Cisco launches Antares open-weight models for local vulnerability detection
Published
Cisco has introduced Antares, a family of small language models built specifically to locate known software vulnerabilities inside source-code reposit...

Cisco has introduced Antares, a family of small language models built specifically to locate known software vulnerabilities inside source-code repositories. The first two models, Antares-350M and Antares-1B, are available as open-weight releases.
A narrow model family for security investigation
Antares is not designed as a general coding assistant. Each model starts with a vulnerability description, searches a repository for relevant patterns, reads candidate files and revises its search strategy as new evidence appears. The output is a ranked list of files that may contain the vulnerability, along with the terminal exploration trace used to reach that result.
Local deployment keeps source code private
Because the released models contain 350 million and 1 billion parameters, they are compact enough to run locally or in on-premises environments. This allows organisations to analyse proprietary code without sending an entire repository to an external cloud model and can reduce the cost of repeated scans.
A new benchmark for vulnerability localisation
Cisco created a 500-task Vulnerability Localization Benchmark because general coding evaluations do not measure this specialised workflow. The benchmark tests whether a model can navigate an unfamiliar repository and identify source files associated with specific vulnerability classes.
Cisco reports that the Antares models outperform several larger open- and closed-weight systems on this benchmark while using less time and estimated compute cost. These are vendor-reported results and have not been independently validated across every production environment.
How Antares fits into a security stack
The models are intended to support early vulnerability triage, advisory-driven investigations, CI/CD review and local code analysis. Cisco says Antares is not a replacement for dependency analysis, secret scanning, dynamic testing, container security, threat modelling or expert review.
What comes next
A larger Antares-3B model is planned for a later release. Cisco has also published the benchmark and supporting technical material so researchers and security teams can evaluate the approach and build additional workflows around the models.
Practical significance
Antares shows how specialised small models can be more useful than a general frontier model for a tightly defined task. For development teams, the main opportunity is faster and more private vulnerability localisation close to the code-review and deployment pipeline.
Cisco announced the model family in an official technical post .
Source: Cisco