06 Jul 2026
AI-powered cybersecurity solutions are often associated with large-scale models that demand high computing costs. Recently, however, Cisco introduced a different approach with Antares, a family of open-weight AI models designed to be compact yet focused on one specific task: locating vulnerabilities within large-scale codebases.
Application security teams often struggle to connect public vulnerability reports to the specific files within large repositories that may be affected. This process is time-consuming, resource-intensive, and prone to human error — especially in codebases that are complex or unfamiliar to the teams handling them.
Cisco has released two initial models, Antares-350M and Antares-1B, available as open-weight models on Hugging Face. Thanks to their small size, these models can run locally, meaning sensitive source code doesn't need to be uploaded to third-party cloud services for analysis — an important consideration for organizations with strict data security policies.
Based on Cisco's internal testing using its Vulnerability Localization Benchmark, Antares matches or even surpasses the performance of several much larger models for this specific task, at a significantly lower operational cost than running frontier models for similar work. For security teams with limited budgets, this opens the door to running AI-based vulnerability detection routinely on every code commit without incurring major operational expense.
It's worth noting that Antares is not intended to replace the entire application security process. The model handles only one part of a much longer application security chain, while other processes — such as software composition analysis, secret scanning, dynamic testing, and manual review — remain necessary as additional layers of defense.
Cisco's approach with Antares shows that effective AI in cybersecurity doesn't always depend on large model scale. For organizations that have viewed AI-based vulnerability detection as too costly or risky in terms of code confidentiality, a lighter, on-premises-capable model like this deserves a place in their security technology evaluation. Perkom, as a Cisco partner, is ready to help organizations that need further discussion on implementing this solution.
Author: Ghea Devita
Marketing Communication PT Perkom Indah Murni