it has occurred. [3] These attempts to bypass a model’s safeguards and modify it for potentially harmful purposes is intentional. In at least one case, concealing a model’s origins was an explicit goal. A paper by researchers at the University of Science and Technology of China sought to create tools to avoid detection in distillation attacks. They reduced the “anomalous features” (异常特征) for which a model’s defense mechanism scans and increased the tool’s “stealthiness” (隐匿性) to defeat backdoor and poisoning detectors (Wang Yifan et al., 2025). [4]

U.S. firms and government officials see adversarial distillation as an activity that harms leading AI companies and may even break U.S. law, but some PRC experts have argued that any legal objections do not matter. A scholar at Xiangtan University notes that distillation is “difficult to effectively regulate” (难以有效规制), and having reviewed the terms of service of ChatGPT, Claude, and Gemini, finds that the companies’ anti-distillation clauses are practically unenforceable. They argue that this is because copyright protects how something is expressed, not what it does, and distillation takes what the model does. To remedy this, they propose that Beijing legislate a “compulsory-licensing” (强制许可) regime so that Chinese “student models” can distill foreign teacher models for a set fee—even over the objections of foreign firms. They justify this in the name of opposing AI hegemony and “malicious monopolies” (恶意垄断) (Han Shuo, 2025). [5]

Adversarial Distillation for Adversarial Purposes

Many of the researchers engaged in the adversarial distillation of frontier models are affiliated with entities whose interests are fundamentally misaligned with those of the United States. These include Chinese military institutions, such as the counterterrorism laboratory highlighted above, as well as entities that operate under the official sanction of the CCP, such as its leading scientific research organization, CAS. Even civilian institutions pose a problem as, under the PRC’s military–civil fusion development strategy, the Party-state has built a system that dissolves the boundary between civilian laboratories and the defense establishment.

A number of papers by military researchers focus on distillation techniques Western models. One survey paper by academics at Army Engineering University of PLA proposes distilling a way to break a model’s safety mechanism—known as “attack knowledge” (攻击知识)—into small, fast tools that can run attacks continuously. The authors note that these tools work very well against “strongly safety-aligned commercial models” (强安全对齐商业模型_) (Tao Jialing et al., 2025). [6]

In a separate paper, written by members of a PLA unit that may be part of the PLA Rocket Force, the authors distill OpenAI’s GPT-3.5 to create a series of smaller models that can summarize code to almost the same standard, with “no significant differences between the summaries generated by the two models in terms of accuracy, completeness, or concision” (在准确性、完整性或简洁性方面并没有显著差异) (You Gang et al., 2025). [7]

PLA researchers have also studied methods to attack closed models for distillation. A group from Air Force Engineering University, PLA Information Engineering University, and an undisclosed PLA unit distilled several teacher models to construct a proxy “black box” model, then built tools to attack it (Shi Jiale et al., 2026). [8] The purpose of this research is to train tools for adversarial distillation. The fact that it was funded as part of a project titled “Key Technologies for Data Security in Military Big-Data Collection and Circulation” (军事大数据采集流转中数据安全关键技术研究) implies that PLA is interested in distillation in part to create good enough models to control all military-relevant data and algorithms—an essential capability for building a self-reliant and intelligentized military. In a similar paper, a group from Nanjing University of Science and Technology, one of the military-linked Seven Sons of National Defense, tested whether Western frontier models can be hijacked via prompt-injection. In an experiment, they concealed written commands inside images of tanks and warships. GPT-4o and two versions of Claude allegedly read the hidden text and obeyed it (Wang Wen et al., 2025). [9]

Additional research focuses on post-distillation methods to obscure the provenance of student models. For instance, one paper by researchers affiliated with the PLA Cyberspace Force and PLA Information Engineering University outlines ways to remove watermarks effectively while still inheriting the teacher model’s capabilities (Yin Zhaoyu et al., 2025). [10]

This tranche of research papers provide the evidence to ground the twin concerns that surround distillation of Western models in the PRC: that Chinese entities are engaging in adversarial distillation to shortcut the model development process, and that the PLA is distilling models for military purposes. If PRC researchers find ways to successfully distill Western models without detection and without any observable trace in the student models, it may become increasingly difficult to assess both the true vulnerabilities of Western models and the true capabilities of Chinese ones.

A further danger is that Western models are distilled for use in systems that may lead to human rights abuses. Most of the research on distillation for public security applications appears to involve the distillation of Chinese models (though, as the CAS study referenced above exposed, many of these models have been built partly by distilling Western models). For instance, engineers at the state-owned China Electronics Technology Group’s smart city institute distilled large security (安防) models to run on the edge processors inside street cameras that can identify individual faces in crowds under low-light conditions for surveillance purposes (Liu Wei, 2025). [11] The same group’s 30th Research Institute has used the same techniques to build tools for intelligence collection, malware detection, and tracing cyberattacks/cyber intrusion to their source (攻击溯源) (Ren Hengyi et al., 2026). [12]

Some evidence is now emerging that Western models are also being distilled for similar purposes. Researchers at the North University of China (中北大学), which has its roots in the ordnance industry, distilled Claude through a “multi-objective knowledge distillation” (多目标知识蒸馏) process to create a classifier they propose could be used for “social media monitoring and content moderation systems” (社交媒体监控以及内容审核系统) (Jiang Biyi et al., 2025). [13]

Conclusion

Distillation of Western frontier models plays an important role in the PRC’s AI ecosystem. This role is not decisive, but it is problematic. It is also set to persist—particularly if, as a recent DeepSeek paper finds, distillation can lead to better-performing models than other fine-tuning techniques such as instruction tuning (DeepSeek-AI, 2025). [14]

Mitigating problematic distillation starts with distinguishing between ordinary and adversarial activity. Distillation continues to be common in the development of smaller, cheaper, competitive models. Adversarial distillation, however, involves building student models via large-scale “knowledge distillation attacks” that violate the terms of use of teacher models, may break the law, are intended to undermine frontier models, and are built for use cases that would not be permitted by the guardrails of the original models. Useful indicators of adversarial distillation include the specific capabilities that get distilled, the actors involved in the distillation, and whether attempts are made to obscure provenance.

Until steps to mitigate adversarial distillation are taken, the PRC will continue to narrow its gap with the technological frontier, improve military capabilities, and support the Party-state’s surveillance and monitoring systems.

Notes

[1] Sunbowen Lee et al., “Quantification of Large Language Model Distillation,” arXiv:2501.12619, 2025.

[2] Li Ronghan [李荣涵], Pu Rongcheng [浦荣成], Shen Jianan [沈佳楠], Li Dongdong [李栋栋], and Miao Qiguang [苗启广]. “Knowledge Distillation of Large Language Models Based on Chain of Thought” [基于思维链的大语言模型知识蒸馏], Journal of Data Acquisition and Processing [数据采集与处理] 39, no. 3 (2024): 547–558.
A team at Guizhou Minzu University applied a similar process to GPT-3.5, keeping only mutually consistent answers (Cai Liqiong et al., 2026). See Cai Liqiong [蔡丽琼], Huo Yujia [霍雨佳], and Yuan Saixian [袁赛仙]. “Multi-path Consistency Distillation Based on Large Language Models” [基于大语言模型的多路径一致性蒸馏], Information Technology & Informatization [信息技术与信息化], no. 1 (2026): 130–133.

[3] Distillation can sometimes be detected because of a model’s watermarks and chain-of-thought reasoning that can carry over into anything trained on its outputs. See Tom Sander et al., “Watermarking Makes Language Models Radioactive,” arXiv:2402.14904, 2024; Sumanth Dathathri et al., “Scalable Watermarking for Identifying Large Language Model Outputs,” Nature 634 (2024).

[4] Wang Yifan [王亦帆], Fan Wei [樊 伟], Yang Keke [杨珂珂], and Li Jing [李 京], “A Knowledge Distillation-Based Backdoor Attack in Federated Learning” [一种基于知识蒸馏的联邦学习后门攻击方法], Computer Applications and Software [计算机应用与软件] 43, no. 3 (2026): 361–368.
Distillation is used to weaken the anomalous features that robust-aggregation defenses rely on to detect a tampered model. See also Zhao Tong [赵桐], “A Knowledge Distillation-Based Backdoor Attack in Federated Learning” [基于知识蒸馏的联邦学习后门攻击方法], Computer Science [计算机科学], 2025.

[5] Han Shuo [韩硕], “Legal Risks and Compliance Countermeasures for AI Model Distillation Conducted in Violation of User Agreements” [违反用户协议进行AI模型蒸馏的法律风险及合规对策], Journal of Taiyuan University of Technology(Social Science Edition) [太原理工大学学报·社会科学版] 44, no. 3 (2026).

[6] Tao Jialing [陶佳玲], Song Huang [黄松], Xinyi Gao [高心怡], Yong Fang [方 勇], Yubin Qu [曲豫宾], Ruiyang Li [李瑞阳], Jiangtao Lu [陆江涛], “A Review of Black-box Jailbreak Attacks on Large Language Models for Optimization” [面向优化的大语言模型黑盒越狱攻击研究综述], Journal of Sichuan University, Natural Science Edition [四川大学学报·自然科学版] 63, no. 2 (2026): 241–58.

[7] You Gang [尤刚], Liu Wenjie [刘文杰], Li Meipeng [李美鹏], Sun Liqun [孙立群], Wang Lian [王 炼], Tian Tieku [田铁库], “Code summarization based on large model knowledge distillation” [基于大模型知识蒸馏的代码摘要自动生成], Command Control & Simulation [指挥控制与仿真], 2025, 47(4): 27–33.
The PLA Rocket Force is assigned all military unit cover designators (MUCDs) that begin with the numbers 96 (See: Miller, Frank, Tung Ho, Kenneth Allen, and Arran Hope, eds. The People’s Liberation Army as Organization Volume 3.0. Washington, D.C.: The Jamestown Foundation; Vienna: Exovera, 2025, p.273).

[8] Shi Jiale [石家乐], Song Yafei [宋亚飞], Wu Shaosuo [吴晓佰], Li Tianpeng [李天鹏], “Black-box attack method based on improved knowledge distillation” [基于改进知识蒸馏的黑盒攻击方法], SCIENTIA SINICA Informationis [中国科学:信息科学] 55, no. 11 (2025): 2780–97.

[9] Wang Wen [王雯], Kuiwu Yang [杨奎武], Songsong Tong [仝松松], Jianghong Wei [魏江宏], Yan Xue [薛岩], Rongkui Zhou [周荣魁], “Research on Watermarking Attack of Deep Neural Network Models” [深度神经网络模型水印攻击研究], Computer Engineering [计算机工程] 52, no. 4 (2026).

[10] Yin Zhaoyu [尹照煜], Song Wen’ai [宋文爱], Liu Honghao [刘宏昊], “Low-resource text new strategy classification in hardware-limited environments” [硬件有限环境中低资源文本分类新策略], Modern Electronics Technique [现代电子技术] 48, no. 8 (2025): 56–62.

[11] Liu Wei [刘伟], “Optimization of a Security Big Data Model Based on Knowledge Distillation on Low-Computing-Power Terminals” [基于知识蒸馏的安防大模型在低算力终端的优化], Information Security [信息安全], May 2025, 125–27. 

[12] Ren Hengyi [任恒毅], Sun Zhi [孙治], Liao Shan [廖珊], Mao Deming [毛得明], Zhang Ling [张玲], Zhang Shuwen [张淑文], “Survey on applications of large language models in cyber threat analysis” [大语言模型在网络威胁分析领域应用的综述], Journal of Computer Applications [计算机应用], forthcoming 2026.

[13] Jiang Biyi [姜碧怡], Song Zhenbo [宋振波], Lu Jianfeng [陆建峰], Lu Chen [陆辰], “Prompt injection attack and defense for visual language models in military command systems” [军事指挥系统视觉语言模型提示注入攻击与防御], Command Information System and Technology [指挥信息系统与技术] 16, no. 6 (2025): 23–29.

[14] DeepSeek-AI, “DeepSeek-R1: Incentivizing Reasoning Capability in LLMs via Reinforcement Learning,” arXiv:2501.12948, 2025.

Jamestown
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.