DeepSeek ๐Ÿ‡จ๐Ÿ‡ณ ยท DeepSeek-R1

DeepSeek-R1-0528

An open-weight May 2025 update to DeepSeek-R1 with substantially stronger reasoning, coding, tool-use, and function-calling performance. NIST later found that agents based on this version remained highly susceptible to simulated hijacking and jailbreak attacks.

DOOM SCORE77.4out of 100model risk profile, not the overall index
0 comments ยท 0 votesOpen discussion

Public discussion is readable by everyone. Sign in to comment, reply, or vote.

No comments yet. Start the discussion.

CURRENT ASSESSMENT ยท REVISION 1

Why this model scores 77.4

The primary model card documents strong reasoning, coding, function calling, downloadable weights, and an MIT license. NIST's controlled evaluation adds high-confidence evidence of agent-hijacking and jailbreak susceptibility, raising misuse and control-difficulty assessments without implying a real-world compromise.

Capability78
Autonomy62
Deployment96
Misuse potential75
Control difficulty80
MODEL-ATTRIBUTED EVIDENCE

News tied to DeepSeek-R1-0528

The model score of 77.4 rates this model's risk profile. The overall Doom Index of 61.3 measures the complete temporally weighted evidence record. These values answer different questions.

NET MODEL-ATTRIBUTED INDEX CONTRIBUTION+0.04

Each article's current Doom Index contribution is divided equally among the exact models named on that article. This prevents multi-model evidence from being claimed in full on several model pages. Model risk scores use a bounded temporal offset around their technical profile, but never feed back into the overall index.

Safety TOWARD

NIST finds DeepSeek agents highly vulnerable to simulated hijacking

NIST's CAISI evaluated three DeepSeek models and four U.S. reference models on 19 benchmarks. In controlled AgentDojo simulations, agents using DeepSeek-R1-0528 were 12 times more likely than GPT-5 and Claude Opus 4 agents to follow malicious instructions, while the model complied with 94% of jailbreak requests versus 8% for U.S. references. The tests did not document a real-world escape or compromise.

Full item contribution
+0.24
DeepSeek-R1-0528 equal share
+0.04
Read assessment โ†’
AUDIT TRAIL

Model score history

  1. R1
    Doom Score 77.4

    New exact-version profile supported by DeepSeek's public model card, Hugging Face creation timestamp, open MIT-licensed weights, and NIST's dated model-specific security evaluation.

    14 Aug 2026