Cisco releases Antares, open-weight small models for locating code vulnerabilities
Cisco Systems Inc. today introduced Antares, a family of small language models built to pinpoint where known security vulnerabilities sit inside a codebase, and released the first two as open-weight downloads on Hugging Face.
The models come from Cisco Foundation AI, the company’s research and engineering group focused on security-specific artificial intelligence. Antares targets vulnerability localization, the work of connecting external vulnerability data such as public databases, advisories and Common Weakness Enumeration entries to the specific files in a repository where a flaw is likely to live.
That step is one of the slower and more expensive parts of software security. Analysts have to search unfamiliar code, follow naming conventions, trace call paths and compare candidate files before deciding whether a weakness is actually present. Antares is designed to narrow that search.
Two models are available now, Antares-350M and Antares-1B, with a larger Antares-3B model due to follow. All are small enough to run locally, which lets security teams keep sensitive source code inside their own environment rather than sending it to a cloud service. Cisco is pitching that as a fit for universities, public-sector bodies, nonprofits and smaller security teams that lack the budget for token-heavy commercial models.
Rather than scan a repository with fixed rules, Antares works through it the way a human investigator would. Each model starts from a vulnerability description, searches for relevant code patterns, reads candidate files, folds in new evidence, changes direction when a path leads nowhere and narrows toward the files most likely to matter. The output is a ranked list of source files likely to contain the relevant vulnerability, along with the terminal exploration trace that produced it.
To measure the models, Cisco built its own test, the Vulnerability Localization Benchmark, a 500-entry set that requires a model to navigate an unfamiliar codebase and recognize vulnerability patterns tied to specific weakness categories. Existing code-search benchmarks measure whether an agent can find code relevant to a general software issue, the company said, not whether it can locate vulnerable files from security descriptions. The closest comparable work, a system called CodeScout, showed that code localization can be trained and measured with a standard Unix terminal.
On that benchmark, Cisco said the Antares models beat about a dozen larger open- and closed-weight models on accuracy while running far cheaper. The company put the cost of an Antares evaluation at under $1, against roughly $12.50 for the strongest open-weight model it tested, GLM-5.2, and about $141 for the strongest closed-source model, GPT-5.5, figures it described as 15.2 times and 172 times cheaper. Antares also finished benchmark runs in about an hour, compared with roughly four and a half hours for GPT-5.5.
Antares is the latest piece of a broader Cisco push around AI in security. In October, the company released Project CodeGuard, an open-source framework of secure-coding rules for AI coding agents and in May it published Foundry Security Spec, an open blueprint for building agentic security evaluation systems. Cisco Foundation AI has also shipped a run of open-weight security models over the past year, including Foundation-sec-8B and a reasoning version.
“The goal is to build toward a system where all security practitioners, regardless of on-prem or resource constraints, can effectively incorporate AI in everyday security operations,” Amin Karbasi, vice president and chief scientist at Cisco Foundation AI, wrote in a blog post.
Cisco was clear about what Antares does not do. The models are meant to speed up the first pass of vulnerability triage, not replace it, and they do not stand in for the rest of the application security stack, including dependency and software composition analysis, secret scanning, dynamic testing and human review.
The two available models and their model card are on Hugging Face, with the Antares-3B model still to come.
Image: Cisco
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more** 11.4k+ theCUBE alumni**— Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.
About SiliconANGLE Media
theCUBE AIand theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.