跳至主要內容
電腦

小型漏洞分析模型

Cisco 發佈Antares-1B及Antares-350M模型

思科(Cisco)推出 Antares-350M 及 Antares-1B,兩款開放權重 AI 模型,設計旨在於軟件代碼庫中,定位可能與已知漏洞類別相關聯的檔案。這兩款模型於 Hugging Face 平台以 Apache 2.0 授權發布,可接收 CWE 識別碼及描述,其後運用終端指令調查程式碼,同時支援本機部署。

Antares 專注於檔案層級的候選項發掘,而非生成修補程式或識別確切的漏洞行數。此系統可輸出人類可讀格式、JSON 及 SARIF 報告,並支援透過 Transformers、vLLM、Docker Model Runner 及量化運行環境進行部署。思科亦公布一套涵蓋 500 項任務的漏洞定位基準測試,並建議於隔離、唯讀的容器環境中運行代碼庫掃描,同時配合日誌記錄及人工監督。

對保安團隊而言,此模型提供一種精簡、注重私隱的方式,於發出安全公告或警報後,優先安排程式碼審查工作。其較小的模型體積,支援更低成本的推論運算及 CI/CD 整合,惟思科指出,此模型於大型代碼庫,以及需要廣泛跨檔案脈絡的漏洞方面,表現相對較弱。

英文原文

Cisco introduced Antares-350M and Antares-1B, two open-weight AI models designed to locate files in software repositories that may be linked to known vulnerability categories. Published under the Apache 2.0 licence on Hugging Face, the models accept CWE identifiers and descriptions, then use terminal commands to investigate code while supporting local deployment.

Antares focuses on file-level candidate discovery rather than generating patches or identifying exact vulnerable lines. It can return human-readable, JSON and SARIF reports and supports deployment through Transformers, vLLM, Docker Model Runner and quantized runtimes. Cisco also published a 500-task Vulnerability Localization Benchmark and recommends running repository scans in isolated, read-only containers with logging and human oversight.

For security teams, the models provide a compact, privacy-focused way to prioritize code review after advisories or alerts. Their smaller sizes support lower-cost inference and CI/CD integration, although Cisco notes weaker performance on large repositories and vulnerabilities requiring broad multi-file context.

前往原文

小型漏洞分析模型
來源
Trend Hunter
發布
2026-07-31
品類
Computers
出處
developer-tech, blogs.cisco

同品類其他訊號