Chinese military used OpenAI, Anthropic AI outputs to train their defence systems: Report

Spread the love


Chinese military used OpenAI, Anthropic AI outputs to train their defence systems: Report

Chinese military researchers have used outputs from leading US artificial intelligence models developed by OpenAI and Anthropic to train domestic AI systems designed to advance China’s defence capabilities, according to a Reuters review of more than 80 Chinese academic papers and patents.The previously unreported findings, based on research reviewed by Reuters and material compiled by the Washington-based Jamestown Foundation, offer a rare look into how Chinese military and security-linked institutions are using advanced US AI models as a shortcut to develop specialised domestic systems despite Washington’s efforts to restrict Beijing’s access to cutting-edge technologies, including advanced semiconductor chips.According to Reuters, the documents reveal widespread use of model distillation, a technique in which outputs generated by a powerful AI model are used to train smaller, specialised models capable of running locally without the vast computing resources required to build frontier AI systems from scratch.

PLA-linked institutions increasingly using model distillation

Reuters’ review, which included Jamestown Foundation research shared exclusively with the news agency, found that model distillation is being widely adopted by researchers affiliated with the People’s Liberation Army (PLA) and other Chinese military institutions.The papers suggest Chinese defence researchers view leading US AI models both as a valuable source of technical expertise and as a means of narrowing the technological gap with American rivals.The dispute centres not on the practice of distillation itself, which is widely used across the AI industry, but on allegations of unauthorised extraction of proprietary model capabilities.The issue has become a major point of contention ahead of US-China discussions on AI governance and safety. US officials have accused some Chinese organisations of using distillation to extract capabilities from American AI systems, arguing the practice could undermine export controls and violate intellectual property rights.China has rejected those accusations, saying Washington is pursuing AI “hegemonism” while maintaining that American companies have also employed similar techniques.Chinese AI startup Moonshot also denied allegations made by the Trump administration last week that its Kimi K3 model relied on distillation, saying the system was built using proprietary innovations.

Researchers adapting Western AI reasoning for military use

Sunny Cheung, a Jamestown Foundation fellow who analysed more than 60 of the papers reviewed by Reuters, said Chinese military researchers are attempting to capture not only AI-generated answers but also the reasoning processes behind them.“Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder,” said Cheung.“These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally.”Reuters independently verified the academic literature and identified an additional two dozen military-linked case studies.One paper published last year by researchers from PLA Unit 96941, a Beijing-based military intelligence and cyber warfare unit, described using OpenAI’s GPT-3.5 to process sensitive military software code.According to the paper, researchers considered third-party AI models unsuitable for handling classified information directly. Instead, they used GPT-3.5 to summarise software code before training a domestic AI model on those summaries, allowing the final system to operate entirely within Chinese military networks.Reuters said the White House, the Pentagon, China’s foreign ministry, the PLA and OpenAI did not respond to requests for comment.

AI models used for surveillance, drones and battlefield operations

Reuters and the Jamestown Foundation found Chinese researchers employing model distillation across a broad range of civilian and military applications.At the North University of China, which has close ties to the country’s defence industry, researchers reportedly used Anthropic’s Claude 3 Haiku to generate synthetic training data for AI systems designed for social media monitoring and content moderation.Anthropic told Reuters it does not provide commercial access to Claude in China or to Beijing-controlled firms and uses monitoring systems to detect violations of its policies.The company also warned that distilled models may lose the original system’s safety protections, potentially allowing sensitive capabilities to be transferred to models beyond its control.Another paper published in 2024 by the PLA’s National University of Defense Technology described using model distillation to shrink an image-processing model for deployment on unmanned aerial vehicles, enabling drones to analyse live video while supporting navigation and targeting decisions even when communications are disrupted.Separately, researchers at China’s Academy of Military Sciences used distillation to run a target-recognition model on tactical hardware during simulated maritime operations involving drones, naval vessels and unmanned submarines, according to a study published earlier this year.

Distillation helps overcome computing constraints

Reuters reported that China has increasingly embraced model distillation as it seeks to compete with the United States in advanced AI while facing restrictions on access to high-end computing hardware due to US export controls.Central and local governments have promoted model lightweighting and edge computing, directing subsidies and research funding towards technologies that allow AI systems to operate on drones, satellites and other devices with limited processing power.However, experts cited by Reuters cautioned that distillation has significant technical limitations.As Chinese AI systems narrow the performance gap with their American counterparts, military researchers are also examining distillation as a potential security vulnerability.A paper published in January by researchers at the Army Engineering University examined the threat posed by “data-free distillation”, a method that can reverse engineer an AI model’s capabilities without requiring direct access to its internal parameters. The researchers proposed defence mechanisms designed to conceal logical information exposed through publicly available model outputs.Trevor Koverko, co-founder of AI data company Sapien, said distilled models still remain less capable than the frontier systems they are trained from.“It is best understood as transferring selected capabilities into a cheaper, locally controlled system, not achieving independence from frontier AI.”

Growing scrutiny over AI capability extraction

The Reuters findings come weeks after Anthropic accused Chinese technology giant Alibaba of conducting what it described as the largest known illicit extraction campaign against its Claude AI models.According to a Reuters report published on June 24, Anthropic alleged operators affiliated with Alibaba and its AI division Qwen generated more than 28.8 million exchanges with Claude between April 22 and June 5 through nearly 25,000 fraudulent accounts as part of a large-scale distillation campaign.Anthropic said the activity was intended to accelerate China’s development of advanced AI capabilities and warned that such attacks threaten American technological leadership.Alibaba did not immediately respond to Reuters’ request for comment and has previously denied allegations linking it to China’s military. The company is also challenging its inclusion on the Pentagon’s list of Chinese military companies.The latest Reuters investigation suggests that while the debate over AI distillation has largely focused on commercial competition and intellectual property, the technique is also playing an increasingly important role in China’s efforts to develop military AI systems for intelligence, surveillance and battlefield operations.



Source link

Leave a Reply

Your email address will not be published. Required fields are marked *