Skip to main content

Envisioning is an emerging technology research institute and advisory.

LinkedInInstagramGitHub

2011 — 2026

research
  • Observatory
  • Newsletter
  • Methodology
  • Origins
  • Vocab
services
  • Signals Session
  • Bespoke Projects
  • Use Cases
  • Readinessfree
  • Signals
  • Free scan↗free
impact
  • ANBIMAFuture of Brazilian Capital Markets
  • IEEECharting the Energy Transition
  • Horizon 2045Future of Human and Planetary Security
  • WKOTechnology Scanning for Austria
solutions
  • Innovation
  • Strategy
  • Consultants
  • Foresight
  • Associations
  • Governments
resources
  • Partners
  • How We Work
  • Data Visualization
  • Multi-Model Method
  • FAQ
  • Security & Privacy
about
  • Manifesto
  • Community
  • Events
  • Support
  • Contact
ResearchServicesSignalsAbout
ResearchServicesSignalsAbout
  1. Home
  2. Vocab
  3. Distillation Attacks

Distillation Attacks

Chinese AI labs illicitly extract capabilities from US frontier models via black-box querying.

Year: 2025Generality: 600Added: May 17, 2026
Back to Vocab

When AI labs in China use repeated queries to American frontier models to generate synthetic data, then use that data to train competing models that replicate the original model's capabilities. Anthropic's May 2026 policy paper described how Chinese labs carry out large-scale distillation attacks to harvest innovations from US AI companies.

The technical mechanism involves querying a target frontier model millions of times across diverse inputs, collecting the outputs, and using that data to fine-tune a separate model. The attacking lab effectively trains its own model to imitate the target's capabilities without ever accessing the target's architecture or weights directly. This is distinct from knowledge distillation, which is a legitimate training technique where a smaller model learns from a larger model's outputs.

These attacks are controversial. US companies view them as a form of intellectual property theft, arguing that the model's outputs represent proprietary innovations. Defenders argue that black-box querying is difficult to prevent since APIs are openly accessible. The practice exploits the fact that frontier models are often accessible via public APIs, making it hard to distinguish legitimate use from systematic capability extraction.

The scale of these attacks is hard to verify independently. Anthropic and other US labs claim they are widespread and systematic, while Chinese labs typically do not publicly discuss them. The ethical and legal status remains contested: querying an open API may be technically legal while still being seen as a violation of terms of service or a form of unfair competition.

Research this in Signals

Scan Distillation Attacks for yourself.

Signals turns a topic into a sourced research record you can inspect and rerun. Your first scan is free, and this one starts with Distillation Attacks already loaded, so edit it or scan as is.