
Nvidia and CrowdStrike pit AI agents against each other on security
Nvidia and CrowdStrike built an experimental system that pits AI attacker and defender agents against each other in a closed loop, aiming to automate detection-engineering work that normally takes human security teams days, Nvidia said in a technical blog post.
- The system runs in four stages: attacker agents execute attacks in an isolated environment, defender agents analyze the resulting data, candidate detection rules get generated and tested against recorded attacks, then validated rules get deployed and retested against new attacks
- Nvidia's Nemotron 3 Ultra model handles defensive planning and reconstructs attack sequences; a customized, smaller Nemotron 3 Super model generates and repairs the actual detection rules
- CrowdStrike fine-tuned the defender model on 9,349 real detection examples covering 59 error types, then improved it further through reinforcement learning
- The automated pipeline lifted the mean detection rate from 16.5% to 41.9%, roughly 2.5 times better, against recorded attack data
- In live tests against 8 attacks the system hadn't seen before, its detections generalized correctly 45% of the time, against 29% for a comparison "frontier" AI system
- The open pipeline produced 3 detections that alone covered all 8 unseen attacks; the frontier system produced zero detections that broad
CrowdStrike reports that its resulting defensive model, built the same way, matches or beats the accuracy of the leading proprietary AI model it tested against, at 99% lower cost to run. Nvidia and CrowdStrike are explicit that this is a case study, not a finished product: the test covered a single family of attacks, used small detection sets, and hit harness failures during testing that the two companies haven't fully resolved.
The project sits on the defensive side of a fight Intokened has been tracking from both directions this week: OpenAI's Astra model earned the company's first Critical rating for building attacks without human help, and MCP servers have widened the surface those attacks can move through. Nvidia and CrowdStrike's system is a bet that defense can automate at the same speed offense proved it could.
None of these numbers describe a shipped, ready-to-buy product. CrowdStrike is folding this research into a system it calls SafeMind, and the case study's own authors call the results directional, not a general benchmark. It does show a specific, measured gap: letting AI agents fight each other in a loop produced detection rules that generalized to new attacks roughly 1.5 times better than a single large model working alone.
Nothing here should be taken as financial advice — just information to consider.

Comments (0)
No comments yet — be the first!
The market talks all day. We write when it says something
Short, and it tells you why it came
Related news
Most readTop 7
Silicon Valley Workers Are Wearing Noise-Cancelling Masks to Dictate AI Prompts
270AI





