Abstract:
Kimi K3, a subsidiary of the Chinese AI company Dark Side of the Moon, has recently been involved in the model distillation controversy again. An investigation published by OpenAI revealed that a coordinated extraction campaign targeting the protected inference content of its models was linked to individuals associated with Dark Side of the Moon. Related activities generated approximately 16,000 requests in a single day and involved more than 15,000 users.
OpenAI stated that these operations did not break through its encryption system, invade the database, or directly obtain user historical conversations, but through carefully designed multi-round model interactions, they tried to regenerate the originally hidden reasoning process in a form visible to the requester.
OpenAI called the incident a "coordinated model distillation event." The so-called model distillation refers to using a more capable teacher model to generate a large amount of output, and then using these results to train a smaller or lower-cost student model, so that the latter can learn the behavior patterns and capabilities of the teacher model. Distillation itself is a common technique in the field of machine learning, but if commercial model output is extracted at scale without authorization and used to train competing models, it may violate terms of service and even lead to intellectual property disputes.
According to the investigation results released by OpenAI, related activities first appeared on July 1, 2026, when the number of requests was still relatively low. Then the activity gradually expanded, with obvious peaks on July 24 and 25. In these two days alone, OpenAI detected approximately 16,000 requests using specific extraction patterns from more than 4,000 users.
OpenAI further stated that similar prompt words and operation modes do not only appear among the more than 4,000 users mentioned above, but are distributed among a larger user group consisting of more than 15,000 users. By analyzing the patterns and correlations between these requests, the company determines that they are not completely independent ordinary user behaviors, but belong to an activity with coordinated characteristics.
One key operation is of particular interest. OpenAI said that the relevant personnel first copied the encrypted inference content returned by the model from one conversation, and then asked the model to decrypt and transcribe the hidden content in a separate conversation. In other words, they did not directly crack the encryption mechanism used by OpenAI to protect the reasoning process, but tried to use the model's own capabilities to let the model process another piece of protected content, thereby indirectly recovering the information.
OpenAI emphasized that this activity did not successfully "break encryption", nor did it break through OpenAI's database, nor did it obtain user chat records stored on the server. Its success lies mainly in manipulating the interactions between models so that protected inference information that would not otherwise be directly displayed to the user reappears in another form.
OpenAI finally completely blocked this type of activity around July 28. The company said that during its investigation, it discovered that one of the core clusters of activity was linked to people associated with Dark Side of the Moon. OpenAI said in a public statement that it was able to attribute the core cluster to "individuals associated with Kimi developer Dark Side of the Moon."
Dark Side of the Moon is a Chinese AI company whose Kimi series of models have developed rapidly in recent years. In July 2026, the company released Kimi K3, an open weight model with approximately 2.8 trillion parameters, and positioned it as a new generation model for code programming, complex reasoning and AI agent tasks. Kimi K3 quickly attracted the attention of global AI developers after its release, and its performance was close to the leading closed-source model in the United States in some third-party tests.
This OpenAI investigation has also brought attention to the previous doubts raised by the US government about the source of the Kimi model. Michael Kratzios, director of the White House Office of Science and Technology Policy and chief science and technology adviser, said at the end of July this year that the U.S. government had relevant information and believed that Dark Side of the Moon had used Anthropic's model to distill Kimi K3. Dark Side of the Moon has not acknowledged the accusation.
In addition to the government's statement, other researchers have recently analyzed the training sources of the Kimi K3 model. A study found that just inputting part of the decoded reasoning content of Claude Opus 4.8 into Kimi K3 may significantly change Kimi K3's subsequent thinking process and final answer, making it appear to be an expression closer to Claude's. Based on this, the researchers believe that the difficulty of extracting certain Claude and GPT reasoning content in Kimi K3 is significantly lower than that of other models.
However, these studies do not alone prove that the Kimi K3 as a whole was distilled from other models through unauthorized means. Similar answering methods, reasoning structures, and knowledge expressions appear among large language models, which may also come from various factors such as public data, similar training objectives, reinforcement learning methods, and model architecture. Therefore, the existence of partial behavioral similarities among models does not equate to proven irregularities in the source of their training data.
Kimi K3 itself also contains technology developed by Dark Side of the Moon. The model is designed using architectures such as Kimi Delta Attention and is optimized for large-scale inference tasks. Dark Side of the Moon also reduces inference costs by reducing KV cache and optimizing the memory footprint of each token. These technologies enable Kimi K3 to run on large-scale data center hardware.
What is special about this controversy is that the behavior alleged by OpenAI itself is not simply copying the model answer, but an attempt to actively obtain "protected reasoning" that the model usually does not directly display. As more and more AI companies adopt hidden reasoning or encrypted reasoning mechanisms, this type of information has become an important part of model capability protection. If competing models are able to restore their content through large-scale automated requests, the mechanisms used by model vendors to protect training results and inference capabilities may face new challenges.
OpenAI has taken action against similar model distillation behaviors many times in recent years. The company believes that large-scale automation of invoking business models, collecting their outputs, and using them to train competing models will allow a party with large amounts of computing resources to replicate at a lower cost the capabilities that other models have developed through long-term research and development.
At the same time, this incident also shows that AI model distillation is becoming a sensitive issue in the artificial intelligence competition between China and the United States. The U.S. government has repeatedly warned that Chinese AI companies may use the model output of U.S. companies to accelerate their own model development, while Chinese companies continue to emphasize the importance of independent research and development capabilities and open weight models. Regarding the current public information, OpenAI has confirmed the discovery of large-scale extraction activities and said that its core activity cluster is related to people related to the Dark Side of the Moon. However, this attribution and whether related activities are ultimately used to train Kimi K3 still require more public evidence to prove.
Learn more:
https://openai.com/index/disrupting-a-coordinated-model-distillation-campaign/
Comments