●researcherWorth adopting this framework when evaluating or proposing new distillation defenses to enable apples-to-apples comparisons.
●policyOrganizations citing output perturbation as an IP or regulatory compliance control should reassess — the threat model underspecification means existing defenses may not hold against realistic adversaries.