MAI-Cyber 1
MAI-Cyber-1-Flash inside MDASH

原始链接: https://microsoft.ai/news/introducing-mai-cyber-1-flash-inside-mdash/

微软推出了 **MAI-Cyber-1-Flash**,这是一款旨在处理 90% 常规网络安全任务的高效安全模型。通过将该模型与更强大的系统(如 GPT-5.4)相结合来应对复杂挑战,MDASH 平台在 CyberGym 测试中实现了 96% 的成功率(提升了 12 个百分点),同时将运营成本降低了 50%。 该战略基于三大支柱: * **模型**:MAI-Cyber-1-Flash,一款从零构建的、专注于安全的小型化模型。 * **数据**:源自微软生态系统中每日数万亿条信号的无与伦比的历史安全洞察。 * **引擎**:MDASH,这是一个经过专家调优的多智能体系统,现已支持 **Perception**——一套用于持续监控和补救的全新智能安全工作流套件。 安全性是该系统的基础。该模型经过了严格的红队测试和第三方验证,并辅以企业级治理。通过利用将威胁数据与实际结果连接起来的持续强化学习循环,微软确保其安全人工智能能够每日改进。这种方法为防御者提供了一个优化、经济且高度可靠的系统,能够为每一项特定任务提供最合适的模型。

Hacker News 社区目前正在讨论微软发布的“MAI-Cyber 1”模型。讨论帖强调了对其可访问性的质疑,用户难以找到使用该工具的明确途径,并指出该模型目前主要局限在微软的企业生态系统内,或仅限于 MDASH 等有限预览版中。 讨论的重点包括: * **可访问性问题:** 用户对获取该模型的难度感到沮丧,有人猜测它最终可能会像微软的其他闪电模型(flash models)一样进入 GitHub Copilot。 * **开放与封闭:** 市场对开源权重模型有明显需求,参与者指出,思科的 Antares 等竞争对手因其开放性而更具吸引力。微软在分享开发细节的同时却保持权重私有的策略被视为自相矛盾。 * **行业观察:** 评论者指出科技品牌的一种趋势,即专有 AI 公司正越来越多地在其博客中采用“朴实、沉稳”的审美风格,以建立信任感。 总的来说,虽然技术社区对该模型在网络安全领域的能力很感兴趣,但主流情绪是对闭源做法和复杂的企业访问障碍感到失望。
相关文章

原文

Picking the right model for the task

Security is an always-on mission, and given the enormous volume of inbound attacks, token cost is now the real constraint for defenders. MAI-Cyber-1-Flash was designed to efficiently handle up to 90% of all tasks, enabling MDASH to use the larger and most costly models in our fleet (in this case GPT-5.4) for the 10% of exceptionally hard tasks that truly need them.

The result is that the unified system of MDASH with MAI-Cyber-1-Flash delivers 96% on CyberGym (+12 pt above Mythos).

This combination delivers a 50% cost saving when compared against our best offering in MDASH today (GPT 5.4 + 5.4 mini + 5.3 codex). That’s the power of a well-tuned, multi-model system with access to uniquely rich historical training data. It ensures you always have the best model at the best price for every task.

In this new environment, being able to go from identifying a new vulnerability to addressing it in real-time is critical. And while AI remediation of software vulnerabilities is now a key security workflow, there are many jobs to be done by Security practitioners themselves.

That’s why today we’re also launching Perception, our agentic security systems, that provides teams of agents for a variety of security workflows in MDASH, to continuously monitor, patch, and close new threat vectors. Perception will also soon use MAI-Cyber-1-Flash for many more security workflows, beyond the software vulnerability work.

Three things matter today: Model. Data. Harness.

We have jointly optimized our world-class models, our unmatched historic data, and our expert-tuned harness to ensure that our customers have a uniquely powerful security offering.

Model. MAI-Cyber-1-Flash is a compact, code-heavy security model derived from the MAI-Thinking-1 lineage, which was built from scratch, in-house, on the highest quality data. Details in our technical report.

Data. Our deepest advantage. Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network, and an unmatched record of real exploits and remediations. No one can manufacture this history.

Harness. MDASH, our multi-agent vulnerability identification and remediation harness, is tuned by the best security experts in the industry, who have created 100+ agents using multiple leading models to find, validate, and remediate vulnerabilities. Agentic code scanning is a critical function in the Security Operating Center and feeds Project Perception, our new agentic security system.

Built with safety first

Because MAI-Cyber-1-Flash is Microsoft’s first cyber model, we built trust into every layer of the system, from model training to customer deployment. The model was developed with a security-first calibration, rigorously evaluated by Microsoft’s AI Red Team, tested through automated and expert-led adversarial exercises, and independently assessed by a third party.

Trust extends beyond the model itself. Through MDASH, customers get enterprise-grade controls including Role-Based Controls, tenant isolation, encryption, auditability, and sandboxed execution environments with no internet access. The result is a cyber model that delivers powerful capabilities to defenders while maintaining the governance, security, and control enterprises expect from Microsoft.

Our hill-climbing machine

Cybersecurity is not just a data-rich domain; it is a live reinforcement learning loop. Every day, defenders investigate threats, triage alerts, hunt adversaries, remediate vulnerabilities, deploy protections, and learn from the outcome.

Microsoft sees that loop end to end: vulnerabilities through Microsoft Security Response Center; attacks and defenses across identity, endpoint, cloud, data, browser, and applications; more than 100 trillion security signals every day; and operational insight from 1.6 million customers. Because we can connect actions to outcomes; what was exploitable, what was contained, what was blocked, and what actually worked; we have more than data.

Our MAI reinforcement learning loop gives us the foundation to build cyber models that improve continuously and become expert cyber defenders. That’ll remain our commitment to our customers for years to come.

联系我们 contact @ memedata.com