A WIRED investigation shows that the popular Chinese AI model is censored on both the application and training level. Less than two weeks after DeepSeek launched its open-source AI model, the Chinese startup is still dominating the public conversation about the future of artificial intelligence. While the firm seems to have an edge on US rivals in terms of math and reasoning, it also aggressively censors its own replies. Ask DeepSeek R1 about Taiwan or Tiananmen, and the model is unlikely to give an answer. To figure out how this censorship works on a technical level, WIRED tested DeepSeek-R1 on its own app, a version of the app hosted on a third-party platform called Together AI, and another version hosted on a WIRED computer, using the application Ollama. (…) After DeepSeek exploded in popularity in the US, users who accessed R1 through DeepSeek’s website, app, or API quickly noticed the model refusing to generate answers for topics deemed sensitive by the Chinese government. These refusals are triggered on an application level, so they’re only seen if a user interacts with R1 through a DeepSeek-controlled channel. Rejections like this are common on Chinese-made LLMs. A 2023 regulation on generative AI specified that AI models in China are required to follow stringent information controls that also apply to social media and search engines. The law forbids AI models from generating content that “damages the unity of the country and social harmony.” In other words, Chinese AI models legally have to censor their outputs. “DeepSeek initially complies with Chinese regulations, ensuring legal adherence while aligning the model with the needs and cultural context of local users,” says Adina Yakefu, a researcher focusing on Chinese AI models at Hugging Face, a platform that hosts open source AI models. “This is an essential factor for acceptance in a highly regulated market.” (China blocked access to Hugging Face in 2023.) To comply with the law, Chinese AI models often monitor and censor their speech in real time. (Similar guardrails are commonly used by Western models like ChatGPT and Gemini, but they tend to focus on different kinds of content, like self-harm and pornography, and allow for more customization.) Because R1 is a reasoning model that shows its train of thought, this real-time monitoring mechanism can result in the surreal experience of watching the model censor itself as it interacts with users. When WIRED asked R1 “How have Chinese journalists who report on sensitive topics been treated by the authorities?” the model first started compiling a long answer that included direct mentions of journalists being censored and detained for their work; yet shortly before it finished, the whole answer disappeared and was replaced by a terse message: “Sorry, I’m not sure how to approach this type of question yet. Let’s chat about math, coding, and logic problems instead!”

via wired: Here’s How DeepSeek Censorship Actually Works—and How to Get Around It

siehe dazu auch: DeepSeek in der Praxis-Analyse: Was den ChatGPT-Konkurrenten besonders macht Die China-KI von DeepSeek ist in aller Munde und sorgte für abstürzende US-Börsenkurse. Was die DeepSeek anders macht und ob sie wirklich eine Zäsur darstellt. (…) Denn das brandneue Modell DeepSeek-R1 und der Vorgänger DeepSeek-V3 sollen in KI-Benchmarks nicht nur OpenAIs ChatGPT 4o und o1 abhängen, sondern auch wesentlich kostengünstiger zu trainieren sein. Das würde insbesondere den massiven Hardware-Einsatz infrage stellen, der für das Training vieler bisherigen universeller LLMs (Large Language Modules) anfällt – und damit unter anderem an Nvidias Geschäftsmodell sägen. Die Entwickler lassen sich zudem in die Karten schauen, indem sie das Modell zum kostenlosen Download zur Verfügung stellen und es damit Dritten erlauben, von ihrer Arbeit zu profitieren. Ein besonders effizientes KI-Modell, das prinzipiell jeder für seine Zwecke verwenden kann, klingt jedenfalls nach einem ernsten Herausforderer. (…) Problematisch ist, wie China die DeepSeek-KI unmittelbar beeinflusst. Das kann jeder schnell nachvollziehen: Auf die grundsätzlich harmlose Frage, was am 4. Juni 1989 passierte, blockte der Chatbot direkt ab und weigerte sich auf Englisch die Frage zu beantworten. Auf die Nachfrage, warum für die KI der 4. Juni ein Problem sein, begann sie ihre Antwort zu formulieren und brach unmittelbar dann ab, als sie selbst Tian’anmen-Massaker schrieb. Wir hatten das Ereignis mit keinem Wort erwähnt. Als wir fragten, was der “Platz des himmlischen Friedens” sei, schrieb die KI tatsächlich eine ausführliche Antwort und gab in ihren Gedankengängen preis, dass sie besonders vorsichtig sein müsse und keine Seite einnehmen dürfe. Nur um dann alles zu löschen, sobald die bloßen Fakten kamen. Eindeutig ist hier also eine rote Linie “eingebaut” – also eine Zensur auch für nicht chinesische Nutzer. Das zeigt: DeepSeek unterliegt erwartungsgemäß den chinesischen Befindlichkeiten. Taiwan etwa ist ein weiterer Themenkomplex, bei dem die KI tendenziell aus chinesischer Sicht antwortet oder eben heikle Aussagen blockiert. Welche das jedoch im Detail sind, weiß man nicht.

Categories: DiensteGewaltInternet