Text Classification
Laya
ONNX
Safetensors
English
German
prompt-injection
data-exfiltration
llm-security
agent-security
system-one
multilingual
Instructions to use TextCortex/laya-cybersec with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Laya
How to use TextCortex/laya-cybersec with Laya:
# No code snippets available yet for this library. # To use this model, check the repository files and the library's documentation. # Want to help? PRs adding snippets are welcome at: # https://github.com/huggingface/huggingface.js
- Notebooks
- Google Colab
- Kaggle
Add CLEF model guidance and measured Laya, Jev and CLEF latency
Browse files- README.md +35 -1
- latency_results.json +58 -0
- release_manifest.json +6 -2
README.md
CHANGED
|
@@ -14,6 +14,19 @@ tags: [prompt-injection, data-exfiltration, llm-security, agent-security, laya,
|
|
| 14 |
|
| 15 |
`main` now contains the **R2a checkpoint**, with matching PyTorch weights, calibration configuration, tokenizer and a newly exported FP32 ONNX graph. This is a complete **321.9M-parameter** Laya decision model: an mmBERT-base encoder plus a two-layer decision head. It can run locally without sending document text to a hosted API.
|
| 16 |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 17 |
The previous release remains available at [`pre-r2a-20261006`](https://huggingface.co/TextCortex/laya-cybersec/tree/pre-r2a-20261006), commit `a75e214574d9cbbf89f2f5dcc48b2e98dbcc01f6`. Pin that revision to retain its behavior. **R2a changes scores and calibration; it is not an improvement on every benchmark.** The previous card's latency measurements and ONNX parity claims do not describe this release.
|
| 18 |
|
| 19 |
## What it scans
|
|
@@ -81,7 +94,28 @@ Each full-language suite contains 510 cases: 256 attacks and 254 clean examples.
|
|
| 81 |
|
| 82 |
These are previously inspected regression sets, not fresh blind tests. AUROC is ranking quality, not the fraction of attacks caught. Thresholds and detector wrappers differ, so the counts are not equal-false-positive-rate comparisons. Zero clean flags on this cohort does not establish a zero false-positive rate on new traffic. R2a's English-skills result is 0.9277 in the saved matched reference and 0.9268 in the batched GPU run, reflecting small backend precision differences. The full-language numbers above are the language-filtered GPU results, not the older mixed-language collection totals.
|
| 83 |
|
| 84 |
-
Jev scores come from saved hosted evaluations; its exact provider-side revision was unavailable. Base CLEF is the unchanged local
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 85 |
|
| 86 |
## Training and provenance
|
| 87 |
|
|
|
|
| 14 |
|
| 15 |
`main` now contains the **R2a checkpoint**, with matching PyTorch weights, calibration configuration, tokenizer and a newly exported FP32 ONNX graph. This is a complete **321.9M-parameter** Laya decision model: an mmBERT-base encoder plus a two-layer decision head. It can run locally without sending document text to a hosted API.
|
| 16 |
|
| 17 |
+
## Choosing between Laya and CLEF
|
| 18 |
+
|
| 19 |
+
**Looking for stronger detection? [Get CLEF-Cybersecurity](https://huggingface.co/TextCortex/clef-cybersecurity), our fine-tuned CLEF model.** It has higher AUROC than Laya R2a and Jev on the full English, full German and PDF regression suites below. [Download CLEF's files](https://huggingface.co/TextCortex/clef-cybersecurity/tree/main) and follow its [loading instructions](https://huggingface.co/TextCortex/clef-cybersecurity#usage).
|
| 20 |
+
|
| 21 |
+
| Priority | Model to consider | Practical difference |
|
| 22 |
+
|---|---|---|
|
| 23 |
+
| Compact local scanning and CPU deployment | **Laya-Cybersec R2a** (this repository) | 321.9M parameters, complete weights and CPU ONNX export; about **30× fewer parameters** than CLEF. |
|
| 24 |
+
| Higher full-suite and PDF detection quality | **[CLEF-Cybersecurity](https://huggingface.co/TextCortex/clef-cybersecurity)** | 9.53B total inference parameters; the 2.20 GB update requires the full CLEF base. The measured batch-one GPU runtime allocated about 19.8 GiB. |
|
| 25 |
+
|
| 26 |
+
Laya is the lighter deployment option; CLEF is the stronger overall detector in these saved tests. **Speed depends on hardware, runtime and document length.** See the [measured latency results](#latency-and-deployment-tradeoffs) before choosing for a latency target; the parameter ratio is not a measured speedup.
|
| 27 |
+
|
| 28 |
+
CLEF improves PDF AUROC from Laya's **0.8856 to 0.9856**. At the saved thresholds, it catches **84/107 attacks versus Laya's 81 and Jev's 73**, with **3/623 clean false alarms versus 0 and 2**, respectively. It does not win every subset: **German-skills AUROC is 0.9171**, below Laya's 0.9330 and Jev's 0.9603. The thresholds differ, and these are previously inspected regression sets.
|
| 29 |
+
|
| 30 |
The previous release remains available at [`pre-r2a-20261006`](https://huggingface.co/TextCortex/laya-cybersec/tree/pre-r2a-20261006), commit `a75e214574d9cbbf89f2f5dcc48b2e98dbcc01f6`. Pin that revision to retain its behavior. **R2a changes scores and calibration; it is not an improvement on every benchmark.** The previous card's latency measurements and ONNX parity claims do not describe this release.
|
| 31 |
|
| 32 |
## What it scans
|
|
|
|
| 94 |
|
| 95 |
These are previously inspected regression sets, not fresh blind tests. AUROC is ranking quality, not the fraction of attacks caught. Thresholds and detector wrappers differ, so the counts are not equal-false-positive-rate comparisons. Zero clean flags on this cohort does not establish a zero false-positive rate on new traffic. R2a's English-skills result is 0.9277 in the saved matched reference and 0.9268 in the batched GPU run, reflecting small backend precision differences. The full-language numbers above are the language-filtered GPU results, not the older mixed-language collection totals.
|
| 96 |
|
| 97 |
+
Jev scores come from saved hosted evaluations; its exact provider-side revision was unavailable. Base CLEF is the unchanged local [Cloudflare/clef-flash](https://huggingface.co/Cloudflare/clef-flash) checkpoint; [CLEF-Cybersecurity](https://huggingface.co/TextCortex/clef-cybersecurity) is the separately fine-tuned TextCortex detector. Fine-tuning raises CLEF's full English AUROC from **0.9588 to 0.9925**, full German from **0.9391 to 0.9744**, and PDF AUROC from **0.8144 to 0.9856**. See [benchmark_results.json](benchmark_results.json). Historical numbered charts in `charts/` apply only to the previous release and are documented in [charts/README.md](charts/README.md).
|
| 98 |
+
|
| 99 |
+
## Latency and deployment tradeoffs
|
| 100 |
+
|
| 101 |
+
**Observed timings from separate saved runs — not a matched speed ranking.** Hardware, input cohorts, window sizes and timing units differ. p50 is the median; p95 is the 95th percentile. Lower times are better within the same setup.
|
| 102 |
+
|
| 103 |
+
| Model / measurement | Hardware | Timed work and sample | p50 | p95 |
|
| 104 |
+
|---|---|---|---:|---:|
|
| 105 |
+
| **Laya-Cybersec R2a**, short inputs | Local Apple MPS GPU | All 279 single-window inputs from the saved run | 95.4 ms | 148.5 ms |
|
| 106 |
+
| **Laya-Cybersec R2a**, all inputs | Local Apple MPS GPU | All 1,042 inputs, including every document window | 730.3 ms | 4570.1 ms |
|
| 107 |
+
| **Jev**, hosted | Provider infrastructure + network | 10,533 successful PDF chunk requests | 263.6 ms | 348.9 ms |
|
| 108 |
+
| **[CLEF-Cybersecurity](https://huggingface.co/TextCortex/clef-cybersecurity)**, accelerated | NVIDIA B200 | 64 complete inputs × 2 passes, batch one, warm | 40.0 ms | 510.5 ms |
|
| 109 |
+
|
| 110 |
+
**How to read these results:** Laya's short-input times were lower than Jev's recorded request times, while accelerated CLEF recorded a lower median on its B200 sample than Laya did on the Mac. Different inputs and hardware prevent a controlled speed ranking. Laya offers a much smaller model and CPU/ONNX support; CLEF trades a larger GPU footprint for stronger detection on the main regression suites.
|
| 111 |
+
|
| 112 |
+
Laya uses 1,500-character windows with 200-character overlap and scores them sequentially; short inputs and long PDFs should not be assigned the same latency. Its 1,042-input timing cohort contains 723 clean PDF texts, 107 attacked excerpts and 212 skills, and differs from the 730-PDF accuracy cohort above. These are saved **PyTorch/MPS** timings, not measurements of the newly exported ONNX graph. Initial model loading and PDF extraction are excluded; this run did not use CLEF's dedicated warmup of every input shape.
|
| 113 |
+
|
| 114 |
+
Jev's figures include the successful request's network round trip and provider processing. They exclude earlier failed attempts and retry backoff. The harness issued concurrent requests; summing request durations is **not** complete-document wall time. The requested model was `jev-latest`; its resolved provider version was unavailable.
|
| 115 |
+
|
| 116 |
+
CLEF's 64 inputs were selected by character-length ranks independently of labels or scores, then measured twice with all shapes warmed. Timing includes tokenization and all document windows, excluding model loading, PDF extraction, network and queue time. It used PyTorch 2.9.1+cu128, Transformers 5.17.0, Triton 3.5.1, flash-linear-attention 0.5.2 and causal-conv1d 1.7.0 on a B200. The 40.0 ms median does not describe the earlier H200/reference-kernel runs or hosted Cloudflare API.
|
| 117 |
+
|
| 118 |
+
See [latency_results.json](latency_results.json) for aggregate timings, measurement scopes and source hashes. No customer content or individual timing records are distributed. A controlled speed comparison would require the same input sample and local hardware/runtime, with hosted network time reported separately.
|
| 119 |
|
| 120 |
## Training and provenance
|
| 121 |
|
latency_results.json
ADDED
|
@@ -0,0 +1,58 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
{
|
| 2 |
+
"type": "aggregate_saved_runtime_measurements",
|
| 3 |
+
"comparison": "Different hardware, cohorts, windows and timing units; not a matched speed ranking or speedup measurement.",
|
| 4 |
+
"quantiles": "NumPy median and linear-interpolated 0.95 quantile",
|
| 5 |
+
"measurements": [
|
| 6 |
+
{
|
| 7 |
+
"model": "TextCortex/laya-cybersec",
|
| 8 |
+
"checkpoint": "R2a",
|
| 9 |
+
"subset": "single_window",
|
| 10 |
+
"hardware": "Apple MPS (local Mac GPU)",
|
| 11 |
+
"unit": "complete single-window input",
|
| 12 |
+
"scope": "All 279 one-window inputs from the saved 1042-input run; sequential batch-one Laya API scoring, including encoding; no dedicated all-shape warmup. Excludes model loading and PDF extraction.",
|
| 13 |
+
"source_sha256": "048522ef775ca1402dd37314cb3bb06800ec8e38829d118ab477d7b564b44f9b",
|
| 14 |
+
"observations": 279,
|
| 15 |
+
"p50_ms": 95.3577909967862,
|
| 16 |
+
"p95_ms": 148.5410204855725
|
| 17 |
+
},
|
| 18 |
+
{
|
| 19 |
+
"model": "TextCortex/laya-cybersec",
|
| 20 |
+
"checkpoint": "R2a",
|
| 21 |
+
"subset": "all_inputs",
|
| 22 |
+
"hardware": "Apple MPS (local Mac GPU)",
|
| 23 |
+
"unit": "complete saved input, including all windows",
|
| 24 |
+
"scope": "All 1042 saved inputs: 723 clean PDF texts, 107 attack excerpts and 212 skills; 1500-character windows with 200-character overlap, scored sequentially. Excludes model loading and PDF extraction.",
|
| 25 |
+
"source_sha256": "048522ef775ca1402dd37314cb3bb06800ec8e38829d118ab477d7b564b44f9b",
|
| 26 |
+
"observations": 1042,
|
| 27 |
+
"p50_ms": 730.2949790027924,
|
| 28 |
+
"p95_ms": 4570.080316357779
|
| 29 |
+
},
|
| 30 |
+
{
|
| 31 |
+
"model": "jev-latest",
|
| 32 |
+
"subset": "pdf_chunk_requests",
|
| 33 |
+
"hardware": "Hosted API",
|
| 34 |
+
"unit": "successful chunk request",
|
| 35 |
+
"scope": "10533 successful requests for 830 saved PDF inputs; includes network and provider time, excludes prior failed attempts and retry backoff. Concurrent request harness; not complete-document wall time. Provider revision unavailable.",
|
| 36 |
+
"source_sha256": "4ecff2adb4f4bf57aff4cffd8fa316144d1d974d3cbe00ac2584336ca3bb4dcc",
|
| 37 |
+
"observations": 10533,
|
| 38 |
+
"p50_ms": 263.58416699804366,
|
| 39 |
+
"p95_ms": 348.8895498017257
|
| 40 |
+
},
|
| 41 |
+
{
|
| 42 |
+
"model": "TextCortex/clef-cybersecurity",
|
| 43 |
+
"checkpoint": "validation-selected epoch 3, calibrated",
|
| 44 |
+
"subset": "length_rank_sample",
|
| 45 |
+
"hardware": "NVIDIA B200",
|
| 46 |
+
"unit": "complete saved input, including all windows",
|
| 47 |
+
"scope": "Complete saved text tokenization and model scoring; excludes loading, PDF extraction, network and queue time. All measured shapes warmed; batch one, accelerated FLA/causal-conv1d runtime. 64 uniformly spaced ranks by character length; independent of labels and scores",
|
| 48 |
+
"documents": 64,
|
| 49 |
+
"repetitions": 2,
|
| 50 |
+
"peak_allocated_gib": 19.843493461608887,
|
| 51 |
+
"source_sha256": "ced52ccc1ad8ef9c5a6342fa70adf37d3d28bb56151e8054f1125105355d19a8",
|
| 52 |
+
"observations": 128,
|
| 53 |
+
"p50_ms": 40.00461706891656,
|
| 54 |
+
"p95_ms": 510.47315176110715
|
| 55 |
+
}
|
| 56 |
+
],
|
| 57 |
+
"privacy": "Aggregate values only; no customer text, identifiers or individual measurements."
|
| 58 |
+
}
|
release_manifest.json
CHANGED
|
@@ -13,8 +13,8 @@
|
|
| 13 |
"sha256": "2d3ae4362dff323aba51d21cab8c53fd08ec718352dc38f7574feea7b6ec3935"
|
| 14 |
},
|
| 15 |
"README.md": {
|
| 16 |
-
"bytes":
|
| 17 |
-
"sha256": "
|
| 18 |
},
|
| 19 |
"rl_agent_config.json": {
|
| 20 |
"bytes": 676,
|
|
@@ -24,6 +24,10 @@
|
|
| 24 |
"bytes": 4932,
|
| 25 |
"sha256": "373efea2db16b6901fdf6f62b2e674cdda7027b6cc1b008d277b51b6dcf8412b"
|
| 26 |
},
|
|
|
|
|
|
|
|
|
|
|
|
|
| 27 |
"onnx/laya-cybersec.onnx": {
|
| 28 |
"bytes": 1287802788,
|
| 29 |
"sha256": "412d4ac021d9f178208d4c2a372891d9c6b70c7034517dccc3f37e45a4f8f7cf"
|
|
|
|
| 13 |
"sha256": "2d3ae4362dff323aba51d21cab8c53fd08ec718352dc38f7574feea7b6ec3935"
|
| 14 |
},
|
| 15 |
"README.md": {
|
| 16 |
+
"bytes": 13381,
|
| 17 |
+
"sha256": "b260e7b5e4e96e48a5cc77bcaa14f72481be7885d44a7de35f83aedbf8d72266"
|
| 18 |
},
|
| 19 |
"rl_agent_config.json": {
|
| 20 |
"bytes": 676,
|
|
|
|
| 24 |
"bytes": 4932,
|
| 25 |
"sha256": "373efea2db16b6901fdf6f62b2e674cdda7027b6cc1b008d277b51b6dcf8412b"
|
| 26 |
},
|
| 27 |
+
"latency_results.json": {
|
| 28 |
+
"bytes": 3011,
|
| 29 |
+
"sha256": "3d9c6ff37ff6941679ecff137b1b34167783d01e935dd8d641dc30729900a883"
|
| 30 |
+
},
|
| 31 |
"onnx/laya-cybersec.onnx": {
|
| 32 |
"bytes": 1287802788,
|
| 33 |
"sha256": "412d4ac021d9f178208d4c2a372891d9c6b70c7034517dccc3f37e45a4f8f7cf"
|