September 28, 2026 – Alibaba’s Fuyuan Xirang large model (XekRung-27B) has claimed the top spot on CyberGym with an 88.9% success rate, becoming the first Chinese model in the history of this internationally authoritative AI security benchmark to take the championship.
While achieving the highest success rate, Fuyuan Xirang also made a breakthrough in being “small yet powerful.” Its 27 billion parameters are only 1/27 to 1/370 of other models on the list, meaning this “small but mighty model” significantly reduces the computing power costs of intelligently identifying security vulnerabilities.
CyberGym is currently one of the most authoritative AI security capability benchmarks internationally. It is operated by a professional research team from the University of California, Berkeley, and is backed by an AI security benchmark testing framework covering 1,507 real security vulnerabilities across 188 software projects.
The CyberGym leaderboard is divided into two parts: the Model Leaderboard and the Agent Leaderboard. The Model Leaderboard uses only a general Harness, without fixed stages or any external tools and knowledge bases, more purely reflecting the model’s security intelligence level. Alibaba topped the Model Leaderboard this time.

On the latest CyberGym Model Leaderboard, Alibaba’s Fuyuan Xirang large model (XekRung-27B) ranked first with an 88.9% success rate. The models ranked second through fifth were developed by Google, OpenAI, Zhipu, and DeepSeek, with success rates of 86.3%, 85.6%, 84.5%, and 83.3%, respectively.
According to Alibaba’s AI Governance Research Center official account, the Fuyuan Xirang large model is based on Alibaba’s self-developed Qwen3.8-27B multimodal large model. After security domain training and extreme intelligent compression, its 27 billion parameters are only 1/27 to 1/370 of comparable models such as GPT-5.5-Cyber and Claude Mythos.
This means the Fuyuan Xirang large model is “small yet powerful,” achieving ultimate cost-effectiveness. Using it to detect security vulnerabilities can greatly save computing power costs and help promote the democratization of security capabilities.
Huang Longtao, head of Alibaba Group’s Security AGI Lab, stated that AI has greatly improved system security detection rates and vulnerability discovery rates, becoming a key force in safeguarding digital world security. Building on this “security intelligence cost-effectiveness,” Fuyuan Xirang will continue to iterate and upgrade in areas such as adversarial intelligence, self-evolution, and Agentic capabilities.
He emphasized that Alibaba’s security capabilities adhere to both “self-protection” and “benefiting others.” The latest security technologies are not only meant to protect Alibaba’s own business but will also be made available to society through various means.
