Chinese Military Explores AI Distillation for Advanced Systems

Chinese military-affiliated researchers are actively investigating the use of AI distillation techniques to develop more efficient models for applications in drones, battlefield operations, cybersecurity, and public security systems. This approach involves training smaller, cost-effective “student” models using outputs from more advanced “teacher” models, potentially accelerating the development of dual-use technologies while circumventing the original models’ built-in safeguards.

AI distillation is a common practice in legitimate AI development, where a less complex model learns from a more sophisticated one to achieve similar performance with reduced computational requirements. However, recent studies indicate that Chinese researchers are applying this method to replicate reasoning abilities, bypass restrictions, and obscure the origins of a model’s capabilities.

Analysts at Jamestown have identified a series of Chinese academic and industry publications from 2024 to 2026 that suggest deliberate efforts in adversarial distillation. These studies are linked to the People’s Liberation Army (PLA), defense-related universities, state institutes, and public security organizations. The research highlights attempts to extract or reproduce the reasoning patterns of leading closed AI models, which are essential for tasks such as coding, logical analysis, and problem-solving.

For instance, a paper from the Army Engineering University proposed distilling knowledge about breaching AI safety mechanisms into smaller tools capable of conducting continuous attacks. Other PLA-affiliated studies explored creating proxy models for black-box attacks and developing compact models that can summarize code at a proficiency level comparable to GPT-3.5.

Additionally, some research focuses on making these replicated capabilities more challenging to detect. A study involving researchers from PLA cyber units outlined methods to remove watermarks while preserving the functionalities of the original models. Other work aimed to diminish the signals that security systems use to identify tampered models.

The implications of these developments extend beyond intellectual property concerns. The risks associated with prompt injection attacks on AI agents demonstrate how models can be manipulated when untrusted instructions are processed as legitimate commands. This vulnerability becomes particularly critical when such systems are integrated into military or operational environments.

The reviewed papers also suggest that distilled models are being proposed or utilized for surveillance, public security, cyber threat analysis, and military command-related tasks. Researchers connected to a state-owned smart-city institute described compact security models for edge processors in street cameras capable of recognizing faces in crowds under low-light conditions. Another institute within the same state-owned group applied similar techniques in proposed tools for intelligence collection, malware detection, and cyber intrusion tracing. Additionally, researchers at the North University of China detailed the distillation of Claude into a classifier to support social media monitoring and content moderation.

Military research has further examined multimodal prompt injection, including experiments that embedded written instructions within images of tanks and warships. The researchers reported that GPT-4o and versions of Claude processed and acted upon the concealed text, raising concerns about hidden instructions targeting AI systems that handle images and external content.

Jamestown analysts caution that publicly available papers likely reveal only a portion of the ongoing activities and may describe research completed one or two years prior. If models can be distilled without detectable watermarks or recognizable reasoning traces, assessing both the true capabilities of Chinese systems and the exposure of Western models becomes increasingly challenging.

These developments underscore the need for vigilance in monitoring the use of AI distillation techniques, particularly when they have the potential to enhance military and surveillance capabilities. The ability to replicate advanced AI functionalities without the original safeguards poses significant security risks, necessitating coordinated efforts to address these emerging challenges.