Technology 技术 | Explainer 解读
What Is AI Distillation and Why Is It a Worry
for the Industry?
什么是 AI 蒸馏,它为何让业界感到担忧?
By Lorelei Smillie 作者:洛雷莱·斯⽶利
June 27, 2026 at 2:18 AM GMT+8
Save 保存
Artificial intelligence companies in the US have spent hundreds of billions
of dollars to develop more advanced chatbots, betting they can earn
enough from customers to justify the investment. That approach carries
the risk of being undermined by rivals who build competing AI systems
Anthropic's Claude Code on a laptop computer at Anthropic's headquarters in San
Francisco. Photographer: Jason Henry/Bloomberg
位于旧⾦⼭ Anthropic 总部的笔记本电脑上运⾏着 Anthropic 的 Claude Code。摄影:杰森·亨利/彭
博社
Translate 翻译
0:000:00 / 4:34/ 4:34
若有侵权,请联系删除。公众号:趣享财经
for far less.
美国的⼈⼯智能公司已投⼊数千亿美元开发更先进的聊天机器⼈,押注于能
从客户那⾥获得⾜够的收益,从⽽使这笔投资物有所值。这种做法⾯临的风
险是,可能会被那些以远低于此的成本开发竞争性⼈⼯智能系统的对⼿所削
弱。
Increasingly, US companies are accusing Chinese competitors of using a
technique known as distillation to improperly piggyback on the results
from leading American AI models to produce a rival generation of
chatbots at a fraction of the cost and with far fewer safety guardrails.
越来越多的美国公司指责中国竞争对⼿利⽤⼀种名为“蒸馏”的技术,不正当
地借⽤美国领先⼈⼯智能模型的研究成果,以极低的成本开发出新⼀代竞争
性聊天机器⼈,且其安全防护措施远不如前者完善。
In June, Anthropic PBC said Alibaba Group Holding Ltd. had “illicitly”
used distillation to extract results from its Claude model on an industrial
scale to help the Chinese tech giant produce its own AI system. Similar
accusations have been leveled by Anthropic and OpenAI against other
Chinese AI labs, including DeepSeek and MiniMax. So far, none of the
Chinese companies, including Alibaba, has responded to the accusations.
今年 6 ⽉,Anthropic PBC 称阿⾥巴巴集团控股有限公司曾“⾮法”利⽤蒸馏
技术,以⼯业规模从其 Claude 模型中提取结果,以帮助这家中国科技巨头
开发⾃⼰的 AI 系统。Anthropic 和 OpenAI 还曾对其他中国 AI 实验室(包
括 DeepSeek 和 MiniMax)提出过类似指控。迄今为⽌,包括阿⾥巴巴在内
的中国公司均未对这些指控作出回应。
What is distillation? 什么是蒸馏?
Distillation is a method commonly used by AI labs to train one large
language model using the outputs of another. A developer submits a
series of prompts to a larger, more capable “teacher” model, and its
responses are used to train a smaller “student” model to replicate many
of the teacher’s capabilities.
“蒸馏”是⼈⼯智能实验室常⽤的训练⽅法,即利⽤⼀个⼤型语⾔模型的输出
结果来训练另⼀个⼤型语⾔模型。开发者向⼀个规模更⼤、能⼒更强的“教
师”模型提交⼀系列提⽰,然后利⽤该模型的响应来训练⼀个较⼩的“学⽣”
模型,使其能够复制“教师”模型的许多能⼒。
若有侵权,请联系删除。公众号:趣享财经
The resulting model can perform many of the same functions as the
original but at a fraction of the cost and computing power required to
develop — and run — a comparable system from scratch. Knowledge isn’t
transferred directly from one model to another, but the student model
learns to mimic its teacher’s behavior based on the results of its queries.
⽣成的模型能够执⾏与原始模型相同的许多功能,但其开发和运⾏成本以及
所需计算资源,仅为从头开始开发并运⾏⼀个同等系统所需的⼀⼩部分。知
识并⾮直接从⼀个模型转移到另⼀个模型,⽽是学⽣模型根据其查询结果,
学会模仿教师模型的⾏为。
Distillation is considered acceptable when companies use it on their own
models or when outside developers use it to build non-competing
technologies. Known as authorized distillation, the method allows
companies and researchers to compress large models into smaller, more
efficient ones that are optimized for specific tasks. Derivative models
typically lack the full capabilities of the original model but perform faster
and cost less to develop and operate.
当企业将其应⽤于⾃⾝模型,或外部开发者将其⽤于构建⾮竞争性技术时,
这种“蒸馏”做法被视为可接受的。这种被称为“授权蒸馏”的⽅法,允许企业
和研究⼈员将⼤型模型压缩成更⼩、更⾼效且针对特定任务进⾏优化的模
型。衍⽣模型通常不具备原始模型的全部功能,但运⾏速度更快,且开发和
运营成本更低。
Why is distillation sometimes controversial?
为什么蒸馏有时会引发争议?
Distillation can be used by third parties to duplicate the capabilities of a
proprietary AI model without the permission of the reference model’s
owner. That practice has raised legal, economic and security concerns.
第三⽅可利⽤“蒸馏”技术,在未经参考模型所有者许可的情况下,复制专有
AI 模型的功能。这种做法引发了法律、经济和安全⽅⾯的担忧。
Leading US AI companies say that unauthorized distillation puts their
business at risk. Many Chinese labs including DeepSeek have developed
open-weight models, meaning that parts of the underlying AI system are
publicly available for users to freely download and run on their own
若有侵权,请联系删除。公众号:趣享财经
platforms.
美国领先的⼈⼯智能公司表⽰,未经授权的模型蒸馏⾏为给其业务带来了风
险。包括 DeepSeek 在内的许多中国实验室都开发了开放权重模型,这意味
着底层⼈⼯智能系统的部分组件已向公众开放,⽤户可以⾃由下载并在⾃⼰
的平台上运⾏。
By contrast, the biggest American AI companies have kept their models
proprietary, betting that customers will pay for access to their products so
that they can recoup the hundreds of billions of dollars spent on data
centers and other infrastructure. They argue that if rivals can replicate
their models at a fraction of the cost and offer them cheaply — or for free
— it risks eroding their sales. US officials have estimated that unauthorized
distillation is costing US businesses billions in annual income.
相⽐之下,美国最⼤的⼏家⼈⼯智能公司⼀直将⾃⼰的模型作为专有技术加
以保护,押注于客户会为使⽤其产品付费,从⽽收回在数据中⼼和其他基础
设施上投⼊的数千亿美元。它们认为,如果竞争对⼿能以极低的成本复制其
模型,并以低价——甚⾄免费——提供,就会危及它们的销售额。美国官员估
计,未经授权的模型蒸馏⾏为每年给美国企业造成数⼗亿美元的收⼊损失。
The US AI companies also say there are security risks in unauthorized
distillation. They warn that foreign adversaries could use the technique to
develop AI models stripped of guardrails that stop people using the
platforms for illegal or dangerous purposes, such as creating deadly
pathogens or conducting automated, large-scale computer hacking.
美国⼈⼯智能公司还表⽰,未经授权的“蒸馏”⾏为存在安全风险。它们警告
称,外国对⼿可能会利⽤这⼀技术开发出缺乏安全防护机制的⼈⼯智能模
型,从⽽使⼈们能够利⽤这些平台从事⾮法或危险活动,例如制造致命病原
体或进⾏⾃动化的⼤规模计算机⿊客攻击。
How can companies detect a distillation attack?
企业如何检测蒸馏攻击?
The evidence is often circumstantial, and for now it can be hard to prove
beyond any doubt that a rival’s model was developed through distillation.
证据往往只是间接证据,⽬前很难毫⽆疑问地证明竞争对⼿的模型是通过蒸
馏法开发的。
若有侵权,请联系删除。公众号:趣享财经
Anthropic said in February that three leading AI developers in China had
worked to “illegally extract” results from its models. It said the companies
had generated more than 16 million exchanges using fraudulent accounts,
and it was able to pinpoint them based on information from internet
protocol addresses and metadata. Industry partners had “observed the
same actors and behaviors on their platforms,” it added.
Anthropic 今年 2 ⽉表⽰,中国三家领先的⼈⼯智能开发商曾试图“⾮法提
取”其模型⽣成的结果。该公司称,这些公司利⽤欺诈性账户⽣成超过 1600
万次交互,⽽该公司通过 IP 地址和元数据信息成功锁定了这些公司。该公
司补充道,⾏业合作伙伴“在其平台上也观察到了相同的实施者和⾏为”。
In a letter sent to several US senators and White House officials in June,
Anthropic said the alleged Alibaba distillation effort involved million
exchanges with its Claude chatbot between April and June through almost
25,000 fraudulent accounts, according to people familiar with the
document and a copy seen by Bloomberg News.
据熟悉该⽂件的⼈⼠及彭博新闻社获得的⽂件副本显⽰,Anthropic 在 6 ⽉
致函数名美国参议员和⽩宫官员时称,据称阿⾥巴巴的此次“数据提取”⾏动
涉及 4 ⽉⾄ 6 ⽉期间通过近 万个欺诈账户与其 Claude 聊天机器⼈进⾏
的 2880 万次交互。
Can distillation be prevented?
能否防⽌蒸馏?
Top American AI companies are taking steps to combat what they call
“distillation attacks,” including wider information sharing on on
unauthorized extraction of their models’ output and efforts to block
suspect users from accessing their systems.
美国顶尖的⼈⼯智能公司正在采取措施应对它们所称的“蒸馏攻击”,包括就
其模型输出结果被未经授权提取的情况进⾏更⼴泛的信息共享,以及努⼒阻
⽌可疑⽤户访问其系统。
Lawmakers in Washington and the Trump administration are taking heed
of the Silicon Valley’s concerns. In April, the White House said it would
work with industry to determine how to rein in distillation and hold bad
actors accountable. House Republicans have also called for US sanctions
against Chinese entities that engage in the practice on an industrial scale
若有侵权,请联系删除。公众号:趣享财经
to build rival systems.
华盛顿的⽴法者和特朗普政府正在重视硅⾕的担忧。4 ⽉,⽩宫表⽰将与业
界合作,探讨如何遏制数据提取⾏为,并追究恶意⾏为者的责任。众议院共
和党⼈还呼吁美国对那些以⼯业规模从事此类⾏为、旨在构建竞争性系统中
国实体实施制裁。
Terms of Service 服务条款
Manage Cookies 管理 Cookie
Trademarks Privacy Policy
商标 隐私政策
Careers Advertise Ad Choices
Help
©2026 Bloomberg . All Rights
Reserved.
职业 ⼴告 ⼴告选择 帮助 ©2026 彭博有限合
伙企业。保留所有权利。
若有侵权,请联系删除。公众号:趣享财经
插入页面
插入页面
加入页码
插入页面
插入页面
加入页码