ProBackend
agentic ai security risks
6 days ago4 min read

Cisco’s Antares Models: Small, Local, and Efficient Bug Hunting

A deep dive into Cisco's mission-specific Antares small language models (SLMs) and how they plan to disrupt the AI security market by focusing on speed, cost, and developer privacy.

Beyond the Chatbot: Why Cisco’s Antares Models Are Changing the Game

For too long, the security industry has been obsessed with the brute force of massive Language Models. When it comes to finding vulnerabilities in a codebase, the default assumption has been that bigger is better—or at least, that more parameters mean more intelligence.

Cisco is calling the industry's bluff.

With the release of its new Antares family of small language models (SLMs), Cisco is flipping the script. They aren't trying to build the next chatty companion that writes poetry or answers complex riddles. They’ve built an investigator. They've built a search engine—specifically designed, from the ground up, to hunt for security vulnerabilities in code, and do it with a level of local efficiency that puts gargantuan frontier models to shame.

A Fundamental Shift in Training

The problem with many current AI tools for security isn't just their inefficiency; it’s that they are fundamentally misunderstood, and often misapplied.

"Sometimes you don't need a private jet to go to a corner store," says DJ Sampath, Cisco's Senior VP and GM of AI software and platform. That is the philosophy behind Antares.

The Antares models, specifically the Antares-350M and the Antares-1B, aren’t just smaller; they behave differently. According to Amin Karbasi, Cisco’s VP and Chief AI Scientist, the approach was fundamentally different. "Antares is inherently not a chatbot. It is an investigator," Karbasi explained.

Training these models involved teaching them not to predict the next word in a sentence, but to navigate the labyrinth of a complex codebase. They are designed to search, pivot, and re-examine. Like a bicycle on a busy city street, they are agile and nimble, allowing them to zip through code far faster than the massive "trucks" of industry-standard AI, which are often burdened by their own enormous, generalized architectures.

Local Execution and the Privacy Imperative

Perhaps the most significant differentiator—the one that will arguably do the most to drive enterprise adoption—is the requirement for local execution.

When you use a generic, cloud-based frontier model to scan your source code for vulnerabilities, you are effectively shipping your intellectual property off-site, into somebody else's cloud. For many organizations, particularly in sectors with rigorous privacy or compliance requirements, this is a non-starter.

Antares changes that. These models are designed to run locally, on the organization's own infrastructure. The code never leaves the house.

"You also need the keys to the source code to scan for and find vulnerabilities," Sampath noted. This ensures that even if an attacker manages to exploit an endpoint or service, they aren't catching a ride on a massive stream of egressing internal code.

Efficiency Doesn't Equal Compromise

The obvious counter-argument to small models is, naturally, performance. How can a model with a billion parameters compete with one possessing hundreds?

Cisco's internal benchmarking suggests it’s not really a fair fight—but not in the way the AI giants would like you to believe.

In tests comparing the time it takes to scan 500 repositories, the Antares-1B finished in just 15 minutes. The behemoth frontier models, by comparison, took five hours. That isn't just a performance delta; it is a fundamental shift in utility.

And then there is the cost. Those hours of processing with frontier models don't come free. They are expensive, token-gobbling black boxes. Cisco reports that the cost can easily climb above $150 for significant scans. Antares? Less than a dollar.

What’s Available, and What’s Coming

Right now, Cisco has released two open-weight models: Antares-350M and Antares-1B. They are currently available on Hugging Face, but access is gated to ensure they are being used responsibly and by vetted organizations—not by individuals who might look to exploit the vulnerability-spotting capabilities.

There's more on the horizon, but don't expect it to be a free-for-all. Cisco is developing a 3-billion-parameter (3B) model, but Karbasi was clear about the intent: "We are completely gating the 3B model to make sure that we responsibly release it to communities that need it."

This gated approach is a realistic, pragmatic step in a world where AI safety and AI misuse are two sides of the same coin. By controlling the distribution, Cisco is attempting to position itself as a responsible partner for organizations grappling with the very real risks of AI-automated security.

The Verdict on Bug Hunting

We’ve reached a point where applying the same massive, general-purpose LLM to every single task is no longer sustainable. It’s expensive, it's slow, and for many users, it presents an unacceptable privacy risk.

Antares represents a maturation of the AI security market. It signifies a move away from the "bigger is better" hype and toward mission-specific engineering. For security teams that are overwhelmed, under-budgeted, and terrified of data leakage, the Antares models don't just look like a good option.

They look like the only reasonable one.


Task ID: 42fa11ab-1257-4f95-abdd-20359efae30b

Beyond the Chatbot: Why Cisco’s Antares Models Are Changing the Game

Beyond the Chatbot: Why Cisco’s Antares Models Are Changing the Game

More blogs