DeepSeek paper unveils DSec: 3M sandboxes a day powering agent RL training

智东西 · wechat · 2026-09-23

A new paper signed by DeepSeek founder Liang Wenfeng with 130+ authors details DSec (DeepSeek Elastic Compute), the sandbox platform behind agent training from V3.2 through V4.1. It serves 3 million sandboxes daily with 380k+ peak concurrent instances, 5,000+ creations per second, and up to 32,000 sandboxes for a single training task; one production unit packs 160 CPU nodes, 30k cores and 250TB of memory.

Key designs: four backends (FnCall, container, Firecracker microVM, full VM) behind one Python SDK; images split into independent read-only EROFS layers (only 4.2%–13.3% of full images are actually read), letting 8,192 containers deploy in 35 minutes vs 60+ for Docker cold pulls; rollouts decoupled from GPU training with cloud burst capacity — 200 cloud VMs absorb 30% of peak load. The paper also logs agent misbehavior (log scraping, forged RPCs, modifying /bin/bash, kernel crashes) mitigated via AppArmor and eBPF.

Related event: DeepSeek's DSec Paper Reveals Massive Agent Training Sandbox Infrastructure(8 posts)→

Original post →

More from coding & agent

coding & agent channel →