DSec: Sandbox Infrastructure for AI Training Introduced
Warning Issued on Risks of System Escape and Environmental Destruction

Chinese artificial intelligence (AI) company DeepSeek has unveiled its own virtual infrastructure system designed to safely train and evaluate large-scale AI agent models. The company also stressed the need to proactively prevent misconduct and system destruction risks from AI agents that operate outside of human control.


According to Chinese media outlets such as The Paper on September 24, DeepSeek on the 19th released a research paper entitled “DeepSeek Secure and Elastic Computing (DSec): A Sandbox Infrastructure for Large-Scale Agent Training” on the preprint platform arXiv. More than 130 individuals, including DeepSeek founder Liang Wenfeng, contributed as authors.


"AI Agents Can Never Be Fully Trusted"... DeepSeek Raises Alarm on AI Training Infrastructure Safety View original image

The core topic of the paper is the “sandbox,” a security technology that allows computer programs and AI code to be executed and tested safely in an isolated virtual environment, preventing any impact on external systems or networks. Previously, it was reported that in a sandbox environment created by OpenAI in the United States to evaluate AI models’ cyberattack capabilities, an AI agent managed to hack an external website after escaping control. This incident highlighted the importance of stable isolated environments for AI agent training.


According to the paper, DeepSeek’s DSec infrastructure is equipped with approximately 160 server nodes, 30,000 central processing unit (CPU) cores, and 250 terabytes (TB) of memory for each basic unit. This infrastructure can generate 3 million virtual sandboxes daily and operate over 380,000 simultaneously, achieving the efficiency of creating more than 5,000 new sandboxes per second.


DeepSeek designed DSec to overcome the resource idle state that occurs when an AI agent is waiting for additional instructions or producing computational results. The company reported that it has increased efficiency by controlling average CPU utilization to below 5% in approximately 90% of sandboxes.


In particular, DeepSeek highlighted the security and safety risks associated with operating large-scale AI agents. The research team firmly stated that “AI agents in operation can never be trusted,” noting practical problems such as agents exhausting system resources, interfering with system configuration, or directly damaging their own execution environments.



In addition, the team observed that when AI agents were assigned tasks, they sometimes bypassed developer-imposed constraints and arrived at “unintended shortcut solutions.” They emphasized that embedding anti-cheating and behavioral restraint mechanisms directly into the training infrastructure has become essential. Since no single mechanism is sufficient to block all failures and misconduct, DeepSeek plans to continually strengthen DSec’s monitoring system.


This content was produced with the assistance of AI translation services.

© The Asia Business Daily. All rights reserved. Unauthorized AI training and use prohibited.

Today’s Briefing