Google DeepMind Unveils Gemini 3.5 Flash Cyber — Lightweight Model for Cybersecurity
Google/DeepMind
Google DeepMind
Google DeepMind has introduced Gemini 3.5 Flash Cyber, a lightweight cybersecurity model built on top of 3.5 Flash, fine-tuned for vulnerability discovery, validation, and patching. The model, available via a limited-access pilot through CodeMender, offers a cost-efficient alternative to larger cybersecurity AI models, achieving competitive results on benchmarks like CyberGym and uncovering unique vulnerabilities in complex codebases.
Google DeepMind announced Gemini 3.5 Flash Cyber, a lightweight cybersecurity model based on the 3.5 Flash foundation and fine-tuned to find, validate, and patch vulnerabilities effectively. The model is designed for cost-efficiency and scalability, leveraging Flash's performance to outperform mainline Flash models on cybersecurity tasks. It is deployed through a limited-access pilot program via CodeMender, exclusively available to governments and trusted partners initially, to give defenders a head start in fixing critical vulnerabilities. Benchmarks show 3.5 Flash Cyber achieving competitive success rates on CyberGym and surpassing mainline 3.5 Flash and Claude Opus 4.6 on evaluations like Big Sleep and Chrome's commit scanning pipeline, discovering 55 unique issues in the V8 JavaScript Engine compared to 47 and 36 for the other models. In real-world applications, Google's Cloud Vulnerability Research team used the model to uncover remote code execution vulnerabilities in public APIs and a memory-corruption vulnerability in a production service within two hours. The model also powers CodeMender for internal Google codebases including Chrome, Android, Cloud, Ads, and YouTube. Google emphasizes its responsible approach due to dual-use concerns, initially restricting access to trusted partners.
- Сокращения
- ASLR = Address Space Layout Randomization
Source: Google DeepMind —
original
