Can an Open Model Do Security Research? Cantina's apex-flash-1

Cantina Security, in collaboration with Yeta Labs, has released apex-flash-1 — an open-weights model trained specifically for vulnerability research. It is a reinforcement learning fine-tune of Z.ai's GLM-5.3-Flash, published on Hugging Face under the MIT license.

Is it deployable? Yes. The MIT-licensed weights run on vLLM, SGLang, or Transformers, but BF16 inference requires roughly 640 GB of GPU memory.

What Cantina Built

According to its Hugging Face safetensors metadata, apex-flash-1 has 321.3B total parameters. The underlying GLM-5.3-Flash base is a Mixture-of-Experts (MoE) model with 18B active parameters.

Cantina trained it with GRPO using a rank-256 LoRA plus selective full-parameter training. The training data covers 150 tasks built from 50 real-world vulnerability cases.

Each case appears in three variants: guided whitebox, focused whitebox, and focused... [continues]

via MarkTechPost

Related