Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Sen. Wyden introduces bill to curb Trump’s tariff powers

    As COE premiums correct from recent high in early July, more supply could be on the way

    Why MiMo Code Is A Game-Changer For AI Operations Teams

    Facebook X (Twitter) Instagram
    Facebook X (Twitter) Instagram Pinterest VKontakte
    Sg Latest NewsSg Latest News
    • Home
    • Politics
    • Business
    • Technology
    • Entertainment
    • Health
    • Sports
    Sg Latest NewsSg Latest News
    Home»Technology»Cisco open-sources Antares AI models for vulnerability detection
    Technology

    Cisco open-sources Antares AI models for vulnerability detection

    AdminBy AdminNo Comments6 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Cisco has released two open-weight security models designed to search software repositories for files linked to known vulnerability categories. Antares-350M and Antares-1B are listed on Hugging Face under the Apache 2.0 licence, with access to the model files subject to Cisco’s request process.

    The models are designed for vulnerability localisation rather than general code generation, patch creation, or issue resolution. Their narrower focus gives developers and security teams a locally deployable alternative to using larger general-purpose coding models for repository-level vulnerability triage.

    How Antares searches code

    Vulnerability localisation connects information from security advisories, vulnerability databases, and Common Weakness Enumeration categories with the files that may contain the relevant code. Antares receives a CWE identifier and a generic description of the weakness, then explores a repository through a terminal interface using commands such as grep, find, and cat.

    The model inspects files, revises its search, and returns a list of candidate file paths. It does not perform an unrestricted scan for every possible flaw, but starts with known vulnerability context and identifies where reviewers should investigate first.

    During Cisco’s benchmark, each model received a CWE category and description without advisory text, severity information, or file hints. It was limited to 15 terminal commands before submitting its answer.

    Antares returns file-level candidates rather than confirmed vulnerabilities. It does not identify affected lines, explain why the code is vulnerable, or generate fixes, and Cisco recommends human validation before teams act on its output.

    Cisco positions Antares as a complement to existing application security tools rather than a replacement for them. Conventional static analysis examines source code without executing it, using methods that can include predefined rules, control-flow analysis, data-flow analysis, and taint tracking.

    Antares begins instead with external vulnerability context and applies a learned search process to navigate the repository and prioritise related files. A security advisory could identify the relevant weakness category before Antares searches the affected codebase, while other tools continue to handle dependency analysis, secret scanning, dynamic testing, runtime behaviour, and remediation.

    Local deployment and CI/CD use

    Antares-1B contains about one billion parameters, while Antares-350M has about 350 million. Cisco is also developing a three-billion-parameter version.

    Their smaller size allows organisations to host them within their own infrastructure, reducing the need to send proprietary source code to an external model provider. Cisco documents deployment through Transformers, vLLM, SGLang, Docker Model Runner, and quantised formats compatible with tools including llama.cpp and Ollama.

    The command-line interface connects to a user-configured OpenAI-compatible inference endpoint. Keeping repository data within an organisation’s environment therefore requires both the model and the endpoint to be hosted internally, alongside the hardware, access controls, logging, and model-management processes needed to operate the system.

    Cisco recommends analysing repositories in isolated containers with network access disabled. It also advises using read-only repository access, command timeouts, resource limits, audit logging, and human oversight.

    The Antares CLI supports targeted investigations based on specified CWE identifiers, as well as broader repository sweeps. It can return human-readable reports, JSON, and SARIF 2.1.0 output, allowing findings to appear in compatible code-scanning systems such as GitHub Code Scanning or pass into internal reporting and orchestration tools.

    In a CI/CD workflow, Antares could run after a security advisory, dependency alert, or selected weakness category triggers further investigation. Cisco allows the CLI to fail a pipeline when candidate files are returned, but leaves that setting disabled by default because the findings still require review.

    The published documentation does not specify whether production deployments should rescan an entire repository, inspect only changed files, or reuse earlier results. Those implementation choices would affect pipeline runtime, computing use, and the amount of review required from developers or security teams.

    Benchmark results and technical limits

    Cisco said the compact models require less inference capacity than larger general-purpose systems. It reported that Antares-1B completed the 500-task benchmark in approximately 13 to 15 minutes on one Nvidia H100 GPU using 16 parallel workers.

    Cisco estimated the inference cost for the full Antares-1B benchmark run at US$0.71. Its comparison placed GLM-5.2 at US$12.50 and GPT-5.5 at US$141 under the company’s evaluation setup.

    Those figures cover model execution rather than the full cost of deployment. Hardware, integration, maintenance, pipeline engineering, and manual review would add to the total cost of operating the system.

    Cisco created the Vulnerability Localization Benchmark because general coding tests do not directly measure security-specific file localisation. The benchmark contains 500 tasks drawn from 290 repositories, covering six package ecosystems and 147 CWE categories, while 78% of the entries have associated CVE identifiers.

    Each task uses a repository snapshot from before a vulnerability was fixed. The ground-truth files are implementation files changed in the corresponding security patch, excluding tests, documentation, and configuration files.

    Antares-1B recorded a file-level F1 score of 0.209, with precision of 0.262 and recall of 0.224. Cisco said it outperformed several larger models when they were tested with the same tools, prompts, terminal-command limit, and generation settings.

    The results also show that the model returned incorrect candidate files and missed some files associated with recorded fixes. The benchmark results were reported by Cisco, and the accompanying materials do not include an independent replication.

    Cisco said its reinforcement-learning training set and evaluation benchmark do not overlap. The company has not published the complete proprietary training corpus.

    Repository size remains one of the model’s documented constraints. Cisco reports that Antares performs less effectively on repositories larger than 10MB under the default 15-command limit, while vulnerabilities requiring context from five or more files also produce weaker results.

    Performance varies by weakness category. Cisco reported stronger results for vulnerabilities with distinctive searchable patterns, including type confusion and prototype pollution, but weaker results for issues involving permissions, locking, memory management, or broader program behaviour.

    Cisco does not publish a fixed list of supported programming languages. Its documentation says performance can vary according to the languages and vulnerability categories represented in the training data.

    The models’ training data has a cutoff of April 10, 2025. Cisco recommends supplementing them with current vulnerability feeds and security databases when investigating newer advisories.

    (Photo by boris misevic)

    See also: Hugging Face confirms AI agent breached production systems

    Banner for Cyber Security Expo by TechEx events.

    Want to learn more about cybersecurity from industry leaders? Check out Cyber Security & Cloud Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the AI & Big Data Expo. Click here for more information.

    Developer Tech News is powered by TechForge Media. Explore other upcoming enterprise technology events and webinars here.

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Admin
    • Website

    Related Posts

    Why MiMo Code Is A Game-Changer For AI Operations Teams

    Galaxy Watch 9 brings a new chip, bigger batteries, One UI 9 Watch, and a $30 price hike

    models escaped via package proxy

    Chinese Tech Firm Jingce Electronic to Fully Acquire Semiconductor Subsidiary in Major Reorganization

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Most Impressive Team Streaks Of The 21st Century: Where Does 2024-26 Spain Rank?

    NBC’s ‘Stumble’ is a mockumentary about a cheer team with plenty of tumbling runs and heart

    Xiaomi shares post worst week in 3½ years as accidents stoke EV safety concerns

    Judge reverses Trump administration’s cuts of billions of dollars to Harvard University

    Top Reviews
    9.1

    Review: Mi 10 Mobile with Qualcomm Snapdragon 870 Mobile Platform

    By Admin
    8.9

    Comparison of Mobile Phone Providers: 4G Connectivity & Speed

    By Admin
    8.9

    Which LED Lights for Nail Salon Safe? Comparison of Major Brands

    By Admin
    Sg Latest News
    Facebook X (Twitter) Instagram Pinterest Vimeo YouTube
    • Get In Touch
    © 2026 SglatestNews. All rights reserved.

    Type above and press Enter to search. Press Esc to cancel.