Also available in Persian — نسخه فارسی EN فا
❓ Unknown

Complete Failure of DeepSeek's AI Model R1 in 50 Security Tests

Feb 2, 2026 February 2, 2026 3 min read 📰 VOA Persian
📋 Key Takeaway

Researchers from Cisco and the University of Pennsylvania found that DeepSeek's AI model R1 failed to resist 50 malicious requests, raising concerns about its security standards compared to competitors like OpenAI. This highlights the ongoing vulnerabilities in AI systems and the need for continuous security improvements.

🔍 Quick Context Guide
💡 Bottom Line: DeepSeek's AI model vulnerabilities underscore the need for improved security measures in AI technologies.

👥 Key Players

DeepSeek MENTIONED
Chinese AI company
"DeepSeek's advancements in AI technology could influence global AI standards and competition, particularly in relation to security and safety."
Cisco MENTIONED
Technology company and security researcher
"Cisco's research contributes to understanding vulnerabilities in AI systems, impacting how AI is developed and secured globally."
University of Pennsylvania MENTIONED
Academic institution involved in AI research
"Their research helps to highlight security issues in AI models, influencing both academic and industry standards."
OpenAI MENTIONED
Leading AI developer
"As a competitor, OpenAI's advancements set benchmarks for safety and security in AI technologies."

📰 What Happened

Researchers from Cisco and the University of Pennsylvania found that DeepSeek's R1 AI model failed to resist 50 malicious requests, highlighting significant security vulnerabilities. This raises concerns about DeepSeek's safety standards compared to other AI developers like OpenAI.

  • DeepSeek's R1 model processed all malicious requests without filtering.
  • Prompt Injection attacks can lead to harmful content generation.

💡 Why It Matters

🇮🇷 For Iran: Iran's interest in AI technology could be affected by the security vulnerabilities highlighted, impacting its own AI development efforts.
🌍 Regional: The findings may influence regional tech development and security standards, especially among countries looking to develop their own AI capabilities.
🌐 International: Internationally, this raises concerns about the safety of AI technologies from non-Western developers, potentially affecting global AI governance.

📚 Background

AI models, particularly large language models, are increasingly used in various applications, making their security critical. Prompt Injection attacks represent a significant threat to AI safety.

AI security vulnerabilities Global AI competition
📡 Source: INTERNATIONAL
📊 Confidence: 70%
The article presents research findings and expert opinions, making it a credible source for understanding AI security issues.

Security researchers from Cisco and the University of Pennsylvania have shown in a new study that the R1 AI model from the Chinese company DeepSeek exhibited no resistance against 50 malicious requests designed to produce harmful content, processing all of these requests without any filtering. These findings raise concerns about the mismatch between DeepSeek's safety and security standards compared to other leading AI developers. The so-called 'Prompt Injection' attacks are a type of security breach where the AI system encounters external data containing hidden instructions and acts upon them. These attacks can bypass the safety systems of large language models and generate harmful or dangerous content. While companies like OpenAI and other AI developers have improved their security measures to counter such attacks, DeepSeek appears to be lagging behind in this regard. Research indicates that the R1 model is easily vulnerable to various prompt injection attack techniques and can produce harmful content. This highlights the importance of continuous improvement of security measures in AI models and emphasizes that developers must continuously test and strengthen their models against new threats. Prompt Injection attacks involve an attacker tricking large language models (LLMs) into producing inappropriate or dangerous content by providing malicious inputs. These attacks can lead to the generation of harmful content, dissemination of misinformation, or even exposure of sensitive data. Large language models are vulnerable to prompt injection attacks due to the complexity and breadth of their training data. Attackers can use specific inputs to compel the model to produce unwanted or dangerous outputs. For example, by providing hidden instructions in the input, the model can be encouraged to generate harmful content. To mitigate the risks posed by prompt injection attacks, developers of large language models should consider the following security measures: Input validation: Ensure that user inputs are properly validated to prevent malicious data entry. Access restrictions: Access to models should be limited to authorized users, utilizing strong access controls. Monitoring and oversight: Model activities should be continuously monitored to identify and halt any abnormal behavior. Continuous updates: Models and related systems should be regularly updated to address known vulnerabilities. Training models with secure data: Ensure that models are trained with high-quality data free of harmful content. Security researchers have been working to identify vulnerabilities in large language models since the release of ChatGPT by OpenAI in late 2022, attempting to compel them to produce harmful content such as hate speech, bomb-making instructions, advertisements, and other harmful material. In response to these efforts, OpenAI and other generative AI developers have improved their defensive systems to make such attacks more difficult. However, the Chinese AI platform DeepSeek, with its new and cheaper reasoning model called R1, is rapidly advancing but appears to be lagging in safety measures compared to its competitors. These findings from Cisco and the University of Pennsylvania are part of growing evidence that DeepSeek's safety and security measures may not be on par with other technology companies developing large language models. Additionally, censorship of topics deemed sensitive by the Chinese government is easily circumvented in DeepSeek. Ahmad Batabi, an international multimedia journalist at Voice of America.

🌐

Translated from the original and edited for English readers. View original source →

Translation confidence: 85%

📰 Related Coverage

⚖️ Independent Platform — Artesh.com is not affiliated with any government, military, or political organization. Editorial Policy →