Google Gemini 3.8 Flash & Cyber: What’s New

Source: Google Blog: Gemini Models

Google has introduced Gemini 3.8 Flash and Gemini 3.8 Flash Cyber, marking its third Flash release in six weeks following Gemini 3.7 Flash. Built on an upgraded reasoning foundation, the new lineup focuses on autonomous software engineering and specialized cybersecurity defense while maintaining introductory pricing of $0.75 per million input tokens and $3.75 per million output tokens.

Gemini 3.8 Flash and 3.8 Flash Cyber by Google DeepMind
Gemini 3.8 Flash and Flash Cyber: Performance models tailored for software engineering and defensive cybersecurity

The release is divided into two distinct variants:

  • Gemini 3.8 Flash: Google’s primary workhorse model for complex programming, multi-step reasoning, and long-running autonomous agent loops.
  • Gemini 3.8 Flash Cyber: A specialized defensive model trained specifically for vulnerability discovery and automated patch generation, available to verified defenders through Google’s Fairwind Program.

Gemini 3.8 Flash: long-horizon coding and agentic workflows

Gemini 3.8 Flash changes how the model allocates compute during inference. On demanding tasks, it demonstrates greater diligence: performing extra verification steps, looping through tools iteratively, and evaluating its own reasoning traces recursively before delivering an answer.

Gemini 3.8 Flash benchmark evaluation comparison
Comprehensive benchmark results comparing Gemini 3.8 Flash with predecessor models and commercial competitors

On the DeepSWE v1.1 benchmark for long-horizon software engineering, 3.8 Flash solves complex codebase issues autonomously end-to-end, outperforming several larger, higher-priced frontier models:

DeepSWE v1.1 Software Engineering performance curve
DeepSWE v1.1 evaluation: Autonomous resolution of real-world software engineering issues

In quantitative and professional analysis, 3.8 Flash leads on specialized industry benchmarks, including the Vals Finance Agent V2 financial analysis benchmark and Harvey’s Legal Agent Benchmark. It also achieves 54.9% on HLE-Verified (Humanity’s Last Exam), confirming its ability to sustain multi-step logical chains across science, mathematics, and professional domains.

Interactive application demos in Google Antigravity and AI Studio

Google demonstrated the model’s single-prompt prototyping capabilities across four real-world showcases:

Chronomancers: A playable 3D dungeon puzzle game built via a single looping prompt in Google Antigravity with Nano Banana textures.

DOS Maps: A fully functional retro DOS port of Google Maps built in Google Antigravity, featuring interactive search, route navigation, and ASCII street views.

Real-time topographic map visualizer in Google Antigravity rendering cross-sections and scientific data from U.S. Geological Survey datasets.

Hardware Anatomy: An interactive 3D Three.js visualizer in Google AI Studio generating physically proportioned teardowns with explosion sliders.

Gemini 3.8 Flash Cyber: frontier defensive cybersecurity

Alongside general-purpose coding, Google introduced Gemini 3.8 Flash Cyber, engineered to assist software defenders, security researchers, and system maintainers in securing large-scale codebases.

Official release overview: Gemini 3.8 Flash Cyber and its role in proactive automated defense.

Autonomous vulnerability discovery

On the industry standard CyberGym benchmark, Gemini 3.8 Flash Cyber surpasses previous security models as well as larger general frontier systems:

CyberGym benchmark evaluation for Gemini 3.8 Flash Cyber
CyberGym evaluation: Pass@1 autonomous vulnerability detection rate

In Google’s internal multi-language benchmark spanning 20 programming languages, 3.8 Flash Cyber achieved a vulnerability detection success rate exceeding 70%:

Real-world multi-language vulnerability discovery
Real-world evaluation across 20 languages: Vulnerability identification success

Automated patch generation

Rather than focusing on attack vectors, Google deliberately trained 3.8 Flash Cyber on vulnerability remediation. On CWE-Bench, an external leaderboard benchmark run by Collinear that evaluates automated patching quality, the model achieves a 47.2% Pass@1, matching top frontier systems (47.8%) at substantially lower compute costs:

CWE-Bench automated patching Pass@1 vs Cost
CWE-Bench leaderboard: Automated patching accuracy plotted against cost per rollout

Production deployment inside Google and partner testing

Google has already integrated 3.8 Flash Cyber into its internal security pipelines:

  • Google Chrome Security: The Chrome team reported that 3.8 Flash Cyber generated 2.6 times more correct security patches for Chrome issues than significantly larger commercial models.
  • Wiz: Evaluated the model on internal penetration testing benchmarks, recording 7.5% to 9.7% higher recall at 2.3 to 5.2 times lower cost compared to other frontier systems.
  • Google Cloud Vulnerability Research: Discovered a critical foundational infrastructure vulnerability in under two hours, a process that typically requires months of manual auditing.
  • Industry Feedback: Security leadership from Palo Alto Networks, Snowflake, and Armadin reported significant acceleration in automated threat mitigation and remediation workflows.

Safety controls and prompt injection defense

Both models adhere to Google’s Frontier Safety Framework, incorporating safeguards against Chemical, Biological, Radiological, and Nuclear (CBRN) risks as well as offensive weaponization. Gemini 3.8 Flash Cyber provides more permissive capabilities strictly to vetted defenders under the Fairwind Program.

On prompt injection resilience evaluated by Gray Swan, Gemini 3.8 models demonstrated a notable improvement, resisting adversarial indirect prompt injection attacks:

Gray Swan indirect prompt injection resilience benchmark
Gray Swan benchmark: Robustness against adversarial indirect prompt injections

Pricing, specifications, and platform availability

Parameter Gemini 3.8 Flash Gemini 3.8 Flash Cyber
Input Pricing $0.75 per 1M tokens (introductory) Fairwind Program access tier
Output Pricing $3.75 per 1M tokens (introductory) Fairwind Program access tier
Primary Focus Software engineering, agentic loops, reasoning Vulnerability auditing, automated patching
Supported Environments AI Studio, Antigravity, Android Studio, Sheets Fairwind defensive partner portal
Safety Clearance General public access Vetted defenders and infrastructure teams

Developers can access Gemini 3.8 Flash directly through the Gemini API in Google AI Studio, build native applications via Android Studio, or generate interfaces with Stitch. Complete API technical guides and parameters are detailed in the official Gemini API developer documentation.

For organization-level workflows, enterprises can deploy the model via the Gemini Enterprise Agent Platform. End users and consumers can use 3.8 Flash inside the Gemini web and mobile apps, AI Mode in Google Search, and Google Sheets with Google AI Pro or Ultra plans. Defense teams, government entities, and infrastructure maintainers can request access to Gemini 3.8 Flash Cyber by applying to the Fairwind Program.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top