Is DeepSeek AI A Major Security Threat?
Kelly Reeves
Mindset, Messaging, & Marketing Expert | I help female entrepreneurs 50+ create a profitable business— and a life they love.
UPDATE: Not less than 24 hours after I posted this article, news broke out that DeepSeek halted new signups amid a "large-scale" cyberattack. I guess I answered my own question.
Chi-NAH has done it again: It created technology that's trumped its U.S. competitors.
Said to have "stunned the AI world," a new AI model out of China is throwing down the performance gauntlet of OpenAI's ChatGPT and Google's Gemini, much to the amazement and maybe even chagrin of Silicon Valley.
The Chinese company DeepSeek says it took only two months and $5.6 million to develop its R1 model, a fraction of what its US rivals have paid in R & D.
While Meta's AI chief asserts in a LinkedIn post that the takeaway "is not the competitive threat but the advantages of open-source over proprietary models," the real threat isn't just competition, it's a potential threat to national security.
The AI models have been used to advance cybercriminal activity, especially in the areas of phishing, ransomware, and Deepfakes.
DeepSeek's open-source AI increases the potential for threat actors to exploit its accessible code to manipulate the model, launch targeted attacks, or inject harmful prompts. Criminals can leverage the transparency of their inner workings to understand and exploit vulnerabilities within the system.
Known Vulnerabilities
As with any new AI kid on the block, there are aresearchers are going to get their hands on it to point out the flaws, and they were successful in finding some significant DeepSeek vulnerabilities.
Prompt injection attacks remain a significant threat as does code manipulation. Because the source code is publicly available, attackers can analyze it to identify potential weaknesses and exploit them to inject malicious prompts or commands into the AI system.?Attackers could take control of a user's interaction with the AI by injecting malicious prompts.?
Its open-source nature allows anyone to access and modify its code, potentially enabling malicious actors to identify and exploit vulnerabilities.?
Other concerns include:
What can you do about it?
According to CyberSRC:
A Dramatic Shift in the AI and Cybersecurity Landscape
It's safe and maybe sad to say, that DeepSeek is “feeding” off the existing models that took countless hours and billions of dollars to build, train, and mature. And, it's not the only one. As we begin to see companies and even individuals come up with their own AI models, take a page from their virtual forefathers, and implement them much faster and cheaper, it looks like the real AI challenge is to keep it from becoming a haven for malicious actors to succeed and a race to the proverbial AI bottom.
DeepSeek also represents the growing concern of AI in cybersecurity—both as a defender and a potential threat. As open-source AI tools become more accessible, the lines begin to blur between defense and offense, making it critical for organizations to strike a balance between innovation and responsibility.
CEO ~BIOSOURCE BOTANICALS ~ PRODUCT DEVELOPMENT ~ CONTENT CREATOR
2 周Yes, I would never download it. Been using AI for a couple years. Also would not download TikTok
Mindset, Messaging, & Marketing Expert | I help female entrepreneurs 50+ create a profitable business— and a life they love.
1 个月BREAKING NEWS - As I warned... https://www.cnbc.com/2025/01/27/deepseek-hit-with-large-scale-cyberattack-says-its-limiting-registrations.html
CEO and Founder | B2B Growth Services for SaaS, Critical Infrastructure, AI, and other segments | Start Up Acceleration | Outsourced SaaS Sales Services| MBA
1 个月Very interesting and insightful Kelly. Thank you!
Emeritus Professor, the University of Kansas; Ph.D. University of Pennsylvania, Philadelphia PA; Masters, Washington University, St. Louis, MO. Author, editor, researcher, teacher, thinker
1 个月If course, it is. Almost all AI applications are.