The point: Antares models reduce large codebases to focused file lists for manual vulnerability analysis without replacing code-review processes.
Cisco has developed a family of open-weight AI models called Antares that support code reviewers in identifying potentially vulnerable files in large repositories. The models are specifically trained for vulnerability localization and are based on CWE descriptions rather than predefined rules.
Cisco has released three specialized models with 350 million, 1 billion, and 3 billion parameters trained for vulnerability localization at the repository level. The largest model – Antares-3B – delivers results comparable to GPT-4.5 according to the vendor, while remaining small enough for cost-effective local deployment on individual GPUs.
Antares differs fundamentally from conventional static analysis platforms such as Semgrep or CodeQL, which rely on predefined rules or queries. Instead, Antares functions as an “evidence-driven exploration agent” that adaptively adjusts its search strategy based on repository traversal. The model outputs a prioritized list of source files that might contain a specific vulnerability class, along with a record of the search path. The goal is to reduce large codebases to a manageable set: in large repositories with thousands of files, manual review becomes practically impossible, and Antares is intended to reduce this fatigue.
According to Cisco security researcher Supriti Vijay, the purpose is to “reduce a large codebase to a focused set of files that a security professional or downstream security workflow should investigate.” The model does not replace the judgment of security engineers, but rather aims to enable earlier and more targeted triage.
Cisco deliberately sets boundaries, however: Antares neither replaces verification of exploitability nor identification of exact code lines, severity rating, or patch generation. These tasks remain with analysts or downstream security tools. Cisco is also arguing against the trend toward ever-larger foundational models and instead focuses on specialized models trained for a specific task – Antares-3B outperforms several substantially larger open models from Google, OpenAI, and Meta on this task.
The three models are available on Hugging Face as open-weight. The CLI supports targeted CWE investigations, repository-wide scans, SARIF output, and local inference – enabling organizations to keep proprietary code within their own trust boundary. What remains unanswered is how often such scans are meaningful and whether the reduced investigation time measurably improves security or costs.
Source: www.csoonline.com · Published 22 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.