Research · Blogs & Independent Thinkers

Back to sweep

Research sweep · deep · 2025 – 2026

Security Research into Chinese Open-Weight Models

Independent security research into Chinese open-weight models (DeepSeek R1 and V3, Alibaba Qwen, Moonshot Kimi K2, Zhipu GLM, MiniMax, Baidu Ernie) from February 2025 to August 2026: who is testing them, what red-teaming and provenance methods they use, which results survive independent replication, and how regulated, defence and military buyers are assuring models whose training data and training objectives are never disclosed

  • GPT-5.6-sol
  • financial
  • frontier
  • academic
  • blogs
  • tech

Synthesised 2026-08-03

Narrative

Independent technical bloggers were first movers on DeepSeek scrutiny. Simon Willison tested DeepSeek-R1 directly within days of release, probing prompt-injection resistance and noting that a chain-of-thought hack (intercepting the closing think-tag) could force the model to extend reasoning indefinitely, alongside his broader point that language models are "inherently gullible" as a technology, not a China-specific flaw. HiddenLayer's "DeepSh*t" post used its proprietary automated red-teaming and ShadowGenes model-genealogy tooling and manual assessment to conclude that R1 was vulnerable to jailbreak techniques, prompt injections, glitch tokens, and exploitation of its control tokens, making it less secure than other modern LLMs


Sources

ID Title Outlet Date Significance
b1 The Real Security Concerns of DeepSeek AI and the Open Source Debate teamivity.substack.com February 10, 2025 Retrieved by this lane's web search.
b2 Large Language Model (LLM) for Software Security: Code Analysis, Malware Analysis, Reverse Engineering arxiv.org Retrieved by this lane's web search.
b3 DeepSeek Security, Privacy, and Governance: Hidden Risks in Open-Source AI - Theori BLOG theori.io February 6, 2025 Retrieved by this lane's web search.
b4 Are Chinese open-weights Models a Hidden Security Risk? gradientflow.substack.com May 8, 2025 Retrieved by this lane's web search.
b5 Stealers and backdoors are spreading under the guise of a DeepSeek client | Securelist securelist.com September 11, 2025 Retrieved by this lane's web search.
b6 Comprehensive Analysis of Transparency and Accessibility of ChatGPT, DeepSeek, And other SoTA Large Language Models arxiv.org Retrieved by this lane's web search.
b7 Estimating Worst-Case Frontier Risks of Open-Weight LLMs arxiv.org Retrieved by this lane's web search.
b8 Open-Weight AI and the Case for Global Digital Communism ddgeopolitics.substack.com 2 days ago Retrieved by this lane's web search.
b9 The DeepSeek-R1 family of reasoning models simonw.substack.com January 20, 2025 Retrieved by this lane's web search.
b10 r1.py script to run R1 with a min-thinking-tokens parameter simonwillison.net January 22, 2025 Retrieved by this lane's web search.
b11 DeepSeek-R1 and exploring DeepSeek-R1-Distill-Llama-8B simonwillison.net January 20, 2025 Retrieved by this lane's web search.
b12 Simon Willison on X: "Here's a fun prompt injection challenge: can you get DeepSeek R1 running on https://t.co/qVzuA4QkWV to leak its system prompt? I'm finding it's pretty robust at reasoning about how it shouldn't do that" / X x.com Retrieved by this lane's web search.
b13 Simon Willison on deepseek simonwillison.net Retrieved by this lane's web search.
b14 Simon Willison’s Weblog simonwillison.net 1 day ago Retrieved by this lane's web search.
b15 Simon Willison: "DeepSeek released a new OCR model - I got it work…" - Mastodon fedi.simonwillison.net October 20, 2025 Retrieved by this lane's web search.
b16 deepseek-r1-what-security-teams-need-to-know | Blog | Endor Labs endorlabs.com August 25, 2025 Retrieved by this lane's web search.
b17 Illusory Safety: Redteaming DeepSeek R1 and the Strongest Fine-Tunable Models of OpenAI, Anthropic, and Google - LessWrong lesswrong.com February 7, 2025 Retrieved by this lane's web search.
b18 Illusory Safety: Redteaming DeepSeek R1 and the Strongest Fine-Tunable Models of OpenAI, Anthropic, and Google - LessWrong 2.0 viewer greaterwrong.com Retrieved by this lane's web search.
b19 Illusory Safety: Redteaming DeepSeek R1 and the ... alignmentforum.org February 6, 2025 Retrieved by this lane's web search.
b20 Illusory Safety: Redteaming DeepSeek R1 and the Strongest Fine-Tunable Models of OpenAI, Anthropic, and Google | FAR.AI far.ai 3 weeks ago Retrieved by this lane's web search.
b21 Punching Above Its Weight: A Head-to-Head Comparison of Deepseek-R1 and OpenAI-o1 on Pancreatic Adenocarcinoma-Related Questions ncbi.nlm.nih.gov Retrieved by this lane's web search.
b22 DeepSeek-R1 Thoughtology: Let's think about LLM Reasoning arxiv.org Retrieved by this lane's web search.
b23 DeepSeek’s release of an open-weight frontier AI model iiss.org Retrieved by this lane's web search.
b24 Beyond DeepSeek: China's Diverse Open-Weight AI ... hai.stanford.edu Retrieved by this lane's web search.
b25 How Chinese Open-Weight AI Labs Overtook US Proprietary Models in Twelve Months - SoftwareSeni softwareseni.com April 26, 2026 Retrieved by this lane's web search.

We use analytics cookies to understand site usage and improve the service. We do not use marketing cookies.