Anthropic vs. AISLE: The AI Duel on Flaw Detection

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
Anthropic and AISLE: A Technological Confrontation on Mythos
The start-up Anthropic, known for its advancements in artificial intelligence, recently unveiled its Mythos model, touted for its ability to identify thousands of zero-day vulnerabilities. However, the cybersecurity firm AISLE has published an analysis that questions the uniqueness of Anthropic's results. According to AISLE, the same results can be achieved with open-source AI models, costing only $0.11 per million tokens, while Anthropic charges 240 times more.
On April 7, Anthropic launched Project Glasswing and Mythos Preview, promising a revolution in security flaw detection. On the same day, AISLE published an article titled "AI Cybersecurity After Mythos: The Jagged Frontier," authored by Stanislav Fort, a researcher at the company. The article claims that Anthropic's flagship tests can be replicated using open-source models such as Deepseek, Qwen, and GPT-OSS, which have between 3 and 5 billion active parameters. This revelation opens an interesting technical and commercial debate.
Open-Source Models Compete with Mythos
AISLE tested eight open-source AI models on the code of the vulnerabilities presented by Anthropic. All successfully detected the FreeBSD NFS exploit, considered Anthropic's most impressive demonstration. Among these models, one with 3.6 billion active parameters was priced at just $0.11 per million tokens. Another model, with 5.1 billion parameters, also identified a major bug in OpenBSD dating back 27 years, another key discovery from Anthropic.
In more general security reasoning tasks, smaller open-source models often outperform the cutting-edge models from large labs. According to AISLE, no AI dominates all tasks, making the frontier of cybersecurity capabilities "jagged." Since mid-2025, AISLE claims to have validated 180 CVEs, including 15 in OpenSSL and 5 in curl, highlighting the quality of its reports and its collaboration with major players like the CTO of OpenSSL.
The Debate on AI Model Power
AISLE raises a crucial question: is it the power of the AI model that makes the difference, or the surrounding detection architecture? Anthropic presents Mythos as an integrated solution capable of scanning, isolating, and exploiting vulnerabilities. AISLE, on the other hand, breaks this process down into distinct steps, asserting that modest models may suffice for scanning and detection, while complex exploitation remains a challenge.
This debate occurs in a commercial context where AISLE and Anthropic are in direct competition. AISLE promotes its agnostic pipeline as an effective alternative without requiring expensive models. Bruce Schneier, a cybersecurity expert, had already described Anthropic's announcement as a "public relations operation," emphasizing the need for caution regarding marketing claims.
The Limitations of AISLE's Counter-Test
It is important to note that AISLE's test does not cover the entirety of Anthropic's protocol, particularly the multi-vulnerability exploitation chains. AISLE focused on detecting known vulnerabilities without exploring large-scale discovery in pristine code. According to Anthropic, the strength of Mythos lies in its ability to orchestrate thousands of scans autonomously, an aspect that AISLE's test did not address.
In conclusion, the debate between the unique model and the agnostic architecture is just beginning. Definitive results will likely come from independent third parties, but in the meantime, the marketing discourse surrounding this confrontation continues to captivate the industry's attention.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.