マイクロソフト、サイバーセキュリティ特化モデルを導入
マイクロソフトがサイバーセキュリティ分野に特化した新しいAIモデルの導入を発表した。
AI深層分析を開く2026年7月28日 23:38
AI深層分析
キーポイント
専用セキュリティモデルの導入
Microsoft は MAI-Cyber-1-Flash というコンパクトなコード重視モデルを新設し、全タスクの約 90% を処理して高コストな大規模モデルへの負荷を軽減する戦略を採用した。
MDASH システムのパフォーマンス向上
MAI-Cyber-1-Flash と GPT-5.4 などの大規模モデルを組み合わせることで、CyberGym ベンチマークで Mythos を上回る 96% のスコアを達成し、コストは約 50% 削減した。
自律型セキュリティシステムの発表
Perception と名付けた新しい自律型セキュリティシステムを導入し、チームが常時監視やパッチ適用を行うためのエージェント群を MDASH 環境で提供開始した。
重要な引用
Security is an always-on mission, and given the enormous volume of inbound attacks, token cost is now the real constraint for defenders.
The result is that the unified system of MDASH with MAI-Cyber-1-Flash delivers 96% on CyberGym (+12 pt above Mythos).
This combination delivers a 50% cost saving when compared against our best offering in MDASH today.
編集コメントを表示
編集コメント
トークンコストの最適化とタスク別モデル割り当てという、実運用における課題に直結するアプローチが示された。特に、Microsoft が持つ独自のセキュリティデータ資産を基盤とした自律型システムの発表は、業界標準の進化を示唆している。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
タスクに最適なモデルを選ぶ
セキュリティ対策は常時継続されるミッションです。膨大な量の侵入攻撃が押し寄せる中、今や守る側にとっての最大の制約はトークンコストとなっています。
「MAI-Cyber-1-Flash」は、全タスクの最大 90% を効率的に処理できるように設計されました。これにより、MDASH システムでは、GPT-5.4 のように規模が大きくコストも高いモデルを、本当に必要となる例外的に困難な 10% のタスクに集中して活用できます。
その結果、MAI-Cyber-1-Flash を統合した MDASH システムは、CyberGym で96%というスコアを達成しました。これは「Mythos」を上回る12 ポイントの差です。
この組み合わせにより、MDASH 現在のベストな提供モデル(GPT 5.4 + 5.4 mini + 5.3 codex)と比較して、コストを 50% 削減できます。これは、独自に豊富な歴史学習データを活用した、よく調整されたマルチモデル・システムの威力です。あらゆるタスクに対して、最適なモデルを最良の価格で常に提供できることを保証します。
こうした新しい環境において、脆弱性の特定からリアルタイムでの対応までを一貫して行える能力は極めて重要です。AI によるソフトウェア脆弱性への自動修復がセキュリティワークフローの重要な要素となった今でも、多くの業務はセキュリティ専門家自身が手掛ける必要があります。
そのため、本日私たちは Perception の公開を開始します。これはアジェンシー型セキュリティシステムであり、MDASH における多様なセキュリティワークフローのためにチーム型のエージェントを提供し、新たな脅威ベクトルを継続的に監視・パッチ適用・封鎖するものです。また、Perception はまもなく MAI-Cyber-1-Flash を活用し、ソフトウェア脆弱性対策以外の幅広いセキュリティワークフローでもその能力を発揮します。
今日重要なのは 3 つの要素です。モデル、データ、そしてハルネス(制御基盤)です。
私たちは世界最高水準のモデル、歴史的に類を見ない膨大なデータ、そして専門家によって微調整されたハルネスを統合的に最適化しました。これにより、お客様には他では得られない強力なセキュリティソリューションを提供できるのです。
モデル。 MAI-Cyber-1-Flash は、MAI-Thinking-1 シリーズから派生したコンパクトでコード処理に特化したセキュリティモデルです。この基盤となる MAI-Thinking-1 は、最高品質のデータを用いてゼロから自社開発されました。詳細は 技術レポート をご覧ください。
データ。 これが私たちの最大の強みです。世界最高水準のセキュリティシステムを数十年にわたり構築してきた経験により、ID(アイデンティティ)、エンドポイント、クラウド、ネットワーク全体で毎日兆単位の信号を取得しています。また、実際の攻撃事例と対策実績についても他社が追従できない記録を持っています。この歴史は誰にも模倣できません。
Harness. MDASH は、業界をリードするセキュリティ専門家によって最適化された、マルチエージェント型の脆弱性特定・修復ハッチです。このシステムでは、複数の主要モデルを活用した 100 以上のエージェントが構築され、脆弱性の発見から検証、修正までを一貫して担います。エージェントによるコードスキャンは「セキュリティ運用センター」の中核機能であり、Microsoft が新たに発表したエージェント型セキュリティシステム「Project Perception」へと情報を供給する重要な役割を果たしています。
安全性を最優先に設計
MAI-Cyber-1-Flash は Microsoft 初のサイバーモデルであるため、信頼性を高める仕組みをシステムのあらゆる層に組み込みました。モデルの訓練から顧客への展開に至るまで、セキュリティファーストの観点で厳格な調整が行われています。Microsoft の AI レッドチームによる徹底的な評価に加え、自動化されたテストや専門家主導のアダプティブ攻撃演習を通じた検証、さらに第三者機関による独立した評価も実施済みです。
信頼性はモデル自体だけにとどまりません。MDASH を通じて顧客は、ロールベースのアクセス制御、テナント間の完全な分離、暗号化、監査機能、そしてインターネット接続を遮断したサンドボックス環境など、エンタープライズレベルの管理機能を享受できます。その結果、Microsoft が企業に約束するガバナンス、セキュリティ、コントロールを維持しつつ、防御チームに対して強力な能力を提供できるサイバーモデルが実現しました。
ヒルクライミング型の機械
サイバーセキュリティは単にデータが豊富な分野ではありません。それは、生きた強化学習のループそのものです。
毎日、防御チームは脅威の調査、アラートの優先順位付け、敵対者の追跡、脆弱性の修正、保護策の展開を行い、その結果から学びます。
マイクロソフトはこのループを包括的に把握しています。Microsoft Security Response Center(MSRC)を通じた脆弱性情報、ID、エンドポイント、クラウド、データ、ブラウザ、アプリケーション全体にわたる攻撃と防御、そして毎日 100 兆件を超えるセキュリティ信号です。さらに、160 万社もの顧客からの運用上の洞察も得ています。
何が利用可能だったのか、何が封じ込められたのか、何がブロックされたのか、実際に効果があったのは何か——こうした行動とその結果を結びつけることができるため、私たちは単なるデータの蓄積を超えた価値を持っています。
私たちの MAI(Microsoft AI)による強化学習のループは、継続的に改善し、熟練したサイバー防御者へと成長するモデルを構築するための基盤となります。これが、今後数年にわたって顧客に対して約束し続ける姿勢です。
原文を表示
Picking the right model for the task
Security is an always-on mission, and given the enormous volume of inbound attacks, token cost is now the real constraint for defenders. MAI-Cyber-1-Flash was designed to efficiently handle up to 90% of all tasks, enabling MDASH to use the larger and most costly models in our fleet (in this case GPT-5.4) for the 10% of exceptionally hard tasks that truly need them.
The result is that the unified system of MDASH with MAI-Cyber-1-Flash delivers 96% on CyberGym (+12 pt above Mythos).
This combination delivers a 50% cost saving when compared against our best offering in MDASH today (GPT 5.4 + 5.4 mini + 5.3 codex). That’s the power of a well-tuned, multi-model system with access to uniquely rich historical training data. It ensures you always have the best model at the best price for every task.
In this new environment, being able to go from identifying a new vulnerability to addressing it in real-time is critical. And while AI remediation of software vulnerabilities is now a key security workflow, there are many jobs to be done by Security practitioners themselves.
That’s why today we’re also launching Perception, our agentic security systems, that provides teams of agents for a variety of security workflows in MDASH, to continuously monitor, patch, and close new threat vectors. Perception will also soon use MAI-Cyber-1-Flash for many more security workflows, beyond the software vulnerability work.
Three things matter today: Model. Data. Harness.
We have jointly optimized our world-class models, our unmatched historic data, and our expert-tuned harness to ensure that our customers have a uniquely powerful security offering.
Model. MAI-Cyber-1-Flash is a compact, code-heavy security model derived from the MAI-Thinking-1 lineage, which was built from scratch, in-house, on the highest quality data. Details in our technical report.
Data. Our deepest advantage. Decades of building world-class security systems now give us trillions of daily signals across identity, endpoint, cloud, and network, and an unmatched record of real exploits and remediations. No one can manufacture this history.
Harness. MDASH, our multi-agent vulnerability identification and remediation harness, is tuned by the best security experts in the industry, who have created 100+ agents using multiple leading models to find, validate, and remediate vulnerabilities. Agentic code scanning is a critical function in the Security Operating Center and feeds Project Perception, our new agentic security system.
**Built with safety first
**
Because MAI-Cyber-1-Flash is Microsoft’s first cyber model, we built trust into every layer of the system, from model training to customer deployment. The model was developed with a security-first calibration, rigorously evaluated by Microsoft’s AI Red Team, tested through automated and expert-led adversarial exercises, and independently assessed by a third party.
Trust extends beyond the model itself. Through MDASH, customers get enterprise-grade controls including Role-Based Controls, tenant isolation, encryption, auditability, and sandboxed execution environments with no internet access. The result is a cyber model that delivers powerful capabilities to defenders while maintaining the governance, security, and control enterprises expect from Microsoft.
Our hill-climbing machine
Cybersecurity is not just a data-rich domain; it is a live reinforcement learning loop. Every day, defenders investigate threats, triage alerts, hunt adversaries, remediate vulnerabilities, deploy protections, and learn from the outcome.
Microsoft sees that loop end to end: vulnerabilities through Microsoft Security Response Center; attacks and defenses across identity, endpoint, cloud, data, browser, and applications; more than 100 trillion security signals every day; and operational insight from 1.6 million customers. Because we can connect actions to outcomes; what was exploitable, what was contained, what was blocked, and what actually worked; we have more than data.
Our MAI reinforcement learning loop gives us the foundation to build cyber models that improve continuously and become expert cyber defenders. That’ll remain our commitment to our customers for years to come.
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み