Models

Cantina Releases apex-flash-1 for Security Research

Cantina Security has launched apex-flash-1, an open-weights model that identifies software vulnerabilities at a fraction of the cost of proprietary frontier models like Claude.

MarkTechPost2 days agoModels
Image: MarkTechPost

Cantina Security and Yeta Labs have introduced apex-flash-1, an open-weights model tailored for detecting software vulnerabilities. Distributed on Hugging Face under the MIT license, the model is a reinforcement learning fine-tune of Z.ai's GLM-5.3-Flash base model. It features 321.3 billion total parameters in a Mixture-of-Experts architecture, though only 18 billion parameters are active. Running the model in BF16 precision requires approximately 640 gigabytes of GPU memory, making it compatible with multi-GPU nodes using vLLM, SGLang, or Transformers.

The developers trained the model using Group Relative Policy Optimization (GRPO) with a rank-256 LoRA and selective full-parameter training. The training dataset comprised 150 tasks derived from 50 real-world vulnerability cases, with each case presented in guided whitebox, focused whitebox, and focused blackbox variants. Authorization, identity, and scope flaws represented 72 percent of these cases, while accounting and numerical precision bugs made up 18 percent. The remaining cases covered time validation, business rules, and server-side request forgery (SSRF).

In evaluations on 60 tasks from 20 held-out vulnerability cases, apex-flash-1 successfully solved 40 tasks, achieving a 66.7 percent pass@1 rate at an estimated cost of $2.38. This outperformed its base model, GLM-5.3-Flash, which solved 36 tasks for $4.56. While Claude Opus 5 High solved 43 tasks, its run cost $74.68. This means apex-flash-1 cost roughly $0.06 per solved task compared to $1.74 for the proprietary model, representing a 31-fold cost reduction.

Cantina positions apex-flash-1 as an agentic worker meant to be orchestrated by a larger model, focusing on skills like code reading, tool use, exploit development, and verification. The release also includes an experimental apex-flash-1-abliterated variant with modified refusal behavior. By providing these open weights, the creators aim to give defensive security teams capable tools they can run and control locally.

This is our own summary of reporting by MarkTechPost

More in Models