Text Generation
PEFT
Safetensors
English
cybersecurity
soc-triage
threat-detection
qlora
qwen3
conversational
Instructions to use minar-svn/ThreatQwen-1.7B-Detect with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- PEFT
How to use minar-svn/ThreatQwen-1.7B-Detect with PEFT:
from peft import PeftModel from transformers import AutoModelForCausalLM base_model = AutoModelForCausalLM.from_pretrained("unsloth/Qwen3-1.7B-unsloth-bnb-4bit") model = PeftModel.from_pretrained(base_model, "minar-svn/ThreatQwen-1.7B-Detect") - Notebooks
- Google Colab
- Kaggle
| license: apache-2.0 | |
| base_model: unsloth/Qwen3-1.7B-unsloth-bnb-4bit | |
| language: | |
| - en | |
| tags: | |
| - cybersecurity | |
| - soc-triage | |
| - threat-detection | |
| - qlora | |
| - peft | |
| - qwen3 | |
| pipeline_tag: text-generation | |
| library_name: peft | |
| # ThreatQwen-1.7B-Detect | |
| A QLoRA fine-tune of **Qwen3-1.7B-Instruct** for cybersecurity event triage. Given a raw security event (Sysmon, CloudTrail, HTTP log, etc.), the model returns a structured JSON verdict. | |
| ## Results | |
| Evaluated on a balanced held-out test set of **882 samples (441 malicious + 441 benign)**: | |
| | Model | Accuracy | Mal. Recall | Ben. Recall | Macro F1 | | |
| |---|---|---|---|---| | |
| | **ThreatQwen-1.7B-Detect (ours)** | **95.1%** | **96.1%** | **94.2%** | **0.951** | | |
| | Base Qwen3-1.7B (no fine-tune) | 85.1% | 92.1% | 78.2% | 0.851 | | |
| | GPT-4o (Azure, zero-shot) | 51.8% | 85.0% | 18.6% | 0.458 | | |
| | GPT-4o-mini (Azure, zero-shot) | 51.9% | 59.6% | 44.2% | 0.516 | | |
| Fine-tuning improves the base model by **+10 percentage points** and outperforms GPT-4o by **+43.3 percentage points**. | |
| ## Output Schema | |
| ```json | |
| {"verdict": "malicious | benign"} | |
| ``` | |
| ## Training | |
| | Parameter | Value | | |
| |---|---| | |
| | Base model | unsloth/Qwen3-1.7B-unsloth-bnb-4bit | | |
| | Method | QLoRA 4-bit NF4 | | |
| | LoRA rank / alpha | 16 / 32 | | |
| | Epochs | 3 | | |
| | Effective batch size | 16 (batch 4 × accum 4) | | |
| | Learning rate | 2e-4 cosine | | |
| | MAX_SEQ_LEN | 512 | | |
| | Hardware | Tesla T4 (Kaggle free tier) | | |
| | Training time | ~10 min | | |
| ## Dataset | |
| Combines SigmaHQ, Elastic Detection Rules, and Nuclei templates (~5,823 real malicious events) with GPT-4o-generated synthetic benign examples (~3,743 benign covering Windows, web, email, database, VPN/remote-access). Full dataset: [minar-svn/ThreatQwen-detection-dataset](https://huggingface.co/datasets/minar-svn/ThreatQwen-detection-dataset) | |
| ## Deployment | |
| - Fully offline — no internet required (air-gapped SOC capable) | |
| - ~3.1 GB VRAM (4-bit quantized) | |
| - ~18 tokens/sec on Tesla T4 | |
| - ~5–7 sec/event latency | |
| - Adapter: ~434 MB | |
| - Min GPU: RTX 3060 (8 GB) | |
| ## Usage | |
| ```python | |
| from transformers import AutoModelForCausalLM, AutoTokenizer | |
| from peft import PeftModel | |
| import torch, json | |
| base = AutoModelForCausalLM.from_pretrained( | |
| "unsloth/Qwen3-1.7B-unsloth-bnb-4bit", | |
| torch_dtype=torch.float16, device_map="auto", | |
| ) | |
| model = PeftModel.from_pretrained(base, "minar-svn/ThreatQwen-1.7B-Detect") | |
| tokenizer = AutoTokenizer.from_pretrained("minar-svn/ThreatQwen-1.7B-Detect") | |
| SYSTEM = 'You are a cybersecurity detection model. Respond ONLY with valid JSON. Format: {"verdict": "malicious | benign"}' | |
| event = "EventID: 1 Image: rundll32.exe CommandLine: comsvcs.dll MiniDump User: admin" | |
| msgs = [{"role":"system","content":SYSTEM},{"role":"user","content":f"Analyze:\n\n{event}"}] | |
| prompt = tokenizer.apply_chat_template(msgs, tokenize=False, add_generation_prompt=True).strip() | |
| inputs = tokenizer(prompt, return_tensors="pt").to(model.device) | |
| with torch.no_grad(): | |
| out = model.generate(**inputs, max_new_tokens=40, do_sample=False, | |
| pad_token_id=tokenizer.eos_token_id) | |
| response = tokenizer.decode(out[0][inputs["input_ids"].shape[1]:], skip_special_tokens=True).strip() | |
| blocks = [b.strip() for b in response.split("\n\n") if b.strip()] | |
| print(json.loads(blocks[-1])) | |
| # {"verdict": "malicious"} | |
| ``` | |
| ## Limitations | |
| - All benign test examples are synthetic — real-world benign generalization untested | |
| - English only | |
| - Analyst aid only — not a sole decision authority | |
| ## Citation | |
| ```bibtex | |
| @misc{threatqwen2026, | |
| author = {Md. Minaruzzaman Shovon}, | |
| title = {ThreatQwen-1.7B-Detect}, | |
| year = {2026}, | |
| publisher = {Hugging Face}, | |
| url = {https://huggingface.co/minar-svn/ThreatQwen-1.7B-Detect} | |
| } | |
| ``` | |
| ## License | |
| Apache 2.0 | |