PLA-Linked Researchers Use Distilled U.S. AI for Surveillance, Drones and Battlefield Tasks

Chinese researchers linked to the People’s Liberation Army (PLA) are reportedly using outputs from leading U.S. artificial intelligence models to train smaller domestic systems for surveillance, drone operations, code analysis, and battlefield tasks.

The activity centers on model distillation, a process in which a smaller “student” AI model is trained on the responses of a more capable “teacher” model.

In ordinary commercial use, distillation can reduce computing costs and make AI tools easier to run on local hardware.

But U.S. officials and AI companies warn that adversarial distillation may involve bypassing provider controls, violating terms of service, and transferring advanced capabilities into systems designed for military or public-security use.

A review of more than 80 Chinese academic papers and patents found that PLA-linked researchers and military institutions had used or examined distillation techniques involving models from U.S. firms, including OpenAI and Anthropic.

The research reportedly covers localized models that can operate inside isolated Chinese networks, rather than relying on foreign cloud services.

PLA Uses Distilled AI

Distillation does not necessarily mean copying a model’s source code or internal weights.

Instead, researchers query a powerful AI system, collect its answers, summaries, code outputs, or reasoning-style responses, and use those results as training material for a separate model.

This approach is attractive to military users because a smaller model can run on specialized hardware with lower power and computing requirements.

It can also be deployed in locations with unreliable internet connectivity or where sensitive data cannot be sent to an external AI provider.

One reported example involved researchers linked to PLA Unit 96941, described as a military intelligence and cyber-warfare unit.

The researchers used OpenAI’s GPT-3.5 to summarize complex military-related source code, then used those summaries to train a domestic system intended to operate within Chinese military networks.

The researchers reportedly viewed third-party cloud models as unsuitable for directly handling classified material. Other papers described distillation for visual and autonomous systems.

A 2024 study associated with the PLA’s National University of Defense Technology reportedly used the technique to shrink an image-processing model for use on uncrewed aerial vehicles.

The goal was to allow drones to process live video and support navigation or targeting decisions in real time, including when communications links are disrupted.

The reported applications also extend beyond traditional combat operations. Research examined social media monitoring, content moderation, facial recognition surveillance, malware detection, cyberattack tracing, and intelligence collection.

These uses raise concerns that distilled frontier capabilities could support both military modernization and state surveillance, jamestown said.

The strongest concern is not distillation itself, but whether it is conducted at scale without authorization and whether safeguards are removed during the process.

The White House’s April 2026 National Security and Technology Memorandum said foreign entities principally based in China were conducting “industrial-scale campaigns” to distill U.S. frontier AI systems.

Cut SOC investigation blind spots and contain threats earlier to reduce response costs and business disruption with ANY.RUN. 

Varshini
Varshini
Varshini is a Cyber Security expert in Threat Analysis, Vulnerability Assessment, and Research. Passionate about staying ahead of emerging Threats and Technologies..

Trending News

Related Stories