Akahsizrr commited on
Commit
0ecb523
·
verified ·
1 Parent(s): dbc8059

Publish Cyber-Prime 1.1 final checkpoint and model card

Browse files
.gitattributes CHANGED
@@ -34,3 +34,4 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
36
  tokenizer.json filter=lfs diff=lfs merge=lfs -text
 
 
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
36
  tokenizer.json filter=lfs diff=lfs merge=lfs -text
37
+ cyberprime-1.1-benchmark.png filter=lfs diff=lfs merge=lfs -text
LICENSE ADDED
@@ -0,0 +1,71 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ LFM Open License v1.0
2
+
3
+ TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION
4
+
5
+ 1. Definitions.
6
+
7
+ "License" shall mean the terms and conditions for use, reproduction, and distribution as defined by this document.
8
+
9
+ "Licensor" shall mean Liquid AI, Inc.
10
+
11
+ "Legal Entity" shall mean the union of the acting entity and all other entities that control, are controlled by, or are under common control with that entity. For the purposes of this definition, "control" means (i) the power, direct or indirect, to cause the direction or management of such entity, whether by contract or otherwise, or (ii) ownership of fifty percent (50%) or more of the outstanding shares, or (iii) beneficial ownership of such entity.
12
+
13
+ "You" (or "Your") shall mean an individual or Legal Entity exercising permissions granted by this License.
14
+
15
+ "Source" form shall mean the preferred form for making modifications, including but not limited to software source code, documentation source, and configuration files.
16
+
17
+ "Object" form shall mean any form resulting from mechanical transformation or translation of a Source form, including but not limited to compiled object code, generated documentation, and conversions to other media types.
18
+
19
+ "Work" shall mean the work of authorship, whether in Source or Object form, made available under the License, as indicated by a copyright notice that is included in or attached to the work.
20
+
21
+ "Derivative Works" shall mean any work, whether in Source or Object form, that is based on (or derived from) the Work and for which the editorial revisions, annotations, elaborations, or other modifications represent, as a whole, an original work of authorship. For the purposes of this License, Derivative Works shall not include works that remain separable from, or merely link (or bind by name) to the interfaces of, the Work and Derivative Works thereof.
22
+
23
+ "Contribution" shall mean any work of authorship, including the original version of the Work and any modifications or additions to that Work or Derivative Works thereof, that is intentionally submitted to Licensor for inclusion in the Work by the copyright owner or by an individual or Legal Entity authorized to submit on behalf of the copyright owner. For the purposes of this definition, "submitted" means any form of electronic, verbal, or written communication sent to the Licensor or its representatives, including but not limited to communication on electronic mailing lists, source code control systems, and issue tracking systems that are managed by, or on behalf of, the Licensor for the purpose of discussing and improving the Work, but excluding communication that is conspicuously marked or otherwise designated in writing by the copyright owner as "Not a Contribution."
24
+
25
+ "Contributor" shall mean Licensor and any individual or Legal Entity on behalf of whom a Contribution has been received by Licensor and subsequently incorporated within the Work.
26
+
27
+ "Commercial Use" shall mean any use of the Work for direct or indirect commercial advantage or monetary compensation.
28
+
29
+ "Qualified Non-Profit Organization" shall mean a Legal Entity that is organized and operated exclusively for religious, charitable, scientific, testing for public safety, literary, or educational purposes, and which is exempt from federal income tax under Section 501(c)(3) of the United States Internal Revenue Code of 1986, as amended, or any equivalent non-profit or charitable organization in a foreign jurisdiction.
30
+
31
+ "Non-Commercial or Research Purposes" shall mean purposes that do not involve any use of the Work or a Derivative Work for Commercial Use.
32
+
33
+ "Threshold" shall mean annual revenue of 10 million United States dollars ($10,000,000) or more.
34
+
35
+ 2. Grant of Copyright License. Subject to the terms and conditions of this License, including the Commercial Use limitation set forth in Section 5, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare Derivative Works of, publicly display, publicly perform, sublicense, and distribute the Work and such Derivative Works in Source or Object form.
36
+
37
+ 3. Grant of Patent License. Subject to the terms and conditions of this License, including the Commercial Use limitation set forth in Section 5, each Contributor hereby grants to You a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable (except as stated in this section) patent license to make, have made, use, offer to sell, sell, import, and otherwise transfer the Work, where such license applies only to those patent claims licensable by such Contributor that are necessarily infringed by their Contribution(s) alone or by combination of their Contribution(s) with the Work to which such Contribution(s) was submitted. If You institute patent litigation against any entity (including a cross-claim or counterclaim in a lawsuit) alleging that the Work or a Contribution incorporated within the Work constitutes direct or contributory patent infringement, then any patent licenses granted to You under this License for that Work shall terminate as of the date such litigation is filed.
38
+
39
+ 4. Redistribution. You may reproduce and distribute copies of the Work or Derivative Works thereof in any medium, with or without modifications, and in Source or Object form, provided that You meet the following conditions:
40
+
41
+ (a) You must give any other recipients of the Work or Derivative Works a copy of this License; and
42
+
43
+ (b) You must cause any modified files to carry prominent notices stating that You changed the files; and
44
+
45
+ (c) You must retain, in the Source form of any Derivative Works that You distribute, all copyright, patent, trademark, and attribution notices from the Source form of the Work, excluding those notices that do not pertain to any part of the Derivative Works; and
46
+
47
+ (d) If the Work includes a "NOTICE" text file as part of its distribution, then any Derivative Works that You distribute must include a readable copy of the attribution notices contained within such NOTICE file, excluding those notices that do not pertain to any part of the Derivative Works, in at least one of the following places: within a NOTICE text file distributed as part of the Derivative Works; within the Source form or documentation, if provided along with the Derivative Works; or, within a display generated by the Derivative Works, if and wherever such third-party notices normally appear. The contents of the NOTICE file are for informational purposes only and do not modify the License. You may add Your own attribution notices within Derivative Works that You distribute, alongside or as an addendum to the NOTICE text from the Work, provided that such additional attribution notices cannot be construed as modifying the License.
48
+
49
+ You may add Your own copyright statement to Your modifications and may provide additional or different license terms and conditions for use, reproduction, or distribution of Your modifications, or for any such Derivative Works as a whole, provided Your use, reproduction, and distribution of the Work otherwise complies with the conditions stated in this License.
50
+
51
+ 5. Commercial Use Limitation.
52
+
53
+ (a) The rights granted under this License for Commercial Use are conditioned upon You or Your Legal Entity not exceeding the Threshold.
54
+
55
+ (b) Any Commercial Use of the Work or a Derivative Work by a Legal Entity that exceeds the Threshold is not licensed under this Agreement.
56
+
57
+ (c) The Threshold shall not apply to a Qualified Non-Profit Organization's use of the Work or a Derivative Work for Non-Commercial or Research Purposes.
58
+
59
+ 6. Submission of Contributions. Unless You explicitly state otherwise, any Contribution intentionally submitted for inclusion in the Work by You to the Licensor shall be under the terms and conditions of this License, without any additional terms or conditions. Notwithstanding the above, nothing herein shall supersede or modify the terms of any separate license agreement you may have executed with Licensor regarding such Contributions.
60
+
61
+ 7. Trademarks. This License does not grant permission to use the trade names, trademarks, service marks, or product names of the Licensor, except for the reasonable and customary use in describing the origin of the Work and reproducing the content of the NOTICE file.
62
+
63
+ 8. Disclaimer of Warranty. Unless required by applicable law or agreed to in writing, Licensor provides the Work (and each Contributor provides its Contributions) on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied, including, without limitation, any warranties or conditions of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A PARTICULAR PURPOSE. You are solely responsible for determining the appropriateness of using or redistributing the Work and assume any risks associated with Your exercise of permissions under this License.
64
+
65
+ 9. Limitation of Liability. In no event and under no legal theory, whether in tort (including negligence), contract, or otherwise, unless required by applicable law (such as deliberate and grossly negligent acts) or agreed to in writing, shall any Contributor be liable to You for damages, including any direct, indirect, special, incidental, or consequential damages of any character arising as a result of this License or out of the use or inability to use the Work (including but not limited to damages for loss of goodwill, work stoppage, computer failure or malfunction, or any and all other commercial damages or losses), even if such Contributor has been advised of the possibility of such damages.
66
+
67
+ 10. Accepting Warranty or Additional Liability. While redistributing the Work or Derivative Works thereof, You may choose to offer, and charge a fee for, acceptance of support, warranty, indemnity, or other liability obligations and/or rights consistent with this License. However, in accepting such obligations, You may act only on Your own behalf and on Your sole responsibility, not on behalf of any other Contributor, and only if You agree to indemnify, defend, and hold each Contributor harmless for any liability incurred by, or claims asserted against, such Contributor by reason of your accepting any such warranty or additional liability.
68
+
69
+ 11. Termination. This License will terminate automatically and immediately if You fail to comply with any of its terms and conditions. Upon termination, You must cease all use of the Work and any Derivative Works and delete all copies in Your possession.
70
+
71
+ END OF TERMS AND CONDITIONS
README.md ADDED
@@ -0,0 +1,125 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ ---
2
+ license: other
3
+ license_name: lfm1.0
4
+ license_link: LICENSE
5
+ base_model: LiquidAI/LFM2-2.6B
6
+ pipeline_tag: text-generation
7
+ library_name: transformers
8
+ language:
9
+ - en
10
+ tags:
11
+ - cybersecurity
12
+ - cyberbench
13
+ - threat-intelligence
14
+ - named-entity-recognition
15
+ - phishing-detection
16
+ - http-anomaly-detection
17
+ - lfm2
18
+ - 2.6b
19
+ datasets:
20
+ - jpmorganchase/CyberBench
21
+ - tihanyin/CyberMetric
22
+ - secbench-hf/SecBench
23
+ - XuanwuAI/SecEval
24
+ ---
25
+
26
+ # Cyber-Prime 1.1 (2.6B)
27
+
28
+ Cyber-Prime 1.1 is a cybersecurity-focused instruction-tuned model in the Liquid Foundation Model (LFM2) family. It is intended for defensive security analysis and cybersecurity text tasks: extracting entities from threat reports, classifying phishing emails and anomalous HTTP requests, answering cybersecurity multiple-choice questions, and producing short threat-intelligence headlines.
29
+
30
+ The checkpoint is a full, merged model. Its training lineage starts from Liquid AI's LFM2-2.6B base through earlier Cyber-Prime checkpoints; the final run continued from the prior Cyber-Prime checkpoint.
31
+
32
+ ## Benchmark results
33
+
34
+ Results below use the official CyberBench test splits and task metrics. Precision and recall are included for the binary classification and NER tasks.
35
+
36
+ | Benchmark | Metric | Score | Precision | Recall | Test examples |
37
+ |---|---|---:|---:|---:|---:|
38
+ | CyNER | Micro F1 | 0.4987 | 0.5434 | 0.4608 | 697 |
39
+ | APTNER | Micro F1 | 0.4903 | 0.5187 | 0.4648 | 1,379 |
40
+ | CyNews | ROUGE-1 / ROUGE-2 / ROUGE-L | 0.4299 / 0.2339 / 0.3875 | — | — | 375 |
41
+ | SecMMLU | Accuracy | 0.6000 | — | — | 100 |
42
+ | CyQuiz | Accuracy | 0.6100 | — | — | 100 |
43
+ | Email phishing detection | Binary F1 | 0.8900 | 0.9378 | 0.8469 | 1,329 |
44
+ | HTTP attack-log analysis | Binary F1 | 0.6283 | 0.6321 | 0.6245 | 1,222 |
45
+
46
+ The unweighted mean of the seven primary scores is **0.5925**. This is a descriptive macro-average across different metric types, not an official CyberBench aggregate. SecMMLU and CyQuiz each have only 100 test examples, so their accuracy estimates have substantial sampling uncertainty.
47
+
48
+ ![Cyber-Prime 1.1 compared with Cyber-Prime 1 and published CyberBench baselines](cyberprime-1.1-benchmark.png)
49
+
50
+ ### Evaluation protocol
51
+
52
+ - Test data were held out from the CyberBench training mix.
53
+ - CyNER, APTNER, SecMMLU, CyQuiz, email, and HTTP used two in-context examples from their training pools. CyNews was evaluated zero-shot, as in the CyberBench setup.
54
+ - Generation used greedy decoding (temperature 0) with the model's chat template. Reasoning text was excluded before task scoring where applicable.
55
+ - Email F1 treats `phishing` as the positive class; HTTP F1 treats `anomalous` as the positive class.
56
+ - The published baseline models in the graphic use the CyberBench paper's retrieval-based five-shot setup (zero-shot for CyNews). Cyber-Prime 1.1 was evaluated with two shots for the non-summarization tasks, so the cross-model bars are useful context, not a strictly matched comparison.
57
+
58
+ ## Training
59
+
60
+ The model was developed through successive supervised and reward-guided post-training stages:
61
+
62
+ 1. A direct gold-supervised pass over 14,510 rows, including CyberBench training examples and 2,000 internally generated cybersecurity NER examples.
63
+ 2. Reward-tilted self-distillation from a 22,130-item mixed prompt pool. The run generated eight candidate responses per selected prompt and distilled 6,000 selected completions. The pool included CyberBench training data, synthetic defensive cybersecurity examples, and external cybersecurity multiple-choice data.
64
+ 3. A final low-learning-rate supervised pass over 3,800 rows: 1,800 CyNews training examples and 2,000 multiple-choice examples from CyberMetric, SecBench, and SecEval.
65
+
66
+ The CyberBench test partitions were not used for training. The model was trained and evaluated in bfloat16 using ChatML-style conversations.
67
+
68
+ ## Intended use
69
+
70
+ - Defensive cybersecurity education and research.
71
+ - Cybersecurity entity extraction from reports and logs.
72
+ - Triage assistance for phishing-email and anomalous-HTTP classification.
73
+ - Cybersecurity multiple-choice question answering.
74
+ - Short threat-intelligence headline generation.
75
+
76
+ Use the model as an assistive component with human review. It is not a substitute for security controls, incident-response procedures, or expert validation, and it is not a reliable autonomous vulnerability assessment or exploitation agent.
77
+
78
+ ## Limitations
79
+
80
+ - Performance is measured on the listed benchmark test sets; it should not be assumed to transfer to every organization, threat actor, protocol, or language.
81
+ - NER recall remains lower than precision, especially for rare or densely packed entities.
82
+ - The MCQ test sets are small, and small score differences may be noise.
83
+ - The published baseline comparison uses a different few-shot count than the Cyber-Prime 1.1 run; prompts and serving stacks can materially change scores.
84
+ - The model can produce incorrect, outdated, or overconfident cybersecurity claims. Verify indicators, classifications, and recommendations independently before taking action.
85
+
86
+ ## Loading
87
+
88
+ ```python
89
+ import torch
90
+ from transformers import AutoModelForCausalLM, AutoTokenizer
91
+
92
+ repo = "Akahsizrr/Cyber-Prime-1.1-2.6B"
93
+ tokenizer = AutoTokenizer.from_pretrained(repo)
94
+ model = AutoModelForCausalLM.from_pretrained(
95
+ repo,
96
+ torch_dtype=torch.bfloat16,
97
+ device_map="auto",
98
+ )
99
+
100
+ messages = [{
101
+ "role": "user",
102
+ "content": "Classify this HTTP request as normal or anomalous: GET /index.html HTTP/1.1",
103
+ }]
104
+ input_ids = tokenizer.apply_chat_template(
105
+ messages,
106
+ tokenize=True,
107
+ add_generation_prompt=True,
108
+ return_tensors="pt",
109
+ ).to(model.device)
110
+ output = model.generate(input_ids, max_new_tokens=256, do_sample=False)
111
+ print(tokenizer.decode(output[0][input_ids.shape[-1]:], skip_special_tokens=True))
112
+ ```
113
+
114
+ Use task-specific instructions and validate the output format expected by your downstream system. For NER, request a JSON object; for email and HTTP classification, request only the benchmark label; for CyNews-like summarization, request a concise headline.
115
+
116
+ ## License
117
+
118
+ This model is derived from **LiquidAI/LFM2-2.6B** and is distributed under the upstream **LFM Open License v1.0**, included in [`LICENSE`](LICENSE). This is a custom license, not Apache-2.0. In particular, Section 5 does not license commercial use by a legal entity with annual revenue of USD 10 million or more; such use requires separate permission from the licensor. Review the complete license before use or redistribution.
119
+
120
+ ## Data and references
121
+
122
+ - Liu, Shi, and Buford, [CyberBench: A Multi-Task Benchmark for Evaluating Large Language Models in Cybersecurity](https://zefang-liu.github.io/files/liu2024cyberbench_paper.pdf), AICS 2024.
123
+ - [CyberBench code and evaluation harness](https://github.com/jpmorganchase/CyberBench).
124
+ - [CyberMetric](https://huggingface.co/datasets/tihanyin/CyberMetric), [SecBench](https://huggingface.co/datasets/secbench-hf/SecBench), and [SecEval](https://huggingface.co/datasets/XuanwuAI/SecEval) supplied additional cybersecurity multiple-choice training examples.
125
+ - Published baseline values in the benchmark graphic are referenced from the [CyberBench results table](https://benchmarklist.com/benchmarks/cyberbench/) and the CyberBench paper; they were not re-run as part of this release evaluation.
cyberprime-1.1-benchmark.png ADDED

Git LFS Details

  • SHA256: 65ba7b4a133fd841554cfb36294eeabd28e3f7947ec9cfcf0a2a127318f24e24
  • Pointer size: 131 Bytes
  • Size of remote file: 405 kB
model-00001-of-00002.safetensors CHANGED
@@ -1,3 +1,3 @@
1
  version https://git-lfs.github.com/spec/v1
2
- oid sha256:b89725fb81d993ef936c82facb7ec158d84da7ee247537a5e2466a14cfd80d93
3
  size 4974941440
 
1
  version https://git-lfs.github.com/spec/v1
2
+ oid sha256:493a46e0c4e0790ec57de129b98f8e6db347fb3878120e088505edb68f4f3990
3
  size 4974941440
model-00002-of-00002.safetensors CHANGED
@@ -1,3 +1,3 @@
1
  version https://git-lfs.github.com/spec/v1
2
- oid sha256:f0c94a6b1d18bf91e33ae20fd8c46cbde08e00f9d1f64ac1c15505d871a12654
3
  size 419485992
 
1
  version https://git-lfs.github.com/spec/v1
2
+ oid sha256:cd37ed75d8b3557aa9818a42bd57a0eb9af83719510c265acd4f99262aa1d570
3
  size 419485992