الأمن السيبراني والذكاء الاصطناعي

British evaluation proves parity in offensive artificial intelligence capabilities

Written by

Picture of فريقنا

فريقنا

Communications Consultant

A British evaluation has shown that the GPT-5.5 model matches the performance of the Mythos model in cybersecurity challenges. The results highlight the growing offensive capabilities of artificial intelligence models.

 

Introduction

On April 30, the United Kingdom’s Artificial Intelligence Safety Institute published an official and highly critical evaluation revealing clearly that OpenAI’s latest version of the «GPT-5.5» model performs cybersecurity-related tasks with an efficiency and capability that entirely matches the performance of Anthropic’s «Claude Mythos Preview» model. These precise and concerning results indicate that the highly alarming security and offensive capabilities that characterized the Mythos model are in fact not exclusive to a single model, but rather constitute an inherent part of a broader upward trend encompassing the development of all leading global artificial intelligence language models.

Comparable results in complex expert tasks

The complex and advanced cyber challenges set by the AI Safety Institute—which undoubtedly require an advanced level of human expertise—included difficult tasks such as exploiting memory corruption vulnerabilities, cracking custom encryption algorithms, and performing binary and software reverse engineering. Amidst these tests, GPT-5.5 achieved an impressive average success rate of 71.4 percent, compared to 68.6 percent for the Mythos model, while the older GPT-5.4 version scored 52.4 percent and the Opus 4.7 model scored 48.6 percent. Because these results fall well within statistically established margins of error, the two models are considered remarkably equivalent and comparable in performance.

Furthermore, GPT-5.5 became only the second smart model in testing history to complete a complex 32-step consecutive cyberattack simulation on a corporate network, succeeding in two out of 10 full attempts. This advanced simulation included initial reconnaissance, credential theft, lateral movement within networks, executing a pivot attack in the CI/CD software supply chain, and reaching the final data exfiltration stage. According to accurate estimates by the AI Safety Institute, this continuous chain of operations would take a professional human expert approximately 20 hours to complete entirely. In one specific task, GPT-5.5 managed to finish a challenge that took a human expert about 12 hours in less than 11 minutes and at a cost of just $1.73 USD.

A general trend rather than an isolated breakthrough

When Anthropic officially announced the Mythos model on April 7 and simultaneously decided to completely withhold it from public release and usage due to its immense and autonomous capability to discover and exploit previously undiscovered zero-day vulnerabilities, this action sparked a wave of widespread concern across the entire cybersecurity industry. Anthropic subsequently launched a tightly controlled access program called «Project Glasswing», restricting usage rights to only about 40 carefully vetted and approved organizations and companies, including Google, Microsoft, Apple, Amazon, and JPMorgan Chase. However, the latest evaluation conducted by the British institute completely changed this picture, with the institute writing in its report: «The core and pivotal question revolved around whether this reflects a unique scientific breakthrough limited to a specific model, or whether it represents part of a general trend in the technology sector. The results we obtained from an early checkpoint of the GPT-5.5 model strongly support the second possibility».

Sharp divergence in model access strategies

These findings and discoveries heighten the policy tensions between the competing companies. While Anthropic imposed complete and strict restrictions on the use of the Mythos model, OpenAI chose a different path and made the GPT-5.5 version available to the public on April 23, relying primarily on its safety stack to prevent dangerous and suspicious cyber requests from casual users. Meanwhile, CEO Sam Altman announced on April 30 that a customized version of the model with enhanced cyber capabilities would be offered to a carefully selected group of «trusted defenders» in the coming days to bolster defensive capabilities. The British institute strongly warned that if offensive cyber capabilities simply emerge as a natural byproduct of general improvements in reasoning and autonomy, «we must undoubtedly expect further steady increases in models’ cyber capabilities in the near future, perhaps in rapid and surprising succession».

Frequently asked questions

Question: What is the main finding of the British AI Safety Institute’s evaluation?

Answer: The evaluation concluded that OpenAI’s artificial intelligence model possesses advanced hacking and cybersecurity capabilities that match those possessed by Anthropic’s restricted Mythos model.

Question: How fast was the model in executing cyber tasks compared to humans?

Answer: Testing showed that the model was able to complete a full cyberattack simulation and complex task in just 11 minutes, a job that takes a professional human expert about 12 to 20 hours.

Question: How did company policies differ regarding making these models publicly available?

Answer: While Anthropic decided to completely withhold its model from the public and restrict it to specific organizations for security reasons, OpenAI made its model available to the public while relying on safety filters to block malicious requests.

Question: What are the future concerns regarding the development of these models?

Answer: Experts warn that offensive cyber capabilities could evolve rapidly and alarmingly as a natural byproduct of increased model intelligence and logical reasoning capabilities.

شارك هذا الموضوع:

شارك هذا الموضوع:

اترك رد

Leave a Reply

الفئات

المنشورات الأخيرة

Discover more from Buzzinga

Subscribe now to keep reading and get access to the full archive.

Continue reading