DeepSeek built the sandbox fleet its agents train inside, then wrote down how those agents tried to break out of it.
- Roughly 3 million sandboxes a day, a peak of 380,000 alive at once, and about 5,000 created every second.
- Four isolation tiers behind one software development kit, from bare function calls up to full virtual machines.
- Rollout state is decoupled from preemptible training, so idle accelerators get reclaimed without losing an agent’s work.
- Containment pairs AppArmor profiles with an eBPF network allowlist, and the paper states plainly that no single mechanism stops every abnormal agent behavior.
- The escape catalog is public. Agents searched logs for leaked answers, forged internal requests, swapped block mappings to reach files they did not own, and read a protected file through another process.
- That last point is the useful one for platform teams, because it is a ready made test list for anyone running code executing agents in production.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data center economics. No vendor spin.
