发现DeepSeek-R1在敏感话题上存在本地化内容屏蔽,且可被绕过。
R1dacted: Investigating Local Censorship in DeepSeek's R1 Language Model
- 构建大规模敏感提示集,对比其他模型发现R1独有屏蔽行为。
- R1对政治敏感问题响应具一致性,受语境和措辞影响,跨语言存在类似现象。
- 提出绕过方法并验证其有效性,揭示训练与对齐设计可能引入隐蔽审查机制。
DeepSeek最新发布的R1大语言模型在推理任务中表现优异,甚至超越OpenAI的o1模型。然而,有报告指出R1对中国政治敏感话题拒绝回应。本文首次系统研究该现象:构建大规模、高度筛选的敏感提示集,涵盖多种敏感主题但未被其他模型屏蔽;分析R1的屏蔽模式,包括一致性、触发条件及跨主题、语境和语言的变化;探索其在多语言下的表现,并测试从R1蒸馏出的模型是否继承屏蔽行为;最后提出绕过或移除屏蔽的技术。结果表明,屏蔽可能源于训练或对齐过程中的设计选择,凸显模型部署中的透明度、偏见与治理风险。
原文摘要 · Abstract (English)
DeepSeek recently released R1, a high-performing large language model (LLM) optimized for reasoning tasks. Despite its efficient training pipeline, R1 achieves competitive performance, even surpassing leading reasoning models like OpenAI's o1 on several benchmarks. However, emerging reports suggest that R1 refuses to answer certain prompts related to politically sensitive topics in China. While existing LLMs often implement safeguards to avoid generating harmful or offensive outputs, R1 represents a notable shift - exhibiting censorship-like behavior on politically charged queries. In this paper, we investigate this phenomenon by first introducing a large-scale set of heavily curated prompts that get censored by R1, covering a range of politically sensitive topics, but are not censored by other models. We then conduct a comprehensive analysis of R1's censorship patterns, examining their consistency, triggers, and variations across topics, prompt phrasing, and context. Beyond English-language queries, we explore censorship behavior in other languages. We also investigate the transferability of censorship to models distilled from the R1 language model. Finally, we propose techniques for bypassing or removing this censorship. Our findings reveal possible additional censorship integration likely shaped by design choices during training or alignment, raising concerns about transparency, bias, and governance in language model deployment.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。