算力基建 · 国产替代

深信服AI在CyberGym跻身全球前四
国产GLM-5.2基座支撑,AI安全不再依赖美国模型

Sangfor AI Ranks Top 4 Globally in CyberGym
Domestic GLM-5.2 Base Model Powers It, AI Security No Longer Depends on American Models

深信服Sangfor AI在国际AI安全基准CyberGym中解决86.3%漏洞挑战,全球前四国内第一,完全基于国产智谱GLM-5.2基座。

Sangfor AI solves 86.3% of CyberGym vulnerability challenges, ranking top 4 globally and first domestically, powered entirely by Zhipu's domestic GLM-5.2 base model.

No.024 2026.07.29 约 5 分钟阅读 ~5 min read

AI安全赛道一直默认美国模型最强。但7月29日一条新闻打破了刻板印象。

36氪报道,在国际AI安全基准CyberGym中,深信服(Sangfor)AI在纯国产基座(智谱GLM-5.2)固定配置下,面对ARVO与OSS-Fuzz全量高难度漏洞挑战,1507项任务解决1301项,成功率86.3%,最终全球前四、国内第一

CyberGym是什么,86.3%意味着什么

CyberGym是国际最权威的AI驱动漏洞挖掘和安全分析评测之一,测试AI自动发现、分析、修复软件漏洞的能力。用的都是真实世界高难度CVE,覆盖各种编程语言和漏洞类型,不是训练数据里见过的送分题。

在CyberGym拿高分比MMLU/GSM8K难得多——学术基准是选择题或有标准答案的数学题,漏洞挖掘是开放式问题:给你一段代码找连原作者都不知道的bug,写PoC触发它,甚至生成修复补丁。需要深度代码理解+创造性思维+安全专业知识。

86.3%意味着深信服超过绝大多数美国科技公司和安全厂商的系统,而且用的不是GPT-5/Claude/Gemini,是完全国产的智谱GLM-5.2。网络安全对信任度要求极高:模型会不会留后门?数据会不会出境?地缘政治紧张时API会不会被掐断?金融、能源、电信、政府等关键领域这些是真实供应链风险。

"AI安全的核心矛盾:你需要最强的AI防御最强AI攻击,但你能信任用来防御的AI吗?国产模型CyberGym成绩第一次给出肯定答案。"—— Dawn Vision编辑部

AI安全自主化拐点

上周微软发布首个网络安全专用模型MAI-Cyber-1-Flash和Perception安全平台,Nvidia联合微软组建开放安全AI联盟,Hugging Face被入侵后被迫用中国开源模型防御。AI安全正成为大模型竞争新主战场。

模型能力重要,自主可控同样重要。关键基础设施防御系统不能建立在竞争对手可能掐断的供应链上。深信服用GLM-5.2在CyberGym拿全球前四证明:国产基座在最硬核AI安全任务上已可和美国顶尖模型同台竞技

CyberGym测试的是AI vs AI攻防能力。未来攻击可能是AI Agent自动找漏洞、构造攻击链、横向移动;防御也必须用AI Agent实时检测响应修复。这是AI对AI军备竞赛,模型能力和供应链安全缺一不可。智谱ARR破亿美元、Kimi K3开源引硅谷恐慌、DeepSeek持续迭代——中国大模型2026夏天正从"跟跑"走向"并跑",部分场景"领跑"。

AI安全核心矛盾一直是:你需要最强AI防御最强AI攻击,但你能信任用来防御的AI吗?深信服在CyberGym的成绩,第一次给了这个问题国产答案。

明天见。

Sources · 参考来源

声明:本文为 Dawn Vision 基于公开信息的二次创作与独立分析,标题、观点、行文均为原创,仅供参考,不构成任何投资建议或决策依据。如有侵权请联系删除。

本文基于 Dawn Vision 认知引擎处理的 8 个源信号生成,经编辑部人工审核。素材来源:36氪、TechCrunch。

相关入库笔记:深信服 · Sangfor AI · CyberGym · AI安全 · GLM-5.2 · 智谱AI · 国产大模型 · 漏洞挖掘

The AI security sector has long defaulted to assuming American models are strongest. A July 29 news flash broke that stereotype.

36Kr reported that in CyberGym, the international AI security benchmark, Sangfor AI — running on domestic Zhipu GLM-5.2 — solved 1301 of 1507 high-difficulty vulnerability challenges across ARVO and OSS-Fuzz, achieving 86.3% success rate and ranking top 4 globally, first domestically.

What Is CyberGym and What Does 86.3% Mean?

CyberGym is one of the most authoritative international benchmarks for AI-driven vulnerability discovery, testing AI systems' ability to automatically find, analyze, and fix software vulnerabilities using real-world high-difficulty CVEs across languages and vulnerability types — not freebies from training data.

Scoring high on CyberGym is far harder than MMLU/GSM8K — academic benchmarks are multiple choice or math with standard answers; vulnerability discovery is open-ended: find bugs even original authors didn't know about, write PoCs, generate patches. It requires deep code understanding + creative thinking + security expertise.

86.3% means Sangfor outperformed the vast majority of American tech and security vendor systems, and didn't use GPT-5/Claude/Gemini — it used fully domestic Zhipu GLM-5.2. Cybersecurity demands extreme trust: backdoors? data exfiltration? API cutoff during geopolitical tension? For finance, energy, telecom, government, these are real supply-chain risks.

"The core AI security paradox: you need the strongest AI to defend against the strongest AI attacks, but can you trust the AI you defend with? Domestic models' CyberGym result provides the first affirmative answer."—— The Dawn Vision Editorial Desk

The Autonomy Inflection Point in AI Security

Last week Microsoft released its first cybersecurity-specialized model MAI-Cyber-1-Flash and Perception platform; Nvidia and Microsoft launched the Open Secure AI Alliance; after being breached, Hugging Face was forced to defend with a Chinese open-source model. AI security is becoming LLM competition's new main battlefield.

Model capability matters, but supply-chain autonomy matters just as much. Critical infrastructure defenses can't be built on supply chains competitors might cut. Sangfor's top-4 CyberGym ranking on GLM-5.2 proves domestic base models can now compete with top American models on the hardest AI security tasks.

CyberGym tests AI vs. AI offensive/defensive capabilities. Future attacks may be AI agents auto-finding vulnerabilities, constructing attack chains, moving laterally; defense must use AI agents for real-time detection/response/remediation. It's an AI-on-AI arms race where capability and supply-chain security are both indispensable. Zhipu hit $100M ARR, Kimi K3 open weights caused Silicon Valley panic, DeepSeek keeps iterating — Chinese LLMs in summer 2026 are shifting from catching up to running alongside, leading in some niches.

The core paradox: you need the strongest AI to defend against the strongest AI attacks, but can you trust the AI you defend with? Sangfor's CyberGym result provides, for the first time, a domestic answer.

See you tomorrow.

Sources · 参考来源

声明:本文为 Dawn Vision 基于公开信息的二次创作与独立分析,标题、观点、行文均为原创,仅供参考,不构成任何投资建议或决策依据。如有侵权请联系删除。

This article was generated by the Dawn Vision cognitive engine processing 8 source signals, with human editorial review. Sources: 36Kr, TechCrunch.

相关入库笔记:Sangfor · CyberGym · AI security · GLM-5.2 · Zhipu AI · domestic LLMs · vulnerability discovery

AI安全核心矛盾:你需要最强AI防御最强AI攻击,但你能信任用来防御的AI吗?国产模型CyberGym成绩第一次给出肯定答案。

—— Dawn Vision编辑部

The core AI security paradox: you need the strongest AI to defend against the strongest AI attacks, but can you trust the AI you defend with? Domestic models' CyberGym result provides the first affirmative answer.

—— The Dawn Vision Editorial Desk
深信服 · Sangfor AI · CyberGym · AI安全 · GLM-5.2 · 智谱AI · 国产大模型 · 漏洞挖掘
Sangfor · CyberGym · AI security · GLM-5.2 · Zhipu AI · domestic LLMs · vulnerability discovery
Sources · 信源 Sources

本文基于 Dawn Vision 认知引擎处理的 8 个源信号生成,经编辑部人工审核。素材来源:36氪、TechCrunch。

This article was generated by the Dawn Vision cognitive engine processing 8 source signals, with human editorial review. Sources: 36Kr, TechCrunch.