Cisco Antares AI models hunt code vulnerabilities faster and cheaper than OpenAI and Google

4 Sources

Share

Cisco released two open-weight AI models that specialize in finding known bugs in existing codebases. The Antares family of small language models—Antares-350M and Antares-1B—are now available on Hugging Face to vetted security teams. Designed to run locally, these models scan code much faster and at a fraction of the cost of larger AI systems while keeping proprietary code within organizations.

Cisco Antares Challenges Frontier AI Models With Specialized Security Focus

Cisco has released two open-weight AI models that redefine how organizations hunt for code vulnerabilities. The Antares-350M and Antares-1B models, now available on Hugging Face to vetted users, are part of Cisco's new Antares family of security small language models designed specifically for vulnerability localization

1

2

. These AI models specialize in pinpointing where known bugs exist within codebases, a task that traditionally consumes significant time and resources for security teams.

Source: SiliconANGLE

Source: SiliconANGLE

The networking and security giant is working with academic and nonprofit organizations, as well as smaller and public organizations' security teams, to ensure appropriate access to these vulnerability-hunting tools

1

. DJ Sampath, Cisco's senior vice president and general manager of AI software and platform, emphasized the gated approach: "We're making sure we're gating that and appropriately granting access"

1

. The company also worked with U.S. government agencies on the models' safety and release, vetting who can download the models to ensure adversaries and cybercriminals don't gain access

3

.

Small Language Models Deliver Cost-Effective Performance

Cisco claims that Antares-1B outperforms Google Gemini 3 Pro and matches Z.ai's GLM-5.2 in finding security flaws, while the unreleased Antares-3B surpasses both GLM-5.2 and OpenAI GPT-5.5

1

. The performance difference is striking: Antares finishes scanning 500 repositories in 15 minutes for less than $1, whereas frontier models take five hours and cost between $100 and $150

1

3

. This cost-effective approach makes AI-powered security tools accessible to universities, public sector institutions, and smaller security teams that may lack resources for token-intensive commercial models

4

.

Amin Karbasi, Cisco's vice president and chief AI scientist, explained that the company took a "fundamentally different approach" to building these models. "Antares is inherently not a chatbot. It is an investigator. It is a search engine," he said

1

. The models learn to search repositories, inspect files, change direction when leads don't pan out, and narrow in on files most likely to contain vulnerabilities—behaving more like security investigators than coding assistants

3

.

Local Deployment Protects Proprietary Code

Because both are small models designed for local deployment, organizations can detect vulnerabilities in codebases without sending proprietary code to external servers

1

2

. This enables security analysis in environments with strict privacy or compliance requirements, addressing a critical concern for enterprises handling sensitive source code. Sampath noted that attackers would need both the models and "the keys to the source code" to exploit vulnerabilities, adding a layer of protection

1

.

Source: Axios

Source: Axios

Professor Reza Shokri from the National University of Singapore highlighted the practical implications: "Small models are especially compelling here: they run locally, so proprietary code never leaves the machine, and they're fast enough to gate an agent's output in real time"

2

. This capability becomes particularly relevant as organizations need to rescan repositories repeatedly as software changes, making the cost and speed advantages of open-weight AI models even more significant

3

.

New Benchmark Measures AI for Cybersecurity Effectiveness

To measure the models' performance, Cisco built the Vulnerability Localization Benchmark, a 500-entry test that requires AI models to navigate unfamiliar codebases and recognize vulnerability patterns tied to specific weakness categories

4

. Existing code-search benchmarks measure whether an agent can find code relevant to general software issues, not whether it can locate vulnerable files from security descriptions

4

. The benchmark testing demonstrates that these models outperform many powerful closed- and open-weight models in this critical security task

2

.

Amin Saberi, Professor at Stanford University, emphasized the broader implications: "Security can't be a luxury good, yet advanced AI-based detection has largely belonged to organizations with frontier-scale budgets. Antares's results change that equation"

2

. The models' efficiency makes always-on security scanning possible for every team, particularly important as attackers increasingly use AI themselves.

Building an Ecosystem for AI-Powered Security Tools

Cisco is combining open-weight AI models with Antares, open specifications with Foundry Security Spec, secure coding guidance with Project CodeGuard, and the new benchmark to define practical, trustworthy AI tools for cybersecurity professionals

2

. The company is exploring an industry consortium to expand its work on open AI security tools

3

. Cisco is holding back the public release of the more capable Antares-3B, which it plans to integrate into its own security products while making it available to communities that need it

1

3

.

Source: The Register

Source: The Register

Cisco joins other companies like Capital One, which recently open-sourced VulnHunter, an agentic AI security tool that reviews source code from an attacker's perspective

3

. As organizations face mounting pressure to secure increasingly complex codebases, the availability of efficient, locally-deployable AI models could reshape how security teams approach vulnerability management and triage.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved