Research
14,560-Execution Injection Audit of DeepSeek Harness: Hidden Unicode in Files Hits 25.5% Attack Success
Tencent's AI-Infra-Guard team ran 14,560 controlled executions against DeepSeek Harness across 16 indirect-content channels, two carrier modes, 35 payload objectives and 12 attack methods, preserving the real agent loop, tool registry and session-event path with local sensitive-sink fixtures. Peak attack success: 25.5% for hidden Unicode in file mode, 17.0% for fake-completion in text mode, and 16.0% for the skills channel in file mode. The rule-based and LLM judges disagree materially — the LLM judge assigns partial compliance 7.3% of the time versus 2.0% — which is itself a warning about how injection benchmarks are scored.
↳ Follow the thread