lupAI
pesquisa

Can open-weights models contribute to security research? Cantina’s apex-flash-1 demonstrates potential

CantinaSource: MarkTechPost05/10/2026, 01:08
Cantina Security, in collaboration with Yeta Labs, has unveiled apex-flash-1, an open-weights model designed for vulnerability research. The model, a reinforcement learning fine-tune of Z.ai’s GLM-5.3-Flash, is available on Hugging Face under the MIT license. It requires approximately 640 GB of GPU memory for deployment, with support for vLLM, SGLang, or Transformers. The model boasts 321.3 billion parameters, built upon a base model with 18 billion active parameters. Cantina trained apex-flash-1 using GRPO with a rank-256 LoRA and selective full-parameter training, leveraging data from 150 tasks derived from 50 real vulnerability cases. Each case was tested in three variants: guided whitebox, focused whitebox, and focused blackbox. Authorization, identity, and scope flaws accounted for 72% of the cases, while accounting and numerical precision bugs made up 18%. Cantina evaluated 60 tasks from 20 held-out cases, with apex-flash-1 solving 40 of them at a cost of about $0.06 per task, compared to $1.74 for Opus. Cant, the company, positions apex-flash-1 as a worker model orchestrated by a larger system, targeting skills like code reading, tool use, and exploit verification. An experimental variant with modified refusal behavior was also released but not separately evaluated. Cantina emphasizes the need for defenders to have locally controllable models for security research.
Can open-weights models contribute to security research? Cantina’s apex-flash-1 demonstrates potential — lupAI