MEGA Hub

Antares: Foundation Models for Agentic Vulnerability Localization

Authors

Do you know Supriti Vijay?You can claim authorship or link another user.Do you know Aman Priyanshu?You can claim authorship or link another user.Do you know Didier Chapoteau?You can claim authorship or link another user.Do you know Arthur Goldblatt?You can claim authorship or link another user.Do you know Jianliang He?You can claim authorship or link another user.Do you know Kimia Majd?You can claim authorship or link another user.Do you know Fraser Burch?You can claim authorship or link another user.Do you know Baturay Saglam?You can claim authorship or link another user.Do you know Takahiro Matsumoto?You can claim authorship or link another user.Do you know Zhuoran Yang?You can claim authorship or link another user.Do you know Amin Karbasi?You can claim authorship or link another user.

Abstract

Vulnerability localization is a fundamental step in software security, requiring models to reason over large codebases and iteratively identify vulnerable implementations. We present Antares, a family of compact language models (350M, 1B, and 3B parameters) for agentic vulnerability localization. Based on IBM Granite base models, Antares is trained through a two-stage pipeline that combines supervised fine-tuning on cybersecurity reasoning and repository exploration data with reinforcement learning from verifiable rewards over vulnerable repositories. Across extensive evaluations, Antares-3B approaches GPT-5.5 while outperforming open-weight models over 200x larger in size. The Antares family further enables fast, low-cost local inference, completing a full 500-task evaluation sweep in approximately 15 minutes on a single H100 GPU, corresponding to an amortized evaluation time of under 2 seconds and less than $0.002 per task.

Community

00

Publication notes

Author note
57 pages, 12 figures, technical report for antares