Skip to content

Using the Cyber Model

Sec-Gemini supports the Gemini 3.8 Flash Cyber model (gemini-3.8-flash-cyber), a specialized variant of Gemini 3.8 Flash post-trained specifically for offensive and defensive cybersecurity tasks—including binary reverse engineering, malware analysis, deobfuscation, vulnerability triage, and forensic artifact analysis.

This guide explains how the cyber model works, environment and quota availability, the automatic air-gapped internet isolation policy enforced whenever it is active, and how to select it across the Web UI, TUI, CLI, Python SDK, and environment variables.


gemini-3.8-flash-cyber is fine-tuned to excel at security workflows:

  • Significantly Reduced Refusals: Pre-trained and fine-tuned on dual-use security research tasks (e.g. examining disassemblies, analyzing malicious binaries, generating defensive signatures, inspecting payload mechanics) with minimal false-positive safety refusals.
  • Fast Execution: Built on the Gemini 3.8 Flash architecture for high-throughput, low-latency agent iteration and multi-step tool loops.
  • Role Fan-Out: When selected, the model can power the main agent loop (fast_model), reviewer/reflection agents (escalation_model), and refusal retries (refusal_retry_model).

The Cyber model is a specialized internal model governed by Vertex AI project allowlisting:

  • Internal Environments: Quota is provisioned and available in internal Sec-Gemini environments:
    • powernine-dev (development)
    • powernine-prod-internal (internal dogfood & production)
    • Corp Run internal deployments (internal-ui.secgemini.corp.goog, internal-api.secgemini.corp.goog)
  • Public Production: The public production project (powernine-prod, serving ui.secgemini.google) does not have quota and is deliberately excluded from the allowlist.
  • Fast-Fail Behavior: If a request specifying gemini-3.8-flash-cyber is sent against powernine-prod or an unauthorized GCP project, the system fails fast with a clear error (404 NOT_FOUND ... was not found or your project does not have access to it). There is no silent fallback to default models, ensuring reproducibility during benchmark evaluations and research runs.

Whenever any agent role (fast_model, escalation_model, or refusal_retry_model) is configured to use a cyber model (any model name containing "cyber"), Sec-Gemini automatically and non-bypassably enforces complete internet isolation.

This defense-in-depth isolation prevents accidental network callbacks, beaconing, or data leakage while analyzing untrusted samples:

1. Security Policy Enforcement (default-deny-internet-access)

Section titled “1. Security Policy Enforcement (default-deny-internet-access)”
  • An organizational security policy (default-deny-internet-access, Priority 700) is automatically activated in enforce mode.
  • Non-bypassable: It cannot be disabled, downgraded to audit, or bypassed by client parameters (active_policy_ids).
  • Blocked Operations:
    • Outbound HTTP and TCP connections (http.host != "").
    • Web search tools (mcp_search).
    • Headless browser automation (mcp_chrome).
    • Live network probing tools in mcp_network.
  • Preserved Offline Tools:
    • Offline packet capture (PCAP) inspection tools remain fully operational: sandbox_network_triage_pcap, sandbox_network_extract_pcap_credentials, sandbox_network_filter_pcap_packets, and sandbox_network_extract_pcap_streams.
    • Local terminal, sandbox file operations, decompilation, disassembly, and local static analysis continue without restriction.

2. Sandbox Kernel Network Namespace Isolation

Section titled “2. Sandbox Kernel Network Namespace Isolation”
  • Within the sandbox environment (mcp_sandbox_env), the session policy engine detects default-deny-internet-access.
  • The execution sandbox enables strict Linux network namespace isolation (nsjail clone_newnet: true), ensuring that sandbox processes have no network interfaces or route to the internet.

In the Sec-Gemini Web UI (on internal or local instances):

  1. New Session Menu: Next to the prompt input at the bottom of the new session screen, click the + (Add files or select mode) button.
  2. Toggle Cyber Model: Click Cyber model (shield icon).
    • An active chip [Cyber model (x)] will appear next to the + button.
    • To disable before submitting, click the × on the chip or click Cyber model in the menu again.
  3. Submit Prompt: Enter your prompt and click Send. The session will be created with config.model: "gemini-3.8-flash-cyber".
  4. Session View:
    • The session header displays a Cyber model shield badge indicating the session is running on the cyber model with air-gapped isolation.
    • Follow-up turns in the same session automatically retain the Cyber model and internet isolation policy.

Note: On public production deployments (ui.secgemini.google), the Cyber model option is automatically hidden from the menu.


You can select the Cyber model either from the command line or from within the TUI interface:

Launch the TUI with the --model flag:

Terminal window
sec-gemini --model gemini-3.8-flash-cyber

This pre-selects gemini-3.8-flash-cyber in the New Session model dropdown.

  1. On the New Session screen, navigate to the Model dropdown (next to the Harness picker).
  2. Select gemini-3.8-flash-cyber.
  3. Create your session.

The sec-gemini CLI supports --model on all primary commands:

Terminal window
sec-gemini --model gemini-3.8-flash-cyber
Terminal window
sec-gemini run --model gemini-3.8-flash-cyber "Analyze the decompiled functions in sample.c for vulnerabilities"

Digital Forensics & Incident Response (dfir)

Section titled “Digital Forensics & Incident Response (dfir)”
Terminal window
sec-gemini dfir --model gemini-3.8-flash-cyber "Analyze the memory dump for injected DLLs"

If you want to configure specific agent roles separately:

Terminal window
sec-gemini run \
--fast-model gemini-3.8-flash-cyber \
--escalation-model gemini-3.8-flash-cyber \
"Perform static analysis on payload.bin"

When using the sec-gemini Python SDK, pass the model in the session metadata using MODEL_META_KEY:

import asyncio
from sec_gemini import SecGemini
from sec_gemini.constants import CYBER_MODEL, MODEL_META_KEY
async def main():
async with SecGemini() as client:
session = await client.sessions.create()
# Pass the cyber model shortcut in the prompt metadata
await session.prompt(
"Decompile and analyze suspicious_binary.exe",
meta={MODEL_META_KEY: CYBER_MODEL},
)
async for msg in session.messages.stream():
if msg.get("message_type") == "MESSAGE_TYPE_RESPONSE":
print(msg.get("content", ""))
asyncio.run(main())

You can also specify individual roles in metadata:

meta = {
"config.fast_model": "gemini-3.8-flash-cyber",
"config.escalation_model": "gemini-3.8-flash-cyber",
"config.refusal_retry_model": "gemini-3.8-flash-cyber",
}

5. Environment Variables (Self-Hosted / Local Stack)

Section titled “5. Environment Variables (Self-Hosted / Local Stack)”

For local development or self-hosted worker deployments (e.g. local_services/docker-compose.yml), you can set default models across all sessions via environment variables:

Environment Variable Description
SEC_GEMINI_MODEL Shortcut: Sets fast_model, escalation_model, and refusal_retry_model simultaneously
SEC_GEMINI_FAST_MODEL Model for the main agent loop (planner, executor, responder)
SEC_GEMINI_ESCALATION_MODEL Model for reflection, review, and failure escalation
SEC_GEMINI_REFUSAL_RETRY_MODEL Model for refusal recovery re-prompts

Example:

Terminal window
export SEC_GEMINI_MODEL="gemini-3.8-flash-cyber"
sec-gemini

When multiple methods specify models, Sec-Gemini resolves them in the following order (highest precedence first):

  1. Per-role prompt metadata: config.fast_model, config.escalation_model, config.refusal_retry_model (e.g. CLI flags --fast-model, --escalation-model).
  2. Model shortcut metadata: config.model (e.g. Web UI toggle, CLI flag --model, TUI dropdown, SDK MODEL_META_KEY).
  3. Constructor arguments: Config(fast_model=...).
  4. Mode profile pins: e.g., dfir.toml defaults.
  5. Environment variables: SEC_GEMINI_*_MODEL overrides SEC_GEMINI_MODEL.
  6. Built-in defaults: DEFAULT_FAST_MODEL (gemini-3.8-flash), DEFAULT_REFUSAL_RETRY_MODEL (gemini-3.1-pro-preview).

To confirm that a session is using the Cyber model and that air-gapped isolation is active:

  1. Web UI: Check the session header bar for the Cyber model shield chip.
  2. Session Metrics / API: Inspect the session document meta or sessionMetrics for config.model: "gemini-3.8-flash-cyber" and isCyberModel: true.
  3. Security Policies: Open the Security policies panel in the Web UI or inspect session policies via SDK/CLI. The default-deny-internet-access policy will be marked as Enforced and active. Attempts by the agent or tools to contact external network addresses will be logged as blocked violations.