Cisco's Antares AI Helps Code Reviewers Find Vulnerabilities Faster

Cisco introduces the Antares AI models to streamline the process of finding potential security issues in large code repositories.

ThreatVectr Newsdesk· 3 min read
Photoreal news-editorial style, 16:9 framing, edge-to-edge composition
Share

Key points

  • Cisco launched Antares, an AI model family, on November 2023.
  • Antares focuses on vulnerability localization in software codebases.
  • The models use Common Weakness Enumeration (CWE) descriptions to identify risky files.
  • Cisco claims Antares can approach the performance of larger AI models like GPT-5.5.
  • Antares is available as open-weight models on Hugging Face.

Cisco has announced a new family of AI models called Antares, designed to help teams find potentially vulnerable parts of a software codebase faster. Rather than pinpointing specific known vulnerabilities, these models look at the code using descriptions from a list of common software weaknesses, known as Common Weakness Enumeration (CWE), to spot files that might have issues.

Cisco's goal with Antares is to make the job easier for security professionals by narrowing down the files they need to check. This means instead of wading through an entire mountain of code, they get a shortlist to focus on. Supriti Vijay, an AI researcher at Cisco, explains that the aim is to reduce the workload and fatigue for security engineers while ensuring they don't miss potential problems.

Antares models come in different sizes, with the largest having 3 billion parameters, think of parameters like the brains of the AI. Cisco says this model can perform like some of the biggest AI systems out there, but at a fraction of the cost, so you can run it locally without breaking the bank.

How does Antares differ from existing tools?

Antares isn't out to replace current security tools. Instead, it acts more like a smart assistant. It gives a ranked list of files that might have vulnerabilities, but human experts still need to check if there's really a problem and decide how serious it is.

Unlike other tools that rely on strict rules, Antares adapts as it scans the code, making it unique. This means it's better suited for large projects where manually checking every line is just not feasible.

Cisco is making a case for specialized models like Antares over bigger, generic AI systems. They argue that a focused approach can be more effective, especially for tasks like finding potential security holes in vast amounts of code.

For tech-savvy folks eager to give it a whirl, the models are available on Hugging Face, a popular platform for AI models. They support various investigative tasks and help keep your proprietary code safe by running on your own systems.

But remember, while Antares can help spot where to look, it won't tell you if something's definitely wrong. Companies will need to experiment with how often they use it and see if it really helps save time and money.

© 2026 Threat Vectr