Artificial intelligenceJuly 26, 2026· via MarkTechPost

Sakana AI’s Fugu-Cyber hits 86.9% on cybersecurity benchmarks

Sakana AI’s Fugu-Cyber hits 86.9% on cybersecurity benchmarks

Sakana AI has just pushed the envelope in AI-driven cybersecurity with Fugu-Cyber, a security-focused model that delivers 86.9% accuracy on CyberGym and 72.1% on CTI-REALM—placing it alongside top-tier cyber LLMs like GPT-5.5-Cyber and Claude Mythos Preview. Unlike general-purpose models, Fugu-Cyber is the third endpoint in Sakana’s Fugu orchestration family, specifically tuned for security reasoning and agentic workflows. Its release underscores a growing trend: specialized orchestration is becoming as critical as raw model performance in real-world cyber defense.

A two-sided benchmark challenge

The model’s results are split between two distinct security tasks. CyberGym, developed at UC Berkeley, tests an agent’s ability to reproduce and verify real-world vulnerabilities across 1,507 cases in 188 open-source projects. The agent receives a vulnerability description and an unpatched codebase, then crafts a proof-of-concept that triggers a crash only in the vulnerable version—making it difficult to game. CTI-REALM, from Microsoft, flips the script: it measures how well an agent turns threat intelligence into actionable detections. Using 37 public threat reports, the model must map MITRE ATT&CK techniques, analyze telemetry, refine KQL queries, and output validated Sigma rules across Linux, Azure Kubernetes, and Azure cloud environments.

While CyberGym’s 86.9% result is competitive—only slightly ahead of Anthropic’s 83.1% and OpenAI’s 85.6%—CTI-REALM tells a different story. Microsoft’s own top three configurations (all Claude-based) scored between 0.624 and 0.685 on the benchmark’s trajectory reward scale. Fugu-Cyber’s 72.1% sits above that band, though it’s worth noting the metric isn’t a simple pass/fail rate.

Behind the scenes: orchestration as the secret sauce

Fugu-Cyber isn’t a standalone model—it’s a node in Sakana’s Fugu orchestrator, a language model that dynamically builds agentic workflows. Upon receiving a query, it scaffolds a multi-agent system, delegating sub-tasks to specialized models in a pool. This approach is detailed in Sakana’s technical report and two ICLR 2026 papers, TRINITY and The Conductor. TRINITY assigns distinct roles—Thinker, Worker, Verifier—to different LLMs, while The Conductor uses reinforcement learning to optimize coordination strategies. In cybersecurity, the verifier role is key: potential vulnerabilities are cross-checked by security-specialized sub-agents before any patch is proposed, adding a layer of rigor often missing in automated security workflows.

Access, policy, and practical limits

Fugu-Cyber is tightly controlled. Access requires an application form outlining use cases and verified contact details, with manual review by Sakana’s team. It ships under an updated Acceptable Use Policy explicitly prohibiting offensive misuse, and billing is restricted to the Token Plan, with subscriptions ($20, $100, $200) covering Fugu and Fugu-Ultra only. Routing logic remains proprietary, so users can’t audit which model handled each step—a trade-off between performance and transparency.

Why it matters

Fugu-Cyber’s results highlight a pivotal shift: the best cybersecurity AI isn’t just a smarter model—it’s a smarter system. While raw scores make headlines, the real value lies in orchestration that can verify, refine, and act on threats with minimal human oversight. For defenders, this could mean faster patch validation and more reliable detection engineering, but only if access controls and transparency improve. The model’s performance edge on CTI-REALM in particular suggests a future where AI doesn’t just flag threats but helps build the defenses against them—provided organizations can navigate its gated ecosystem.


Source: MarkTechPost. AI-assisted editorial synthesis — TechnoExpress.

Read the original source on MarkTechPost →

← Back to home