原文標題: Adversarial Distillation of American AI Models
原文連結: 白宮
https://www.whitehouse.gov/wp-content/uploads/2026/04/NSTM-4.pdf
發布時間: 2026/04/23
記者署名:MICHAEL J. KRATSIOS
原文內容:
The United States leads the world in artificial intelligence (AI) technologies.
That lead reflects decades of foundational research, bold entrepreneurial risk-t
aking, and hundreds of billions of dollars in annual private investment. America
n AI leadership drives economic growth, strengthens national security, and advan
ces the frontiers of science, medicine, and human knowledge. The breakthroughs e
merging from American industry raise living standards, expand opportunity, and i
mprove lives around the world. However, the United States government has informa
tion indicating that foreign entities, principally based in China, are engaged i
n deliberate, industrial-scale campaigns to distill U.S. frontier AI systems. Le
veraging tens of thousands of proxy accounts to evade detection and using jailbr
eaking techniques to expose proprietary information, these coordinated campaigns
systematically extract capabilities from American AI models, exploiting America
n expertise and innovation. Models developed from surreptitious, unauthorized di
stillation campaigns like this do not replicate the full performance of the orig
inal. They do, however, enable foreign actors to release products that appear to
perform comparably on select benchmarks at a fraction of the cost. These distil
lation campaigns also allow those actors to deliberately strip security protocol
s from the resulting models and undo mechanisms that ensure those AI models are
ideologically neutral and truth-seeking. The United States is committed to the f
ree and fair development of AI technologies across a competitive ecosystem, from
leading frontier models to highly-tuned applied systems, and from open-source f
rameworks to open-weight models. AI distillation, when legitimately used to prod
uce smaller, lighter-weight models from more advanced systems, is a vital part o
f that ecosystem. Industrial distillation activities that aim to systematically
undermine American research and development and access proprietary information,
however, are unacceptable.
美國在人工智慧(AI)技術領域領先全球。這種領先地位反映了數十年來的基礎研究、大膽
的企業家冒險精神,以及每年數千億美元的私人投資。美國在 AI 領域的領導地位推動了經
濟增長,加強了國家安全,並拓展了科學、醫學和人類知識的邊界。美國產業界不斷湧現的
突破性進展,提高了生活水準,擴大了機會,並改善了全世界人民的生活。然而,美國政府
掌握的資訊表明,外國實體(主要位於中國)正參與蓄意且具備工業規模的行動,以「蒸餾
(distill)」美國的尖端 AI 系統。這些協同行動利用數以萬計的代理帳戶來逃避偵測,
並使用越獄(jailbreaking)技術來暴露專有資訊,系統性地從美國 AI 模型中提取能力,
藉此剝削美國的專業知識與創新。透過這種秘密、未經授權的蒸餾行動所開發出來的模型,
無法複製原始模型的完整效能。然而,它們確實讓外國行為者能以極低的成本,發布在特定
基準測試上表現看似相當的產品。這些蒸餾行動還允許這些行為者故意從生成的模型中剝離
安全協議,並破壞確保這些 AI 模型保持意識形態中立和追求真相的機制。美國致力於在競
爭激烈的生態系統中自由、公平地發展 AI 技術,從領先的尖端模型到高度微調的應用系統
,從開源框架到開放權重模型均包含在內。當合法用於從更先進的系統生成更小、更輕量的
模型時,AI 蒸餾是該生態系統中至關重要的一部分。然而,旨在系統性破壞美國研發並獲
取專有資訊的工業級蒸餾活動,是不可接受的。
To address this threat, the Trump Administration will:
1.Share information with U.S. AI companies concerning attempts by foreign actors
to conduct unauthorized, industrial-scale distillation, including the tactics e
mployed and actors involved.
2.Enable the private sector to better coordinate against such attacks.
3.Work together with private industry to develop best practices to identify, mit
igate, and remediate industrial-scale distillation activities and build strong d
efenses against such activities.
4.Explore a range of measures to hold foreign actors accountable for industrial-
scale distillation campaigns.
There is nothing innovative about systematically extracting and copying the inno
vations of American industry, and there is nothing open about supposedly open mo
dels that are derived from acts of malicious exploitation. As methods to detect
and mitigate industrial-scale distillation grow more sophisticated, foreign enti
ties who build their AI capabilities on such fragile foundations should have lit
tle confidence in the integrity and reliability of the models they produce. Cons
istent with America’s AI Action Plan, the United States will continue to foster
a vibrant open-source ecosystem built on firm foundations, support American ind
ustry in making frontier AI broadly accessible to users worldwide, and safeguard
the free and fair market competition that enables the broad and beneficial diff
usion of these technologies.
為了應對這一威脅,川普政府將:
1.與美國 AI 公司分享有關外國行為者企圖進行未經授權之工業規模蒸餾的資訊,包含其使
用的戰術與涉及的行為者。
2.促使私營部門更好地協調以對抗此類攻擊。
3.與私營產業界合作,制定最佳實踐做法以識別、減輕及補救工業規模的蒸餾活動,並建立
強大的防禦機制以抵禦此類活動。
4.探索一系列措施,就工業規模蒸餾行動向外國行為者追究責任。
系統性地提取和複製美國工業界的創新,這其中沒有任何創新可言;源自惡意剝削行為的所
謂開源模型,也毫無開放可言。隨著檢測和減輕工業規模蒸餾的方法變得越來越精密,將其
AI 能力建立在如此脆弱基礎上的外國實體,對其所生產之模型的完整性和可靠性應該毫無
信心。與美國的《AI 行動計畫》保持一致,美國將繼續培育建立在堅實基礎上、充滿活力
的開源生態系統,支持美國產業界使全球用戶能廣泛獲取尖端 AI,並捍衛自由公平的市場
競爭,從而推動這些技術的廣泛且有益的傳播。
心得/評論:
美國政府明確點名中國蒸餾攻擊並將做出反制
同時Deepseek今天發布V4模型,採用華為硬體推理
最近有推出AI模型的中國廠商有小米1810.HK、智譜2513.HK等等
會不會因為美國封鎖而受影響?
--
※ 發信站: 批踢踢實業坊(ptt.cc), 來自: 42.79.45.64 (臺灣)
※ 文章網址: https://webptt.cc/bbs/Stock/M.1777022140.A.294.html

