
Cisco has released Antares, a pair of compact AI models purpose-built to locate vulnerabilities within codebases by learning to navigate repositories iteratively, much like a human security analyst. The models outperform larger competitors while remaining small enough to run locally, keeping sensitive source code on-premises—a critical advantage for universities, public institutions, and smaller security teams that lack resources for cloud-scale AI tools. Cisco also introduced a new benchmark to measure vulnerability localization specifically, stepping beyond general coding benchmarks that measure different tasks.
Summaries like this, in your inbox every morning.
Sign up free →What happened
Cisco introduced Antares, a family of small language models designed to pinpoint vulnerabilities in codebases. The company released Antares-350M and Antares-1B as open-weight models on Hugging Face, and benchmark testing shows these models outperform many larger closed- and open-weight models on vulnerability localization while running locally without sending sensitive code to the cloud.
Why it matters
Vulnerability triage is expensive and resource-intensive, especially for universities, nonprofits, public-sector teams, and smaller security organizations. Antares's compact size and low inference cost make AI-powered security analysis accessible to teams that previously lacked the resources for token-intensive models, potentially enabling continuous code scanning on every commit without requiring cloud infrastructure.
What to watch
Antares-3B is coming soon. The models are now available on Hugging Face, accompanied by a new 500-task Vulnerability Localization Benchmark, and Cisco is positioning this as part of a broader effort that includes Foundry Security Spec (open specifications for agentic security systems) and CodeGuard (secure coding guidance for AI agents).
Cisco today announced Antares, a family of security-focused small language models designed to solve one of cybersecurity's most expensive problems: locating known vulnerabilities within large codebases. The company is releasing two models immediately—Antares-350M and Antares-1B—as open-weight models on Hugging Face, with Antares-3B announced for future release. Benchmark testing demonstrates that these compact models outperform many larger closed- and open-weight models on vulnerability localization tasks while consuming a fraction of the computational cost and running entirely locally, allowing organizations to keep proprietary code within their own environment rather than sending it to external cloud services.
Vulnerability analysis traditionally demands expert effort, time, and infrastructure; repositories are typically large, security signals are noisy, and evidence is scattered across many files. Security analysts must search unfamiliar code, follow naming conventions, inspect call paths, and manually determine whether a weakness is genuinely present. This work is especially burdensome for universities, nonprofits, public-sector institutions, and smaller security teams operating under constrained budgets. Compact models solve two problems simultaneously: they reduce inference costs and enable on-premises or local deployment, making AI-assisted security practical for organizations that previously lacked resources for token-intensive approaches.
Antares works by following an iterative search pattern that resembles human vulnerability investigation. Starting from a vulnerability description, each model searches for relevant code patterns, reads candidate files, incorporates new evidence, revises its search strategy when a path proves unproductive, and progressively narrows toward the files most likely to contain the relevant vulnerability. The model outputs a ranked list of source files likely to contain a vulnerability alongside the terminal exploration trace showing how it arrived at that conclusion, allowing security teams to prioritize human review during advisory triage or CI/CD checks. Reza Shokri, Associate Professor of Computer Science at the National University of Singapore, noted that Antares-1B recognizes vulnerabilities across several weakness classes and languages, and the provided CLI packages the model's capabilities into a practical workflow for scanning codebases and integrating into automated pipelines. Amin Saberi, Professor of Management Science and Engineering at Stanford University, emphasized that Antares achieves near-frontier accuracy on secure code reasoning at a fraction of the cost and runs fast enough to operate on every code commit, making always-on security scanning feasible for resource-constrained teams.
Cisco also introduced the Vulnerability Localization Benchmark, a new 500-task benchmark specifically designed for this task. Existing coding benchmarks such as SWE-Bench Verified measure whether models can resolve software issues or find code relevant to development tasks, but they do not measure security-specific localization—identifying source files most likely to contain vulnerabilities given CWE-style descriptions or security advisories. This benchmark gap inspired Cisco to build both the Antares models and this new measurement standard, ensuring progress is quantifiable and reproducible. The release is part of a broader Cisco initiative to advance responsible and measurable AI in security, which also includes Foundry Security Spec (a model-agnostic blueprint for agentic security systems with clear roles, guardrails, and reviewable outputs) and CodeGuard (secure-by-default rules and skills guiding AI coding agents toward safer development). Together, these efforts aim to establish open specifications, reusable security knowledge, compact deployable models, and benchmarks that enable all security practitioners—regardless of on-premises requirements or resource constraints—to effectively incorporate AI into everyday security operations.
Cisco's Antares addresses a critical gap in AI-assisted security: existing coding benchmarks measure whether models can resolve software issues or assist development, not whether they can identify vulnerable files from security descriptions or CWE categories. This mismatch prompted Cisco to build both a specialized model family and a new 500-task Vulnerability Localization Benchmark, recognizing that security-focused localization requires different capabilities than general code search. The emphasis on compact, locally-deployable models reflects a practical reality—vulnerability triage demands keeping sensitive source code on-premises, and many organizations lack the resources to run token-intensive cloud-scale models for continuous scanning. By releasing these as open-weight and coupling them with open specifications (Foundry Security Spec) and secure coding guidance (CodeGuard), Cisco is positioning Antares as part of a broader ecosystem aimed at making AI-assisted defense accessible beyond well-funded enterprises. The iterative search pattern Antares employs—navigation, reflection, strategy revision, and backtracking—mirrors human investigator behavior, suggesting the company's goal is not replacement but acceleration of the triage process.
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytime
No comments yet. Be the first to share your thoughts!
Log in to join the discussion




Get curated AI news from 200+ sources delivered daily to your inbox. Free to use.
Get Started FreeFree · takes 30 seconds · unsubscribe anytime
1 minute a day. The AI essentials.
200+ sources · Email / LINE / Slack