Perturb AI’s network of incentivized hackers launches to attack AI models before criminals do

GlobeNewswire | Perturb AI
Today at 12:58pm UTC

Cover Image

SAN FRANCISCO, Aug. 28, 2026 (GLOBE NEWSWIRE) -- Perturb has launched a decentralized adversarial robustness network on Bittensor that continuously stress-tests production AI models and pays a global network of researchers to find vulnerabilities that in-house red teams may miss.

Five weeks after an experimental OpenAI model escaped its test environment and breached Hugging Face's production infrastructure, and days after OpenAI answered with tighter internal monitoring and stronger network isolation, Perturb is launching the network with a blunt premise: the only way to keep pace with AI capability is to attack AI models constantly, at scale, before someone else does.

Perturb is a decentralized adversarial robustness network built on Bittensor. A global subnet of incentivized miners continuously stress-tests AI models with black-box, white-box, and transfer attacks, returning three things to model owners: a robustness score, a vulnerability heatmap showing exactly where the model breaks, and hardening datasets ready to use for retraining.

OpenAI's measures to date are internal controls, and its full postmortem of the incident is still to come. Perturb's premise is that internal controls are the layer the incident defeated: a model's security is unknown until someone outside the building has tried to break it.

The economics invert the traditional security model. Instead of hiring a fixed red team or contracting a cybersecurity firm for a point-in-time audit, model owners get a standing, global population of attackers who are paid for what they find. Perturb positions the service as faster, more comprehensive, and more cost-effective than conventional security vendors, whose engagements can take weeks and reflect only the attack ideas of a single team.

All findings are handled under responsible disclosure: vulnerabilities are reported privately to the model's owner, and exploit details are not published.

"Every model in production today has vulnerabilities its builders have never seen, because no in-house team can think of everything," said Koyuki Nakamori, co-founder and CEO of Perturb. "The recent incidents are not anomalies. They are what it looks like when capability outruns testing. We built a network where thousands of incentivized attackers probe your model continuously, and every vulnerability they find is one a bad actor can't use."

An early version of the network is available to try at perturbai.io/playground.

About Perturb
Perturb is a decentralized adversarial robustness network built on Bittensor. Its global network of incentivized security researchers continuously attacks production AI models — black-box, white-box and transfer techniques, across text, image, audio and multi-modal systems — and is paid for the vulnerabilities it finds. Model owners receive a robustness score, a vulnerability heatmap showing where the model breaks, and hardening datasets ready for retraining. Perturb was co-founded by Koyuki Nakamori (CEO), Jeffrey Lamb (CTO) and Vadym Shakuro. Whitepaper and playground at perturbai.io.

Contact

Sam Allcock
sam@digital24.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/c8169181-d1f9-4c8e-b947-0abd07bc8fef


Primary Logo