Chinese military researchers have used US AI models for defence systems

The documents indicate that model distillation is used in local systems on drones, tactical equipment and military networks.

0

Chinese military researchers have used the results of work carried out by the American companies OpenAI and Anthropic to train their own artificial intelligence systems for defence purposes. This was established by Reuters after analysing more than 80 Chinese scientific papers and patents. The focus is primarily on distillation — the process of transferring specific capabilities from large models to compact systems capable of operating on local networks and on hardware with limited resources.

Briefly about the main points

  • Reuters analysed more than 80 Chinese scientific papers and patents.
  • The researchers used distillation of responses from OpenAI and Anthropic models.
  • GPT-3.5 was used to process military source code.
  • The technology was tested for use with drones, target recognition and content monitoring.
  • Distilled models do not replicate the full capabilities of state-of-the-art systems.

From software code to tactical platforms

Reuters also examined academic publications compiled by the Washington-based Jamestown Foundation and identified a further two dozen or so examples linked to military organisations. According to the foundation’s researcher, Sunny Cheng, Chinese academics are systematically attempting to apply the logic of Western systems — for surveillance, cyber warfare and tactical decision-making — to smaller-scale models.

One of the papers, published last year by researchers at the 96941 branch of the NVA in Beijing, describes the use of GPT-3.5 for generalising military programme code. The authors considered third-party models unsuitable for handling classified data, so they trained the domestic system using these generalisations. It was intended to be run entirely within Chinese military networks.

In a 2024 study by the National University of Defence Technologies (NVDT), distillation was used to reduce the size of an image-processing model for installation on drones. Such a system was designed to analyse video in real time and assist with navigation and target selection, even when communications were interrupted. The Chinese Academy of Military Sciences, for its part, tested a target recognition model on tactical equipment during simulated naval operations involving drones, ships and unmanned underwater vehicles.

Why has distillation become a subject of controversy?

Distillation is, in itself, a common practice in the industry: a powerful model generates responses or training data, which are then used to train a smaller, specialised system. This reduces computational requirements and enables the model to be deployed locally. For China, this approach is particularly relevant given US restrictions on access to advanced chips; the country’s central and local authorities support «lightweight» models and edge computing for devices such as drones and satellites.

Washington has accused certain Chinese entities of using reverse engineering to unlawfully extract capabilities from American models, which, in the US view, could undermine export controls and infringe intellectual property rights. Beijing has rejected these allegations, describing US AI policy as «hegemony», whilst the start-up Moonshot refuted the Trump administration’s claim that his Kimi K3 had been produced using distillation.

Anthropic told Reuters that it does not provide commercial access to Claude in China or to companies controlled by Beijing, and that it carries out monitoring to detect breaches of the rules. The company cautioned that smaller models may lack the built-in safety safeguards of the original system, which could result in sensitive capabilities being transferred beyond the developer’s control.

An advantage in deployment does not imply technological independence

At the same time, Chinese military researchers also regard distillation as a risk. In January, researchers at the Army Engineering University described the threat of «data-free distillation» — a method of reverse-engineering a model’s capabilities without direct access to its underlying parameters. They proposed concealing logical information that might be revealed in the system’s public responses.

Trevor Koverko, co-founder of the AI data company Sapien, emphasised that distilled systems remain less powerful than the models on which they were trained. Consequently, whilst this method allows individual functions to be transferred to cheaper and more controllable on-premises tools, it does not replace the large-scale computing required to build advanced AI models from scratch.

WRITE A REPLY

enter your comment!
enter your name here