Perturb, built on the Bittensor decentralised network, launched publicly on 27 August 2026. A global subnet of incentivised miners continuously stress-tests AI models using black-box, white-box, and transfer attacks. Model owners receive a robustness score, a vulnerability heatmap showing exactly where the model breaks, and hardening datasets ready for retraining.
The timing is deliberate. OpenAI's response to the Hugging Face breach concentrated on tighter internal monitoring and stronger network isolation. Perturb's premise is that internal controls were the layer the breach defeated: a model's security is unknown until someone outside the building has tried to break it.
The economics invert what conventional red-teaming costs. Instead of a fixed team or a point-in-time contract, model owners get a standing global population of attackers paid per vulnerability found. The company positions this as faster and more comprehensive than security vendors whose engagements can take weeks and reflect a single team's attack imagination.
All findings go through responsible disclosure: vulnerabilities are reported privately to the model's owner and exploit details are not published.
Koyuki Nakamori, co-founder and CEO, said: "Every model in production today has vulnerabilities its builders have never seen, because no in-house team can think of everything. The recent incidents are not anomalies. They are what it looks like when capability outruns testing. We built a network where thousands of incentivised attackers probe your model continuously, and every vulnerability they find is one a bad actor can't use."
An early version of the network is available at perturbai.io/playground. Perturb was co-founded by Nakamori, Jeffrey Lamb (CTO), and Vadym Shakuro.
To stay across the latest in cloud, AI and enterprise tech analysis from Compare the Cloud, subscribe to our weekly newsletter at https://www.comparethecloud.net/newsletter