The DPI in the product I work on is blacklist- and standards-based. i.e. it involves actually parsing most common formats, making sure that they are valid documents with no out-of-bounds values that could cause e.g. buffer overflows, and blacklisting known attacks.

FWIW our product can do this very quickly (we sell a 1U which can inspect 8 Gb/s).