US-China AI war: Warnings and countermeasures over model control


Featured image USChina AI war Warnings and countermeasures over model control

The global race for artificial intelligence is heating up, and with it comes a new and urgent concern for the United States and its AI developers: the shadowy practice of distillation attacks. These sophisticated methods, which involve extracting the intelligence from powerful frontier models, threaten to reshape the competitive landscape and could inadvertently be fueling the development of similar capabilities in rival nations like China and Russia.

Distillation, at its core, is a powerful technique. It allows smaller language models to learn the complex capabilities and nuanced responses of much larger, more advanced systems. By feeding the smaller model prompts and outputs from a superior model, it essentially learns to emulate the higher-level intelligence without needing the massive resources required for traditional training. While this method is a legitimate tool for internal development or creating specialized, lighter models, the worry arises when it is used maliciously to siphon the immense investment and intellectual property of other companies.

The concern is twofold: commercial and geopolitical. Frontier AI labs, including those in the West, have invested hundreds of billions in developing state-of-the-art models. There is a strong argument that using these proprietary models as training material for competitors—or even for unauthorized distillation—is not only ethically questionable but directly undermines the business models of these pioneering companies.

This dynamic is particularly stark when looking at the divide between Western and Chinese AI approaches. While some Chinese AI models, such as those from Deepseek and Kimi, have demonstrated remarkable leaps in capability, the debate centers on the source of that advancement. The focus shifts to whether these gains are driven by open-source innovation or by the potentially illicit extraction of proprietary knowledge.

The situation creates a complex ethical knot. While some argue that openly sharing knowledge benefits the wider field, the ability to simply download the “essence” of a multi-billion dollar development effort raises serious questions about intellectual property and fair compensation. It mirrors the historical debate over whether training on copyrighted material, such as pirated books, constitutes legitimate learning or theft.

Efforts to curb this practice have been underway for months, with major Western AI labs pledging collaborative countermeasures. However, the battle is challenging. Detecting distillation is possible, especially when attackers deliberately engineer prompts designed to expose a model’s internal reasoning traces—a method Anthropic has highlighted as being exploited.

In response, companies like Anthropic have taken defensive steps, including banning accounts and blocking suspicious IP addresses. They have also implemented safeguards, such as making models summarize their reasoning before responding, making it harder for attackers to extract the internal data needed for distillation. Yet, stopping the practice entirely remains elusive, especially since actors can acquire chat logs from legitimate users or exploit gray market “transfer stations” to bypass geographic restrictions.

The path forward involves a mix of technical defense and international diplomacy. While governmental bodies, such as the CISA organization, have released recommendations for AI developers to help detect and prevent these attacks, their universal effectiveness is still being tested. As the world watches the trajectory of AI, the upcoming discussions between leaders, including President Trump and Chinese Premier Xi Jinping, will be keenly focused on establishing a framework that balances technological competition with necessary security and ethical guardrails.

You may also like: