Cisco’s Antares Models Challenge AI Giants in Hunt for Software Flaws

Cisco released Antares-350M and Antares-1B, small open-weight models that locate vulnerabilities in codebases faster and cheaper than Gemini or GPT systems. They run locally to protect proprietary code and access is gated to vetted security teams. The approach could broaden AI-driven defense without handing attackers new advantages.
Cisco’s Antares Models Challenge AI Giants in Hunt for Software Flaws
Written by John Marshall

Cisco just put two small open-weight AI models on Hugging Face. They find vulnerable spots in massive codebases faster and cheaper than far larger systems from Google and OpenAI. The release marks a shift. Security teams no longer need to ship proprietary code to the cloud or burn huge budgets on frontier models for basic triage.

The models, called Antares-350M and Antares-1B, come from Cisco’s Foundation AI team. A larger 3B version remains under tighter control for now. All three specialize in one task. Give them a description of a known vulnerability and access to a repository. They explore the code like a careful investigator, reading files, backtracking when paths go cold, and finally spitting out a ranked list of the files most likely to contain the flaw.

Results surprised even the researchers. On a new 500-task benchmark built from real GitHub Security Advisories, the 1B model posted a File F1 score of 0.209. That beat a 753-billion-parameter model from Z.ai’s GLM lineup, which scored 0.186. Cisco’s official blog post details how Antares-1B also outperformed Google’s Gemini 3 Pro while matching or exceeding other heavyweights in targeted tests. The withheld 3B version cleared the board against both GLM-5.2 and OpenAI’s GPT-5.5.

Speed tells an even sharper story. Antares scanned 500 repositories in 15 minutes. Frontier models needed five hours for the same work. Cost followed suit. The small models ran the job for less than a dollar. Bigger systems rang up between $100 and $150. “Antares clears 500 code repositories in 15 minutes, against five hours for frontier models. That works out at less than $1, versus $100 to $150 for the big systems,” said Amin Karbasi, Cisco’s chief AI scientist, in a report from The Register.

But here’s the twist. These models don’t chat. They don’t write code. They search. Cisco trained them from the start as specialized agents that navigate, reflect, and revise their path through unfamiliar territory. The approach draws from earlier Cisco research on compact models that learn to hunt needles in giant haystacks. The name Antares itself nods to a red supergiant star 1,000 times the size of the sun. One file hiding a critical bug can feel that outsized inside a million-line codebase.

Reza Shokri, a computer scientist at the National University of Singapore, put the broader stakes plainly. “AI agents now ‘write more of the code, and are growing capable of exploiting it.'” His comment, carried in both the original The Next Web coverage and Cisco’s announcement, captures the double-edged reality. Tools that locate flaws can also help attackers weaponize them. Cisco responded by gating access.

Only vetted academic researchers, nonprofits, and smaller public-sector security teams receive approval. Interested parties must apply through a contact form. The policy aims to stop the technology from becoming a luxury available only to the best-funded defenders while attackers freely adopt similar AI. “We’re making sure we’re gating that and appropriately granting access,” explained DJ Sampath, Cisco’s senior vice president and general manager of AI software, according to The Register. “You also need the keys to the source code… proprietary code never leaves… enables security analysis in strict environments.”

Running locally brings immediate practical wins. Banks, government agencies, and any organization under strict data-residency rules can analyze their own systems without sending snippets to distant APIs. The models operate through a simple terminal-based loop. They issue commands, read outputs, adjust strategy, and build an exploration trace alongside the final ranked list. Analysts still perform the heavy review. Yet the first pass through unfamiliar code drops from days to minutes.

Cisco stresses the models complement existing defenses. Dependency scanning, secret detection, dynamic testing, and human expertise remain essential. Antares simply accelerates the expensive, slow step of locating likely problem spots from a vulnerability advisory or CWE category. Early experiments on X show developers already wiring the models into local Ollama setups and read-only sandboxes that output SARIF-formatted results ready for CI/CD pipelines.

The accompanying technical report and new Vulnerability Localization Benchmark, both hosted on Cisco’s GitHub pages, give outsiders a clear view. The paper explains the training process and why small, focused models can outperform general-purpose giants on this narrow job. Stanford’s Amin Saberi called the results striking. “Antares’s results change that equation: near-frontier accuracy at a fraction of the cost… makes always-on security scanning possible.”

Industry reaction on X mixed excitement with caution. Several posts highlighted how a 350-million-parameter model beat much larger systems at spotting vulnerable files. Others noted the release lands amid growing worries about open-weight AI. Recent stories, including one from Ground News on OpenAI’s push for U.S. restrictions on powerful Chinese open models, show the tension. Cisco’s move offers a counterpoint. Open weights, when paired with strict access controls and local execution, could broaden access to strong defenses rather than widen the attack surface.

SecurityWeek picked up the story quickly, framing Antares as a low-cost option for source-code security that avoids cloud dependencies. Additional coverage from The Mosaic News and Veriwire emphasized the privacy angle and the models’ ability to run on single GPUs. None of these reports surfaced major new technical revelations beyond Cisco’s own disclosures. Yet together they signal genuine interest from both enterprise security teams and the wider AI community.

Karbasi offered a memorable analogy in The Register. Sometimes you don’t need a private jet to go to the corner store. A bicycle works fine and arrives quicker in city traffic. The biggest models aren’t always the right tool. For vulnerability localization, nimble, purpose-built agents appear to hold the edge.

Whether Antares sparks a wave of specialized security small language models remains to be seen. Cisco already ties the work to its broader Foundry Security Specification and CodeGuard efforts. The company wants measurable, governable AI systems that actually improve defense outcomes. For now, the 350M and 1B models sit on Hugging Face under Apache 2.0 for approved users. The 3B version waits in the wings.

One thing looks clear. The cost curve for AI-assisted code review just dropped sharply. Organizations that once dismissed automated triage as too expensive or too risky may take another look. And attackers? They will certainly study the same techniques. The advantage, as multiple experts noted this week, may lie less in model size than in who points the tool most effectively.

Subscribe for Updates

AISecurityPro Newsletter

A focused newsletter covering the security, risk, and governance challenges emerging from the rapid adoption of artificial intelligence.

By signing up for our newsletter you agree to receive content related to ientry.com / webpronews.com and our affiliate partners. For additional information refer to our terms of service.

Notice an error?

Help us improve our content by reporting any issues you find.

Get the WebProNews newsletter delivered to your inbox

Get the free daily newsletter read by decision makers

Subscribe
Advertise with Us

Ready to get started?

Get our media kit

Advertise with Us