Distillation attacks involve feeding prompts and responses from a more advanced model into a smaller one, enabling the smaller model to learn to emulate the larger model's capabilities without requiring the same level of training or computing power. Western labs have attempted to detect and prevent the practice, but foreign actors have also been purchasing logs of third-party conversations made using legitimate accounts, making it difficult to stop entirely.
Speculation has linked distillation to Chinese AI advances such as Deepseek in 2025 and Moonshot's Kimi K3 in 2026, which reportedly delivered performance close to frontier U.S. models but far cheaper and faster. Chinese state media, including the People's Daily, have pushed back, arguing that U.S. companies like OpenAI and Anthropic trained their models on illicitly obtained material such as pirated books and scraped web content. The South China Morning Post reported that the U.S. startup Thinking Machines used other models, including Moonshot's Kimi K2.5, to generate early training data for its Inkling model.
The controversy underscores the different approaches taken by U.S. and Chinese AI firms: American labs have largely kept models proprietary, while many Chinese developers release open-weight models. Proponents of open development argue that distillation is a legitimate method for smaller companies and researchers to build capable AI, while critics see it as theft of massive investment.