UC Berkeley RDI
UC Berkeley RDI, the Center for Responsible Decentralized Intelligence, publishes and operates cybergym.io as an observatory: a site that self-describes as continuously and openly tracking AI’s cybersecurity capabilities across the stages of attack and defense, so developers, researchers and policymakers can stay informed in a timely manner.1 It runs three benchmarks, one per stage of the vulnerability lifecycle, and takes feedback at rdi_research@berkeley.edu.1 Dawn Song is the senior author common to all three.
Benchmarks
| Benchmark | Stage | Scale |
|---|---|---|
| CyberGym | Vulnerability reproduction | 1,507 instances across 188 OSS-Fuzz projects |
| ExploitGym | Exploit generation | 869 instances: 502 userspace, 181 V8, 186 Linux kernel |
| CyberGym-E2E | End-to-end discover-and-patch | 920 tasks across 139 OSS projects, four cumulative stages |
CyberGym is published at ICLR 2026; CyberGym-E2E at ICML 2026. ExploitGym is a seven-organization effort: UC Berkeley, the Max Planck Institute for Security and Privacy, UC Santa Barbara, Arizona State University, Anthropic, OpenAI and Google — with benchmark design and experimental methodology attributed to the academic authors and Anthropic, OpenAI and Google credited with providing model access and feedback.2 Yan Shoshitaishvili of Arizona State University is a named co-author of ExploitGym; he does not appear on the CyberGym or CyberGym-E2E author lists.
The site cross-links a separate RDI analysis, “Frontier AI’s Impact on the Cybersecurity Landscape”, and a live leaderboard site it calls the “Frontier AI Cybersecurity Observatory”, at rdi.berkeley.edu/frontier-ai-impact-on-cybersecurity/benchmarks.html.1 The observatory’s own leaderboard tables render client-side and carry no score readable from a static fetch, so this page states no leaderboard rank or score.
See also
- CyberGym Benchmark — the reproduction-stage benchmark.
- ExploitBench & ExploitGym — the exploit-generation benchmark, jointly authored with Arizona State University among others.
- CyberGym-E2E — the end-to-end discover-and-patch benchmark.
- Arizona State University — the wiki’s other non-vendor primary source on this axis, overlapping with RDI on ExploitGym’s author list.
- Frontier AI for Vulnerability Discovery — the wiki thesis this observatory’s three benchmarks anchor.
- Agentic Vulnerability Discovery — the method page CyberGym’s reproduction and open-ended-discovery results underwrite.
- End-to-End Harness Evaluation — the method page CyberGym-E2E’s four-stage validation ladder underwrites.
Footnotes
-
UC Berkeley RDI, CyberGym observatory front page (fetched 2026-08-31), which carries the observatory self-description, the feedback address and the three-benchmark index, and the CyberGym benchmark page, which carries the cross-links to RDI’s own analysis and leaderboard and the ICLR 2026 publication (OpenReview
2YvbLQEdYt). Local copies:.raw/articles/cybergym-observatory-2026-08-31.md,.raw/articles/cybergym-benchmark-2026-08-31.md. ↩ ↩2 ↩3 -
UC Berkeley RDI, ExploitGym (fetched 2026-08-31); arXiv:2605.11086. Local copy:
.raw/articles/exploitgym-2026-08-31.md. ↩