Research · Tech Industry & Practitioner

Back to sweep

Research sweep · deep · 2025 – 2026

Security Research into Chinese Open-Weight Models

Independent security research into Chinese open-weight models (DeepSeek R1 and V3, Alibaba Qwen, Moonshot Kimi K2, Zhipu GLM, MiniMax, Baidu Ernie) from February 2025 to August 2026: who is testing them, what red-teaming and provenance methods they use, which results survive independent replication, and how regulated, defence and military buyers are assuring models whose training data and training objectives are never disclosed

  • GPT-5.6-sol
  • financial
  • frontier
  • academic
  • blogs
  • tech

Synthesised 2026-08-03

Narrative

Independent testing of Chinese open-weight models split into two waves. In the week after DeepSeek R1's January 2025 release, security vendors raced to publish jailbreak results: KELA's AI Red Team reported it could jailbreak R1 across a wide range of scenarios, including ransomware and weapons content, using a mix of outdated and novel techniques. Qualys TotalAI ran an 8B distilled variant through 885 attacks across 18 jailbreak types and found the model failed 58% of these attempts, demonstrating significant susceptibility to adversarial manipulation


Sources

ID Title Outlet Date Significance
p1 DeepSeek R1 Exposed: Security Flaws in China’s AI Model | KELA Cyber kelacyber.com January 27, 2025 Retrieved by this lane's web search.
p2 DeepSeek’s Flagship AI Model Under Fire for Security Vulnerabilities - Infosecurity Magazine infosecurity-magazine.com March 30, 2026 Retrieved by this lane's web search.
p3 DeepSeek Robustness Against Semantic-Character Dual-Space Mutated Prompt Injection arxiv.org Retrieved by this lane's web search.
p4 Token-Efficient Prompt Injection Attack: Provoking Cessation in LLM Reasoning via Adaptive Token Compression arxiv.org Retrieved by this lane's web search.
p5 The DeepSeek Jailbreaking Concerns Highlight The Importance of Red Teaming zwillgen.com March 18, 2025 Retrieved by this lane's web search.
p6 Death by a Thousand Prompts: Open Model Vulnerability Analysis - Cisco Blogs blogs.cisco.com November 14, 2025 Retrieved by this lane's web search.
p7 DeepSeek Jailbreak: How Hackers Are Exploiting AI Systems tech-now.io Retrieved by this lane's web search.
p8 DeepSeek's AI Model Proves Easy To Jailbreak - And Worse remunerationlabs.substack.com Retrieved by this lane's web search.
p9 The Best Open Source LLM for Cybersecurity & Threat Analysis in 2026 siliconflow.com Retrieved by this lane's web search.
p10 Kimi K2.6 vs GLM 5.1 vs Qwen 3.6 Plus vs MiniMax M2.7: Which Open Source Model Wins for Coding in 2026 - Atlas Cloud Blog atlascloud.ai June 11, 2026 Retrieved by this lane's web search.
p11 Open-Weight LLM Showdown 2026: DeepSeek vs Qwen vs Kimi vs GLM vs Llama wavect.io 1 month ago Retrieved by this lane's web search.
p12 GLM-5.2 vs DeepSeek V4 vs Kimi K2.6: 62% SWE Pro [2026] tech-insider.org 1 month ago Retrieved by this lane's web search.
p13 Chinese AI Models Compared: DeepSeek, Qwen, GLM, Kimi (2026) | GEO Toolbox geotoolbox.ai 2 weeks ago Retrieved by this lane's web search.
p14 Best Chinese AI Models 2026: Kimi K3, DeepSeek, Qwen layer3labs.io 2 weeks ago Retrieved by this lane's web search.
p15 Modelos chinos open source en 2026: Qwen, GLM ... - Levante levanteapp.com April 29, 2026 Retrieved by this lane's web search.
p16 Chinese AI Firm DeepSeek Triggers a Wide U.S. Policy Response: Wiley wiley.law March 17, 2025 Retrieved by this lane's web search.
p17 State and Federal Governments Move to Ban DeepSeek on Government Devices conference-board.org March 21, 2025 Retrieved by this lane's web search.
p18 Pentagon Moves to Block DeepSeek After Employees Connect to Chinese Servers - Technology Org technology.org February 4, 2025 Retrieved by this lane's web search.
p19 February 10, 2025 governor.ny.gov Retrieved by this lane's web search.
p20 Microsoft Reveals Breakthrough ‘Sleeper Agent’ Detection for Large Language Models | FinancialContent financialcontent.com February 5, 2026 Retrieved by this lane's web search.
p21 Microsoft Reveals Breakthrough 'Sleeper Agent' Detection ... markets.financialcontent.com February 5, 2026 Retrieved by this lane's web search.
p22 From Poisoned to Aware: Fostering Backdoor Self-Awareness in LLMs arxiv.org Retrieved by this lane's web search.
p23 Shared Latent Structures Enable Unified Backdoor Detection and Mitigation in LLMs arxiv.org Retrieved by this lane's web search.
p24 A Systematic Survey of Security Threats and Defenses in LLM-Based AI Agents: A Layered Attack Surface Framework arxiv.org Retrieved by this lane's web search.
p25 Attestation-based verification of SBOM integrity via consumer-side reproducibility - ScienceDirect sciencedirect.com June 28, 2026 Retrieved by this lane's web search.

We use analytics cookies to understand site usage and improve the service. We do not use marketing cookies.