"Battling Attackers and Defenders in the Same Digital Twin"—SafeMind's Concept of Adversarial Co-evolution
On September 1st, CrowdStrike announced a new AI system called "SafeMind" at the Fal.Con 2026 keynote address. NVIDIA CEO Jensen Huang took the stage and declared, "This marks the beginning of a new era in cybersecurity." This system employs an intriguing architecture that continuously pits two AI models, an attacker and a defender, against each other in a closed loop. As a journalist with a background in AI research, I want to examine this design philosophy of "adversarial co-evolution."
Two Paired Models: "Red Tempest" and "Blue Solano"
At the core of SafeMind are two specialized AI models built on NVIDIA's open model, "Nemotron." "Red Tempest" is the attacker (red team) model, designed to mimic the behavior of an AI adversary and execute sophisticated attack scenarios. "Blue Solano" is the defensive (blue team) model, responsible for deploying real-world, field-tested countermeasures used by actual defense personnel to protect corporate assets.
These two models operate within a "digital twin" (virtual replica environment) of the customer's environment, built using NVIDIA's simulation technology. Red Tempest repeatedly attacks this virtual environment, and Blue Solano learns each time, identifying vulnerabilities and continuously deploying new detection rules until no more viable attack paths remain, forming a closed feedback loop.
A Warning: "Time to Intrusion" Has Become "Execution Time"
Crucial to understanding this announcement is CrowdStrike CEO George Kurtz's recognition of industry changes. The company has annually reported on how much the "breakout time"—the time it takes for an attacker to move laterally within the network—has decreased. According to Kurtz, this time has continued to shrink year after year, from 2 minutes to 72 seconds, and then to 27 seconds.
The message Kurtz conveyed in this announcement is that the very concept of "breakout time" is becoming meaningless. In attacks using AI agents, this time is now synonymous with "runtime," and the time window for human decision-making is effectively disappearing.
Claim of "99% Lower Cost and Accuracy Exceeding Frontier Models"
The figures published by CrowdStrike and NVIDIA regarding technical performance are also noteworthy. The Blue Solano model, fine-tuned based on Nemotron 3 Super, showed higher accuracy than major frontier models (general-purpose large-scale language models) in internal evaluations, while costing 99% less.
This is a concrete example demonstrating that specialized, smaller-scale models can significantly outperform general-purpose large-scale models in terms of cost-effectiveness for specific tasks (in this case, cybersecurity threat detection and response). This achievement can be seen as an extension of the industry-wide technological trend of "specialization over generality, efficiency over scale," which is also reflected in the previously discussed NVIDIA Nemotron 3.5 Lightning and Samsung's PIM technology.
NVIDIA's Strategy: "Open Weights"
In this announcement, Mr. Huang emphasized that the Nemotron model is being offered as open weights (the trained weights are made public, allowing anyone to use and customize them). He stated that "the strength of cybersecurity lies in transparency and collective action," indicating his belief that enabling defenders to more widely adopt and customize this type of model will lead to improved overall industry defense capabilities.
As previously mentioned, Mr. Huang has repeatedly publicly spoken about the importance of open-source AI models in recent months. This collaboration with CrowdStrike can be understood as an extension of this consistent strategy.
Research Significance of the "Adversarial Co-evolutionary Loop" Method
SafeMind's design, which involves continuously pitting attack and defense models against each other in a closed environment, can be understood as an application of the concept of adversarial learning—found in machine learning research such as Generative Adversarial Networks (GANs)—to the practical field of cybersecurity.
The attacking model explores exploitable pathways through multiple sub-agents—Recon, Assault, and Compromise—while the defense model handles monitoring with Falcon sensors, verification of detection candidates, and automatic network strengthening. The extent to which this type of mutually enhancing automated learning process can sustainably improve actual defensive capabilities is an interesting research topic that should be verified through future operational performance.
What Researchers Should Keep an Eye on
SafeMind's announcement highlights a structural shift across the entire industry: the rapid acceleration of AI-driven attacks necessitates that defenders also utilize the same AI technology at the same speed. Both OpenAI's "GPT-5.6-Cyber," previously discussed, and the CrowdStrike/NVIDIA initiative are based on a shared concern: an attempt to bridge the speed gap between attack and defense.
The extent to which these automated attack and defense loops function reliably in actual corporate networks, and to what extent unintended false positives and side effects can be minimized, will become clear as more extensive real-world operational data is accumulated. We should closely monitor the future development of cybersecurity as both attackers and defenders seek a new equilibrium point based on AI-driven automation.