New AI security benchmark: Backbone breaker release

Check Point and Lakera have launched the b3 benchmark to enhance LLM security in AI agents, promising improved security measures for developers.

  • Wednesday, 29th October 2025 Posted 7 months ago in by Aaron Sandhu

Check Point Software Technologies Ltd., a global leader in cyber security solutions, has teamed up with Lakera to launch the backbone breaker benchmark (b3). Developed in collaboration with researchers from the UK AI Security Institute, this open-source security evaluation is specifically designed to enhance the security of large language models (LLMs) within AI agents.

The b3 introduces a novel approach known as threat snapshots. Rather than simulating the entire life cycle of an AI agent, threat snapshots focus on critical junctures where vulnerabilities are apt to occur. This targeted testing strategy allows developers to gauge the resilience of their models against real-world adversarial challenges, devoid of the complexities involved in modelling complete agent workflows.

Mateo Rojas-Carulla, Co-Founder and Chief Scientist at Lakera, expressed, "Threat Snapshots allow us to systematically surface vulnerabilities that have until now remained hidden in complex agent workflows. By making this benchmark open to the world, we hope to equip developers and model providers with a realistic way to measure and improve their security posture."

The benchmark consists of 10 representative agent "threat snapshots" and utilises a comprehensive dataset that features over 19,000 adversarial attacks sourced from the gamified Gandalf: Agent Breaker simulator. This ensures robust testing against varied forms of cyber threats, including system prompt exfiltration, phishing, and malicious code injection.

Initial assessments conducted on 31 popular LLMs have unveiled crucial insights: while enhanced reasoning capabilities tend to bolster security, the model size itself doesn't necessarily influence security performance. Notably, closed-source models generally demonstrate superior security, although leading open-source models are swiftly catching up.

The backbone breaker benchmark is available under an open-source license, providing developers worldwide with an invaluable tool for fortifying AI security. Originally an internal hackathon project at Lakera, the Gandalf: Agent Breaker game has evolved into the world's foremost red teaming platform. This hacking simulator challenges users to test AI agents within realistic scenarios, encouraging a deeper understanding of potential vulnerabilities in GenAI applications.

Since its inception, Gandalf has generated over 80 million data points, rapidly expanding the global red teaming community. Though initially crafted as a playful endeavor, Gandalf's mission remains serious: to raise vital awareness about AI-first security and the inherent challenges posed by GenAI technology.

Jamf survey highlights emerging challenges as AI adoption deepens across organisations, underscoring the growing need for effective governance to...
Smartsheet integrates AI capabilities with major platforms, supporting enterprise teams in work management and data-driven insights.

Understanding the evolving landscape of cyber threats

Posted 3 days ago by Sophie Milburn
The latest insights from Check Point Software highlight the persistent cybersecurity challenges faced globally, amid evolving threats and...

Inforcer expands with Threat Detection and Response

Posted 1 week ago by Sophie Milburn
inforcer launches its latest solution to provide complete threat detection and response, aiming to strengthen security for Managed Service Providers.
Keepit earns top marks in SaaS backup and recovery, helping demonstrate customer satisfaction and secure data handling globally.
CyberSmart's latest findings reveal an increasing focus on third-party risk, with MSPs facing new challenges amid regulatory changes.
New capability aims to improve visibility, monitoring, and control of AI agents in enterprise environments as organisations increasingly adopt...
Hack The Box and Semperis form an alliance to strengthen cybersecurity through hands-on skills development and identity security strategies.