Google has been investing in cybersecurity for years, pioneering automatic vulnerability detection to secure the world’s codebases. Tools like CodeMender, our code security agent, can automatically find and fix critical software vulnerabilities. However, as AI agents become increasingly capable of finding vulnerabilities faster than defenders can fix them, addressing this global threat requires a highly productive, low-cost, and scalable approach.
Today, we are expanding our multi-year efforts to better prepare defenders with the launch of Gemini 3.5 Flash Cyber, our lightweight cybersecurity model built on Flash 3.5 and optimized to quickly and efficiently find, inspect and patch vulnerabilities, making it more effective at these tasks than Gemini’s mainstream Flash models.
Flash’s performance and effectiveness make it an ideal foundation for our cybersecurity model efforts. Based on Flash technology, 3.5 Flash Cyber provides a cost-effective and high-performance alternative to huge, costly cybersecurity models.
Given the dual nature of this technology, we have taken a deliberate approach to how we deploy version 3.5 of Flash Cyber. As a limited-access pilot program, version 3.5 of Flash Cyber will soon be available exclusively to governments and trusted partners through CodeMender, with expansions over time. This will give frontline defenders an advantage in finding and remediating critical vulnerabilities before they can be exploited, while protecting against broader abuses.
Separately, we also make core CodeMender capabilities available directly to customers with generally available Gemini models via Gemini Enterprise agent platform.
The search space problem: the advantage of lightweight models in code security
Finding deep-seated errors requires exploring a huge search space. Relying on a single, costly call to a huge language model can create a bottleneck. 3.5 Flash Cyber is particularly useful for finding vulnerabilities when an agent needs to scan a huge code base and analyze a huge number of code paths.
CodeMender calls Flash Cyber 3.5 multiple times, allowing agents to analyze many more code paths to detect and check for vulnerabilities. The sub-agents then produce a single, high-quality report.
Thanks to its speed and affordability, 3.5 Flash Cyber can be easily integrated into regular scans, time-sensitive launch processes, or large-scale scan pipelines.
3.5 Flash Cyber Benchmark Results: An Effective Alternative to Larger Cybersecurity Models
We tested 3.5 Flash Cyber in various benchmarks. Specifically, we tested version 3.5 of Flash Cyber on the CyberGym benchmark, which evaluates AI agents for hundreds of real-world software vulnerabilities. By leveraging the low cost of 3.5 Flash Cyber by configuring CodeMender to invoke 3.5 Flash Cyber up to five times for a single final report, the agent achieved overall performance competitive with much larger models in CyberGym*.
