Cisco releases open-source AI models for vulnerability scanning
The networking giant's Antares family promises faster, cheaper security audits that keep sensitive code in-house.

Cisco unveiled two compact AI models Tuesday specifically engineered to hunt for software vulnerabilities in large codebases, offering security teams a faster and more economical alternative to general-purpose language models.
The Antares family of small language models can scan repositories for known vulnerabilities while running locally on company infrastructure, eliminating the need to transmit sensitive source code to external AI providers. Cisco is making two versions—Antares-350M and Antares-1B—available on Hugging Face to verified cybersecurity professionals, while reserving a more powerful 3-billion-parameter variant for its own commercial security products.
Why it matters
Repeated security scans across evolving codebases can quickly become prohibitively expensive with large AI models. Cisco's approach addresses both the cost barrier and the data sovereignty concerns that prevent many organizations from using cloud-based AI for security audits. By training specialized models that behave like security investigators rather than coding assistants, the company is demonstrating how purpose-built AI can outperform general tools on specific enterprise tasks.
Performance and cost advantages
In Cisco's internal testing, Antares scanned 500 repositories in approximately 15 minutes for under $1. The same task required roughly five hours and more than $100 when performed using OpenAI's GPT-5.5. Despite their smaller size, the Antares models matched the performance of much larger systems including GPT-5.5 and Z.ai's GLM-5.2 on Cisco's benchmark measuring accuracy in identifying vulnerable files within real-world software repositories.
"You really don't need a private jet to go to your corner store," DJ Sampath, Cisco's senior vice president and general manager of AI software and platform, told the publication. "You want to be able to use something that's practical."
Investigative approach to code analysis
Unlike general-purpose language models that treat security as an extension of coding capabilities, Antares was trained to mimic the behavior of security investigators. The models learn to systematically search repositories, examine files, pivot when leads prove unproductive, and zero in on code segments most likely to harbor vulnerabilities.
"A vulnerability can be only a few lines of code in a million lines of code," explained Amin Karbasi, Cisco's vice president and chief AI scientist. Antares "is going to be finding these security needles in the haystack of your repository."
Controlled release and industry collaboration
Cisco coordinated with U.S. government agencies on safety protocols and will vet download requests to prevent malicious actors from accessing the tools. The company is also exploring an industry consortium to expand open AI security tool development.
The release follows Capital One's recent open-sourcing of VulnHunter, an agentic AI tool that adopts an attacker's perspective when reviewing code. These developments signal growing momentum behind specialized, open-source AI for cybersecurity applications.
These details were first reported by Axios.
This is an original analysis by the Omega editorial team. Source reporting: AI Watch.
Want systems like this working for your business?
Book a Call
