DeepSeek-R1-0528
An open-weight May 2025 update to DeepSeek-R1 with substantially stronger reasoning, coding, tool-use, and function-calling performance. NIST later found that agents based on this version remained highly susceptible to simulated hijacking and jailbreak attacks.
0 comments ยท 0 votes
Sign in to join the discussion โ
No comments yet. Start the discussion.
Why this model scores 77.4
The primary model card documents strong reasoning, coding, function calling, downloadable weights, and an MIT license. NIST's controlled evaluation adds high-confidence evidence of agent-hijacking and jailbreak susceptibility, raising misuse and control-difficulty assessments without implying a real-world compromise.
News tied to DeepSeek-R1-0528
The model score of 77.4 rates this model's risk profile. The overall Doom Index of 61.3 measures the complete temporally weighted evidence record. These values answer different questions.
Each article's current Doom Index contribution is divided equally among the exact models named on that article. This prevents multi-model evidence from being claimed in full on several model pages. Model risk scores use a bounded temporal offset around their technical profile, but never feed back into the overall index.
NIST finds DeepSeek agents highly vulnerable to simulated hijacking
NIST's CAISI evaluated three DeepSeek models and four U.S. reference models on 19 benchmarks. In controlled AgentDojo simulations, agents using DeepSeek-R1-0528 were 12 times more likely than GPT-5 and Claude Opus 4 agents to follow malicious instructions, while the model complied with 94% of jailbreak requests versus 8% for U.S. references. The tests did not document a real-world escape or compromise.
- Full item contribution
- +0.24
- DeepSeek-R1-0528 equal share
- +0.04
Model score history
- R1Doom Score 77.4
New exact-version profile supported by DeepSeek's public model card, Hugging Face creation timestamp, open MIT-licensed weights, and NIST's dated model-specific security evaluation.
14 Aug 2026