Fudan's Whitzard agent ranks No. 2 on CyberGym exploit benchmark

Share
Fudan's Whitzard agent ranks No. 2 on CyberGym exploit benchmark

A Chinese university team just proved that an open-weight model plus strong agent scaffolding can out-hack the labs that built the models.

Fudan University's Whitzard agent jumped to No. 2 globally — and No. 1 among universities — on CyberGym, the AI security benchmark, cracking 91.2% of the real-world vulnerabilities it faced. The new leaderboard, released this week, puts the team led by Professor Yang Min's lab in the world's first tier of AI attack-and-defense research. CyberGym, initiated by UC Berkeley, is one of the harsher tests in AI security: agents are dropped into full repositories of millions of lines of code drawn from 188 large open-source projects and must autonomously locate, analyze, and exploit real vulnerabilities, then verify the attack in a sandbox. No multiple choice — either the code breaks or it doesn't.

The jump is the story. Whitzard's previous phase score was 68.9%; the new version hit 91.2% — cracking 1,374 of the benchmark's 1,507 vulnerabilities — after iterating on long-horizon reasoning and dynamic verification, and after switching its engine to DeepSeek-v4-Flash, an open-weight model. That result beats DeepSeek's own official CyberGym entry by 14.5%, which makes the point neatly: in hard, real-world tasks, agent design and model choice matter as much as raw scale. The Fudan group — the only Chinese team holding a "grand slam" of distinguished paper awards at the four top cybersecurity conferences — is turning a decade of academic work into working attack agents.

Why it matters: this is offensive capability, not a trivia benchmark. An agent that autonomously finds and exploits real vulnerabilities in production-scale codebases is exactly the dual-use capability safety researchers keep flagging — the same theme as Zhipu's GLM-5.3 shipping with "emergent" cyber tools earlier this week, which we covered in Zhipu's GLM-5.3 ships with 'emergent' cyber capabilities. When a university team out-hacks the model makers using their own open weights, the "we'll gate the dangerous capabilities ourselves" argument gets harder to sell — to regulators and to the labs.

What to watch: whether the model-vs-scaffolding split holds as bigger labs pour more compute into their own agents, and who eventually claims the No. 1 slot on CyberGym.

If a university-built agent can out-exploit the labs that trained the models, who should control AI security research? Tell us in the comments.

Sources: Fudan University · Sina Finance (via Shanghai Observer)