Antares: Open Weight AI Models for Vulnerability Localization (blogs.cisco.com)

🤖 AI Summary
Cisco has launched Antares, a series of small language models (SLMs) specifically designed for vulnerability localization in codebases, which addresses the challenging and resource-intensive task of identifying known security vulnerabilities. The two models, Antares-350M and Antares-1B, are now available as open-weight models on Hugging Face. They boast significant performance advantages over larger models while being affordable and capable of running locally, allowing sensitive code to remain private. This innovation is expected to empower smaller organizations with limited security resources, making advanced AI-based detection accessible to a broader range of users. Antares differentiates itself by employing an iterative search approach that mimics human investigation techniques, enhancing its effectiveness in pinpointing vulnerabilities. It operates through several workflows, enabling tasks such as locating files linked to specific vulnerability classifications and streamlining advisory-driven investigations. Alongside the Antares release, Cisco introduced the Vulnerability Localization Benchmark, tailored to evaluate models' effectiveness in navigating codebases and recognizing security-related patterns. The open-weight release aligns with Cisco's vision of fostering a more collaborative and practical AI security ecosystem, where all security practitioners can leverage AI to improve operational efficiency and threat response.
Loading comments...
loading comments...