So much discussion about whether we should be using Chinese open-source models in the US. But how could they actually hurt us?
Matan Grimberg
@matanSF breaks down the biggest risks-
1. Intentional vulnerabilities. A model could contain backdoors, sleeper behavior, or other weaknesses deliberately introduced into the weights, potentially sitting dormant until the right conditions trigger them.
2. Unintentional vulnerabilities. A model built in China will naturally be trained and optimized around Chinese users, codebases, languages, and data. It could perform incredibly well overall while having subtle blind spots or security weaknesses in Western systems that nobody intentionally put there.
The third we may not know for years. The most concerning failures might not show up in today’s benchmarks or security evaluations. If models become deeply embedded across companies and infrastructure, vulnerabilities could emerge only after we’ve become dependent on them.