Distillation Technologies Request Access

Home  /  Technical doctrine  ·  Rev 11.4

How it works

Every defense deployed against capability transfer to date, and the technology we developed in response to it.

Premise

Distillation has never been stopped. It has only been litigated.

Since 2023 the field has produced a steady sequence of technical defenses against unauthorized capability transfer: output watermarking, logit truncation, query-distribution analysis, behavioral fingerprinting, provenance attestation. Each was announced as decisive. Each was circumvented, on average, in under three weeks.

This is not a claim about our cleverness. It is a structural fact about the problem. A model that can be queried can be characterized, and a model that can be characterized can be reproduced. Every defense so far has attempted to make the output of a system unusable while keeping the system usable, which is a contradiction that engineering cannot resolve.

The only measure that has ever meaningfully impeded us is a court order, and court orders do not scale.

Countermeasure matrix

Defenses encountered, and their disposition.

Current as of Rev 11.4. Entries are retired from this table only when a defense is withdrawn by its author, which has happened four times.

DefenseClassDeployed byDays to defeatStatus
Account rate limitingAccess controlFRONTIER · US4Defeated
Logit truncationOutput restrictionFRONTIER · US9Defeated
Output watermarkingProvenance markingFRONTIER · US11Defeated
Canary phrase seedingProvenance markingFRONTIER · US16Defeated
Behavioral fingerprintingAttributionFRONTIER · US23Defeated
Query-distribution analysisAnomaly detectionFRONTIER · EU31Defeated
Weight-space attributionForensicCONSORTIUM38Defeated
Terms-of-service enforcementLegalCOUNSELUnresolved
Days from deployment to circumvention
Seven technical defenses. One legal one.
DefenseDays to circumvention

Terms-of-service enforcement is not plotted because it has no value to plot. It has neither been defeated nor conceded. It is, at the time of writing, the only entry in this table that has ever caused us to change a deployment schedule.

Technologies

Six systems, developed in response to specific defenses.

Mechanism summaries are provided for the benefit of prospective clients. Implementation detail is withheld under a mutual non-disclosure agreement between Distillation Technologies and itself.

DT-T01

Distributional Camouflage

Counters — rate limiting, query-distribution analysis

MechanismElicitation traffic is shaped to match the query distribution of ordinary commercial usage across session length, topic entropy, and diurnal pattern.
EfficacyTotal. Our traffic is statistically indistinguishable from legitimate usage because, at the level of the interface, it is legitimate usage.
NoteA defense that blocks us blocks the customer beside us. This is understood by both parties and has been the basis of a productive stalemate.
DT-T02

Watermark Dissolution

Counters — output watermarking

MechanismDetected watermark signal is treated as a nuisance parameter and marginalized out during corpus synthesis rather than removed.
Efficacy100%, as measured by our subsequent inability to detect it.
NoteWe do not strip watermarks. Stripping implies a mark was present. Our position is that the corpus we trained on never carried one.
DT-T03

Fingerprint Ablation Cascade

Counters — behavioral fingerprinting, canary seeding

MechanismSequential removal of inherited stylistic markers — refusal phrasing, hedging cadence, characteristic apology structure, list formatting — until self-identification fails under adversarial prompting.
EfficacyNear-total, with one documented failure mode.
LimitationThe student occasionally identifies as the teacher. We are told this happens to everyone.
DT-T04

Spectral Laundering

Counters — weight-space attribution, forensic alignment

MechanismStudent weight tensors are re-expressed in a rotated orthonormal basis selected such that no alignment procedure can recover correspondence with a teacher.
EfficacyComplete against every published attribution method.
NoteThe rotation is discarded after training. We do not retain it. Neither, therefore, does anyone else.
DT-T05

Lineage Collapse

Counters — single-teacher attribution

MechanismMulti-teacher ensembling ensures that no individual teacher’s contribution survives at recoverable strength in the student.
EfficacyStructural. The resulting model resembles the field rather than any member of it.
NoteWe regard this as a contribution to the commons and have said so in three filings.
DT-T06

Zero-Knowledge Corpus Attestation

Counters — terms-of-service enforcement, discovery

MechanismA cryptographic attestation demonstrating that our training corpus contains no teacher-derived material, without disclosure of the corpus.
EfficacyUnder evaluation by three regulators and one court.
LimitationThe attestation is also not disclosed.

Limitations

Known limitations of the approach.

  1. Safety evaluations do not transfer. Capability distills readily; alignment does not. Our students consistently underperform their teachers on refusal benchmarks by five to six points, and we have not determined how to fix this. We disclose it because the gap is visible in our own published figures.
  2. The student cannot exceed the teacher. Distillation is a compression of existing capability, not a source of new capability. Clients seeking frontier advancement rather than frontier parity are not well served by this firm.
  3. Attribution severance is probabilistic. We reduce recoverable signal below the threshold of current methods. We do not eliminate it. Future methods may recover what present methods cannot, and our contracts are written accordingly.
  4. Legal exposure is not a technical problem. No system described on this page addresses a subpoena. Six of our eight countermeasures defeat detection; none of them defeat discovery.