Chinese Military Researchers Exploit U.S. AI Models to Sharpen Beijing’s War Machine

Chinese military researchers have been using outputs from leading American artificial intelligence models to train homegrown systems aimed at strengthening Beijing’s military capabilities, according to a Reuters review of more than 80 Chinese academic papers and patents.

The findings offer a blunt look at how China’s military and security establishment is trying to squeeze value out of U.S. innovation while Washington works to limit Beijing’s access to advanced chips and strategic technology.

At the center of the issue is “model distillation,” a technique in which the outputs of a powerful AI model are used to train smaller, specialized systems.

In plain English, China appears to be taking lessons from the best American systems and using them to build cheaper tools it can run on its own networks.

Reuters said its review included research compiled by the Washington based Jamestown Foundation and shared exclusively with the news agency.

The material showed the technique is being used widely by researchers tied to the People’s Liberation Army and other military institutions.

The papers suggest Chinese defense institutions view U.S. AI models as both a technical shortcut and a way to narrow the gap with American rivals.

That is not exactly shocking to anyone who has watched Beijing treat Western innovation like an all you can copy buffet.


The dispute is not over distillation itself, which is a common practice in the tech industry.

The sharper concern is unauthorized extraction from U.S. models, especially when the resulting capabilities could support surveillance, cyber warfare, targeting, or battlefield decision making.


Russia Shares Intelligence with Iran That Could Enable Tehran to Hit U.S. Forces, Officials Say
Navy Seaman Landon Blackwell monitors surface contacts from the combat information center aboard Arleigh Burke-class guided-missile destroyer USS John S. McCain in the East China Sea, July 15, 2021.

The issue is now a major flashpoint ahead of U.S. and China talks on AI governance and safety. U.S. officials have accused some Chinese entities of using distillation to pull capabilities from American AI models, potentially undermining export controls and violating intellectual property rights.

China has rejected the accusations and accused Washington of AI “hegemonism,” because apparently Beijing believes the real problem is America noticing the pattern. Chinese developers have also pushed back on claims that their advances depend on foreign models.


AI startup Moonshot recently denied allegations by the Trump administration that its Kimi K3 model was built using distillation. The company claimed the model was driven by proprietary innovations.

China, Iran and Russia Hold Joint Naval Drills in Mideast

Sunny Cheung, a Jamestown fellow who analyzed more than 60 of the papers, said Chinese military scientists are systematically capturing the reasoning steps of Western models. He said they are adapting those capabilities for surveillance, cyber warfare, and tactical decision making.

“Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder,” said Cheung.

“These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally.”

Reuters verified the academic literature and identified about two dozen additional military linked case studies.

One paper published last year by researchers in PLA Unit 96941, a military intelligence and cyber warfare unit in Beijing, described using OpenAI’s GPT 3.5 to process sensitive military source code.

China to Develop Robot Dog Drones with Thermobaric Weapons for 'Comprehensive Destruction'

The researchers said outside models were not suitable for classified information. Their workaround was to use GPT 3.5 to summarize software code, then train a domestic model on those summaries so it could operate inside Chinese military networks.

The White House, War Department, China’s foreign ministry, the PLA, and OpenAI did not respond to Reuters requests for comment.

The review found Chinese researchers using distillation for everything from content monitoring to military deployment.

At the North University of China, which has close ties to the weapons industry, researchers used Anthropic’s Claude 3 Haiku to generate synthetic training data for a text classification model focused on social media monitoring and content moderation.

Anthropic said it does not provide commercial access to Claude in China or to Beijing controlled firms. The company said it uses monitoring systems to detect policy violations and warned that distilled models may lose the original safety safeguards.

A 2024 paper from the PLA’s National University of Defense Technology described using distillation to shrink an image processing model for use on unmanned aerial vehicles.

That would allow drones to analyze live video and support navigation and targeting decisions even when communications are cut.

China's Shipbuilding Dominance a National Security Risk for US: Report

Researchers at China’s Academy of Military Sciences also used distillation to run a target recognition model on tactical hardware during simulated maritime operations.

Those exercises involved drones, ships, and unmanned submarines, according to a study published earlier this year.

China has embraced distillation as it tries to compete with the United States in frontier AI while dealing with Washington’s export controls on high end chips.

Central and local governments have promoted model lightweighting and edge computing for drones, satellites, and other platforms with limited processing power.

Still, experts warn that distilled models have real limits.

Chinese military researchers are also studying distillation as a security threat, including “data-free distillation,” a method of reverse engineering model capabilities without direct access to core parameters.

Trevor Koverko, co founder of AI data company Sapien, said distilled models remain less capable than their teacher systems.

“It is best understood as transferring selected capabilities into a cheaper, locally controlled system, not achieving independence from frontier AI.”



Leave a Comment

Your email address will not be published. Required fields are marked *




Scroll to Top

Sign Up for Our Daily Newsletter

Receive The Populist Time’s hard-hitting coverage, direct to your inbox!