Cisco has unveiled a new family of small, open-weight AI models designed specifically for cybersecurity, claiming they can match—or even outperform—much larger frontier models on software vulnerability detection while operating at a fraction of the cost. The models, called Antares-350M and Antares-1B, are built to help security teams identify vulnerable files in large codebases without relying on expensive cloud-based AI services. Cisco says an even more capable Antares-3B model, which it is keeping private for now, surpasses OpenAI’s GPT-5.5 on its internal vulnerability localization benchmark.

Unlike general-purpose coding assistants, Antares is purpose-built for repository-level security analysis. Cisco trained the models to behave like security investigators, enabling them to search through unfamiliar codebases, follow vulnerability clues, and pinpoint files most likely to contain known software flaws. By focusing on a narrow cybersecurity task instead of broad language understanding, the company says the models deliver faster results, lower inference costs, and improved privacy by allowing organizations to run them locally.

Image 61

Cisco Introduces Antares Cybersecurity AI Models

The Antares family currently includes two publicly available open-weight models:

  • Antares-350M
  • Antares-1B

Cisco has also developed a more powerful Antares-3B model, but it will only be released to verified cybersecurity communities and integrated into Cisco’s own security products due to responsible AI considerations.

Antares Model Lineup

ModelAvailabilityPrimary Purpose
Antares-350MOpen-weightVulnerability localization
Antares-1BOpen-weightRepository-level security analysis
Antares-3BLimited releaseAdvanced vulnerability detection

Purpose-Built for Vulnerability Detection

Rather than functioning as a coding assistant, Antares is designed to investigate software repositories much like a human security analyst.

Its capabilities include:

  • Searching repositories for vulnerable files.
  • Interpreting security advisories.
  • Following multiple investigative paths.
  • Narrowing down likely locations of software vulnerabilities.
  • Supporting security teams during vulnerability triage.

Cisco says this investigator-style approach allows the models to find “needles in the haystack” within millions of lines of code.

Smaller Models Deliver Comparable Performance

According to Cisco’s benchmark testing:

  • Antares-1B outperformed several larger open models, including Google Gemini 3 Pro, on vulnerability localization.
  • The unreleased Antares-3B exceeded the performance of GPT-5.5 and GLM-5.2 on Cisco’s internal benchmark.
  • The models were specifically optimized for cybersecurity tasks rather than general reasoning.

Cisco cautions that these comparisons are based on its own benchmark and have not yet been independently validated by third parties.

Performance Comparison

FeatureFrontier ModelsCisco Antares
Primary FocusGeneral-purpose AIVulnerability detection
DeploymentMostly cloud-basedLocal or on-premises
Repository AnalysisHigher compute costOptimized for security workflows
Benchmark ClaimStrong general coding abilityComparable or better vulnerability localization

Faster and Significantly Cheaper

One of Cisco’s biggest selling points is cost efficiency.

The company says:

  • Scanning 500 repositories takes about 15 minutes.
  • The total inference cost is under $1 on a single GPU.
  • Comparable frontier models require roughly five hours and cost more than $100 for the same workload.
  • Antares is estimated to be 172 times cheaper than leading frontier models and over 15 times cheaper than the best-performing open-weight alternative evaluated by Cisco.

Cost Comparison

MetricAntaresFrontier AI Models
Repositories Evaluated500500
Processing Time~15 minutes~5 hours
Estimated CostLess than $1More than $100

Privacy and Enterprise Benefits

Because Antares can run locally, organizations do not need to upload sensitive source code to external AI providers.

This offers several advantages:

  • Better data privacy.
  • Compliance with data sovereignty requirements.
  • Lower recurring AI costs.
  • Faster continuous vulnerability scanning.
  • Easier deployment in air-gapped or highly regulated environments.

Cisco Also Launches a New Security Benchmark

Alongside Antares, Cisco introduced the Vulnerability Localization Benchmark (VLB), a 500-entry benchmark designed to measure how accurately AI models identify vulnerable files within real-world software repositories.

The benchmark evaluates models on:

  • Repository navigation.
  • Vulnerability localization.
  • Code reasoning.
  • Security pattern recognition.

Cisco says the benchmark reflects practical security workflows more closely than traditional coding evaluations.

Looking Ahead

Cisco’s Antares models highlight a growing trend toward specialized, task-specific AI systems that prioritize efficiency over sheer model size. By focusing exclusively on repository-level vulnerability detection, the company claims its compact models can deliver performance comparable to—or better than—much larger frontier models while dramatically reducing compute costs and enabling local deployment. Although Cisco’s performance claims are currently based on its own benchmark and await broader independent validation, the release underscores the industry’s shift toward smaller, domain-specific AI models for enterprise use.

Looking ahead, if independent testing confirms Cisco’s results, Antares could reshape how organizations approach AI-powered software security by making advanced vulnerability detection more affordable, privacy-preserving, and accessible. The models also reinforce a broader industry trend in which specialized AI systems increasingly complement, rather than replace, large general-purpose language models in enterprise workflows.

Get the day’s top stories in your inbox

One concise email. No spam, unsubscribe anytime.