NVIDIA与CrowdStrike发布SafeMind
NVIDIA and CrowdStrike Strengthen Agentic Cybersecurity Frontier
Agentic安全是当下热点,SafeMind展示了Nemotron模型在垂直领域落地的高性价比方案(低成本高准确率),对安全从业者有直接参考价值。
“We’re at an inflection point in cybersecurity,” Jensen Huang told a sold-out crowd at CrowdStrike’s Fal.Con 2026 in Las Vegas Tuesday. Attacks are now automated. Defense has to be, too.
"我们正处于网络安全的转折点,"英伟达创始人兼CEO黄仁勋周二在拉斯维加斯CrowdStrike Fal.Con 2026大会的满座人群中表示。攻击现已实现自动化,防御也必须如此。
The NVIDIA founder and CEO joined CrowdStrike CEO and founder George Kurtz to announce CrowdStrike SafeMind, its agentic cybersecurity system developed by the CrowdStrike Cyber Superintelligence Lab.
英伟达创始人兼CEO与CrowdStrike CEO兼创始人George Kurtz共同发布了SafeMind,这是由CrowdStrike Cyber Superintelligence Lab开发的代理式网络安全系统。
“This is the beginning of a new age of cybersecurity,” Huang told the crowd of 10,000 security professionals. “On the one hand, the adversaries are going to be more armed than ever. On the other hand, all of you are going to be more armed than ever.”
"这是一个网络安全新时代的开端,"黄仁勋对现场1万名安全专业人士说道。"一方面,对手将比以往任何时候都装备更精良;另一方面,你们也将比以往任何时候都装备更精良。"
SafeMind combines CrowdStrike’s purpose-built, beyond frontier-capable models and customized agentic harnesses, with defensive models built on NVIDIA Nemotron, in a continuous coevolution loop where offense and defense repeatedly challenge and improve each other.
SafeMind将CrowdStrike专为超越前沿能力打造的模型和定制化的代理式框架(agentic harnesses),与基于NVIDIA Nemotron构建的防御模型相结合,形成一个持续的共同进化循环,在此循环中,进攻与防御不断相互挑战并提升彼此。
CrowdStrike also announced CrowdStrike Falcon IQ to operationalize Project QuiltWorks through agentic workload automation and expanded its CrowdStrike Guardian AI safety solution.
CrowdStrike还宣布了Falcon IQ,通过代理式工作负载自动化来落实Project QuiltWorks,并扩展了其Guardian AI安全解决方案。
“We have asymmetric advantages because we have a large community of cybersecurity experts who want to work with each other and keep the world safe,” Huang told the crowd.
"我们拥有不对称的优势,因为我们拥有一个庞大的网络安全专家社区,他们希望彼此协作,让世界更安全,"黄仁勋对现场人群说道。
CrowdStrike’s annual conference drew security leaders from financial services, healthcare, the public sector and critical infrastructure.
CrowdStrike年度大会吸引了来自金融服务、医疗保健、公共部门和关键基础设施的安全领袖参加。
“The real gap that I saw was that the attackers had frontier AI, and the defenders didn’t,” Kurtz told them. “And that changes now.”
"我看到的真正差距是,攻击者拥有前沿AI,而防御者没有,"Kurtz对他们说。"而现在情况改变了。"
SafeMind
SafeMind
CrowdStrike built SafeMind’s defensive model using NVIDIA Nemotron open models, post-trained with CrowdStrike’s cyber experience and threat data. The SafeMind models are paired with proprietary cybersecurity harnesses optimized to work as an agentic stack.
CrowdStrike使用NVIDIA Nemotron开源模型构建了SafeMind的防御模型,并利用CrowdStrike的网络经验和威胁数据进行了后训练。SafeMind模型与专有的网络安全框架配对,这些框架经过优化,可作为代理式堆栈(agentic stack)运行。
The result ships natively in the CrowdStrike Falcon platform as SafeMind, CrowdStrike’s agentic cybersecurity system. SafeMind brings offensive and defensive AI together in a continuous coevolution loop, where each side adapts to and strengthens the other. This process continuously hardens the security of the customer environment until attacks are unsuccessful.
其成果以原生方式集成在CrowdStrike Falcon平台中,作为SafeMind——CrowdStrike的代理式网络安全系统。SafeMind将进攻性和防御性AI结合在一个持续的共同进化循环中,双方相互适应并增强彼此。这一过程不断加固客户环境的安全性,直到攻击失败为止。
“Your decade and a half of security data that we can train on — we can take a frontier model and make it essentially a super AGI that is incredibly good at cybersecurity,” Huang told Kurtz.
"我们可以利用你们十五年的安全数据进行训练——我们可以将一个前沿模型转化为本质上极其擅长网络安全的超级AGI,"黄仁勋对Kurtz说道。
“Together with NVIDIA, we built cybersecurity’s first complete agentic system for cybersecurity, including the first frontier models and harness purpose-built for defenders,” Kurtz said. “This isn’t a copilot baked into someone else’s intelligence. It’s not a chatbot with a security skin. It is a frontier-class model built and trained by CrowdStrike on our data in partnership with NVIDIA.”
“与英伟达合作,我们构建了网络安全领域首个完整的智能体系统,包括为首批前沿模型以及专为防御者打造的工具链,”Kurtz 表示。“这不是嵌入他人智能的副驾驶功能,也不是披着安全外衣的聊天机器人。它是 CrowdStrike 基于自有数据、与英伟达合作构建并训练的前沿级模型。”
NVIDIA Nemotron 3 Ultra orchestrates the defensive agent harness. A fine-tuned Nemotron 3 Super powers SafeMind’s rule-generation sub-agent.
NVIDIA Nemotron 3 Ultra 负责编排防御智能体工具链。经过微调的 Nemotron 3 Super 驱动 SafeMind 的规则生成子智能体。
By post-training Nemotron with CrowdStrike data, CrowdStrike internal evaluations showed that the Blue Solano model — based on Nemotron 3 Super — delivered higher accuracy rates than leading frontier models at 99% lower cost.
通过对 Nemotron 进行 CrowdStrike 数据的后训练,CrowdStrike 内部评估显示,基于 Nemotron 3 Super 的 Blue Solano 模型在成本降低 99% 的情况下,准确率高于领先的前沿模型。
While SafeMind can operate as a complete system, the models can be used independently to empower defenders to stay ahead of the adversary. Security experts can also pair their own models with CrowdStrike’s custom harnesses, giving customers the flexibility to use the right models and capabilities for their environment.
虽然 SafeMind 可以作为完整系统运行,但这些模型也可独立使用,帮助防御者保持对攻击者的优势。安全专家还可以将自有模型与 CrowdStrike 的定制工具链结合,为客户提供了根据环境选择合适模型和能力的灵活性。
“The harness is essentially the exoskeleton of the large language model,” Huang said. “The large language model is the brain. The exoskeleton turns it into an agent — and this exoskeleton doesn’t have to be the same shape and capability for every domain.”
“工具链本质上是大语言模型的外骨骼,”Huang 说。“大语言模型是大脑。外骨骼将其转化为智能体——而且这种外骨骼不必在所有领域都具备相同的形态和能力。”
When AI Is the Defense
当 AI 成为防御手段时
AI-enabled attacks rose 89% in the past year, and the fastest eCrime breakout time has reached 27 seconds, according to CrowdStrike. Human-speed response isn’t defense. It’s documentation.
据 CrowdStrike 称,过去一年中启用 AI 的攻击激增了 89%,最快的电子犯罪爆发时间已缩短至 27 秒。人类速度的响应算不上防御,那只是记录。
“There are many applications in the world where you must have the ability to fine-tune, to post-train — to create an AI that is super good at a particular domain,” Huang said. “Nemotron was created for precisely that. Completely free. Incredibly fast. You have the ability to have an asymmetric advantage against whatever comes your way.”
“世界上有许多应用场景要求必须具备微调、后训练的能力——以创建在特定领域表现卓越的人工智能,”Huang 说。“Nemotron 正是为此而生。完全免费。速度极快。你能够针对任何挑战获得不对称的优势。”
With open Nemotron as the base, CrowdStrike’s security teams post-trained on their own threat data without sending it to an outside provider, and customized the AI to their environment.
以开源的 Nemotron 为基础,CrowdStrike 的安全团队利用自身威胁数据进行后训练,无需将数据发送给外部提供商,并根据其环境对 AI 进行了定制。
That’s not possible with a closed frontier model, and in security, the ability to inspect what’s defending matters.
这是封闭的前沿模型所无法实现的,而在安全领域,能够检查防御机制本身至关重要。
Red vs. Blue
红队与蓝队对抗
NVIDIA announced its work testing the CrowdStrike SafeMind models and harnesses in a high-fidelity cyber agent environment running as a simulation of the NVIDIA network.
NVIDIA 宣布了其测试 CrowdStrike SafeMind 模型和工具链的工作,该测试在一个高保真网络智能体环境中进行,模拟了 NVIDIA 的网络场景。
The testing runs SafeMind in an offensive-defensive loop for adversarial coevolution. An offensive red-team agent finds the exploit, a blue-team defensive agent closes it and the findings become actionable detections to block attacks.
SafeMind 在对抗性协同进化中运行攻防循环。进攻方红队代理发现漏洞,防守方蓝队代理修复该漏洞,并将发现转化为可操作的检测规则以阻止攻击。
The red-agent harness runs Recon, Assault and Compromise sub-agents executing attack paths inside the cyber agent environment. The blue-agent harness monitors via Falcon sensors, generates detection candidates, validates them and promotes them.
红队代理框架运行 Recon、Assault 和 Compromise 子代理,在网络安全代理环境中执行攻击路径。蓝队代理框架通过 Falcon 传感器进行监控,生成检测候选项,验证它们并将其提升为正式检测。
CrowdStrike built the test environment with NVIDIA: a digital twin of NVIDIA’s own accelerated computing infrastructure, validated against NVIDIA’s real threat landscape.
CrowdStrike 与 NVIDIA 合作构建了测试环境:这是 NVIDIA 自身加速计算基础设施的数字孪生体,并针对 NVIDIA 的真实威胁态势进行了验证。
“The basic framework of SafeMind — an adversarial model acting on a digital twin of the environment, with a defender model in a continuous cat-and-mouse loop, eventually learning how to secure itself — this basic framework applies to robotics, edge computing, enterprise computing and just about everything,” Huang said.
“SafeMind 的基本框架——一个在环境数字孪生体上运作的对抗模型,以及在一个持续的猫鼠循环中的防御模型,最终学会如何保护自身——这一基本框架适用于机器人技术、边缘计算、企业计算以及几乎所有领域,”Huang 表示。
CrowdStrike also announced Falcon IQ. NVIDIA Nemotron models help to power the agentic engine at the heart of Charlotte AI AgentWorks, CrowdStrike’s no-code agent development platform where Falcon IQ runs.
CrowdStrike 还宣布了 Falcon IQ。NVIDIA Nemotron 模型有助于驱动 Charlotte AI AgentWorks 核心的代理引擎,Falcon IQ 正是在 CrowdStrike 的无代码代理开发平台 Charlotte AI AgentWorks 上运行。
Falcon IQ uses more than 50 agents working together as a unified agentic workforce to automate the most time-intensive workflows in assessment, prioritization and remediation.
Falcon IQ 利用 50 多个代理作为统一的代理劳动力协同工作,自动化评估、优先级排序和修复中最耗时的工作流程。
Partners use Falcon IQ to deliver customized findings, recommendations and executive outputs to customers. Charlotte AI AgentWorks enables every Falcon user to build their own agentic security workforce.
合作伙伴使用 Falcon IQ 向客户提供定制化的发现结果、建议和高管报告。Charlotte AI AgentWorks 使每位 Falcon 用户都能构建自己的代理安全劳动力。
The Full Stack
全栈
CrowdStrike has thousands of customer organizations generating trillions of daily security events.
CrowdStrike 拥有成千上万的客户组织,每天产生数万亿条安全事件。
With NVIDIA’s full-stack accelerated computing platform, the collaboration runs from the chips up through the models to the harnesses acting on what those models find. For Kurtz, that’s the point.
借助 NVIDIA 的全栈加速计算平台,此次合作从芯片一直延伸到模型,再到作用于模型发现结果的代理框架。对 Kurtz 来说,这就是关键点所在。
“The crowd in CrowdStrike,” Kurtz added, “is the asymmetry that puts the defenders in a unique position to defeat the adversary.”
“CrowdStrike 中的‘众’(crowd),”Kurtz 补充道,“是一种不对称优势,使防守方处于击败对手的有利地位。”
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力