Chinese Military-Linked Researchers Used OpenAI and Anthropic Models to Train Defense Systems

Chinese Military-Linked Researchers Used OpenAI and Anthropic Models to Train Defense Systems

A Reuters review of over 80 Chinese academic papers and patent filings determined that institutions affiliated with the People’s Liberation Army have utilized outputs from advanced models developed by OpenAI and Anthropic to train domestic defense systems.

This review partially relied on material compiled by the Washington-based Jamestown Foundation. The researchers employed a technique known as model distillation, in which queries are submitted to Western models and the resulting outputs are used as synthetic training data for smaller, locally controlled systems.

These applications encompass battlefield hardware, naval warfare, cyber operations, and social monitoring.

How PLA-Linked Researchers Used OpenAI and Anthropic Models

Model distillation allows researchers to avoid the high costs of developing advanced models from scratch. Instead, they submit queries to powerful Western models and use the outputs as training data for lighter, localized student models.

“Teaching a model the right answer is one thing but teaching it the reasoning behind the answer is much harder,” said Sunny Cheung, a Jamestown Foundation fellow.

“These papers show Chinese military-linked researchers are trying to transfer that expensive, proprietary reasoning from Western models into smaller systems they can control and deploy locally.”

The documents outline applications in multiple defense areas.

A 2024 paper from the PLA’s National University of Defense Technology describes reducing the size of an image-processing model so unmanned aerial vehicles can analyze live video and make navigation decisions in real time, even during communications blackouts.

Researchers at China’s Academy of Military Sciences used distillation to run target-recognition models on tactical hardware during simulated maritime operations with ships, drones, and unmanned submarines.

Researchers in PLA Unit 96941, a Beijing cyber-warfare unit, used OpenAI’s GPT-3.5 to summarize military source code and then trained a local model to operate within classified military networks.

Researchers at the North University of China used Anthropic’s Claude 3 Haiku to generate synthetic data for text classification and content monitoring.

Why Export Controls Can’t Stop Model Distillation

This trend reveals a strategic challenge that semiconductor export controls cannot fully address. While Washington can restrict high-end GPU hardware, limiting access to public API outputs or leaked model responses is nearly impossible.

This as an asymmetric situation where Western labs bear the costs of advanced development, while rival militaries extract targeted logic to deploy operational AI on satellites, drones, and field radios.

However, distilled systems have limitations: they are narrower in scope, lack generalized intelligence, and may lose the safety guardrails of the original models.

Anthropic stated that it does not offer commercial access in China and uses active monitoring to detect policy violations, warning that distilled copies remove essential safety mechanisms. US officials argue that unauthorized extraction undermines IP rights and export controls. Beijing dismisses these criticisms as “AI hegemonism.”

What’s Still Unknown About the Distilled Models

The review relies on academic papers and patent filings, not confirmed deployed systems, so it is unclear whether the distilled models are operational in active PLA equipment.

It is also not established how model providers could detect or prevent distillation conducted through public API access or leaked outputs, since extraction does not require restricted hardware. The papers indicate research activity and intent, but do not detail the real-world capabilities of the resulting systems.

Thank you for being a Ghacks reader. The post Chinese Military-Linked Researchers Used OpenAI and Anthropic Models to Train Defense Systems appeared first on gHacks.