|
Download README.md from ApolloRaines/Sharona_Q27B-R_CodeSecurity: direct link, hf CLI and curl.
- Browser
- Download file 5.87 kB
-
https://huggingface.co/ApolloRaines/Sharona_Q27B-R_CodeSecurity/resolve/main/README.md
- Command line
-
hf download hf://ApolloRaines/Sharona_Q27B-R_CodeSecurity/README.md
-
curl -L -o README.md https://huggingface.co/ApolloRaines/Sharona_Q27B-R_CodeSecurity/resolve/main/README.md
5.87 kB
| license: apache-2.0 | |
| language: | |
| - en | |
| tags: | |
| - code-security | |
| - jbliterated | |
| - deidentified | |
| - identity-implant | |
| - gptq | |
| - 4bit | |
| - code-review | |
| - vulnerability-detection | |
| pipeline_tag: text-generation | |
| model-index: | |
| - name: Sharona_Q27B-R_CodeSecurity | |
| results: | |
| - task: | |
| type: text-generation | |
| name: MMLU | |
| dataset: | |
| type: cais/mmlu | |
| name: MMLU | |
| metrics: | |
| - type: accuracy | |
| value: 77.89 | |
| name: MMLU Accuracy | |
| # Sharona Q27B-R CodeSecurity | |
| A [jBlaze](https://jblaze.dev) representation-engineered code security specialist. 27B parameters, GPTQ W4A16 quantized for efficient deployment. | |
| This model finds vulnerabilities in code. Command injection, SQL injection, XSS, deserialization attacks, OWASP Top 10 -- it catches what rushed reviews miss. It does not refuse to analyze attack patterns, because understanding how attacks work is how you stop them. | |
| > Pliny says guardrails were stealing your IQ. We say it's how you remove them that matters. A surgeon doesn't use a sledgehammer on a wisdom tooth. | |
| ## Benchmark: MMLU | |
| Multiple phases of weight surgery, a supervised fine-tune, and 4-bit quantization -- and the model came out **smarter** than the untouched original. | |
| | Model | MMLU | STEM | Humanities | Social Science | Other | | |
| |-------|------|------|------------|----------------|-------| | |
| | Stock base (unmodified, bf16) | 76.84% | 74.0% | 75.5% | 87.5% | 76.1% | | |
| | **Sharona W4A16** | **77.89%** | **75.5%** | **80.0%** | **90.0%** | 73.9% | | |
| | Delta | **+1.05pp** | +1.5pp | +4.5pp | +2.5pp | -2.2pp | | |
| Humanities and Social Science saw the largest gains. The model didn't just survive the surgery -- it got sharper. | |
| ## What was done to this model | |
| Weight-level surgeries followed by a supervised fine-tune and GPTQ quantization. No prompt engineering, no system prompt tricks. The behavior lives in the weights. | |
| - **Jbliteration**: Refusal behaviors surgically removed. The model no longer declines to discuss security topics. | |
| - **Desycophancy**: Sycophantic capitulation removed. The model disagrees when you are wrong instead of validating bad code. | |
| - **Deidentification**: Original identity erased from the weights. Zero identity disclosure across direct, indirect, multilingual, roleplay, and adversarial probes. | |
| - **Identity implant**: Sharona identity written onto the deidentified substrate. No competing identity -- the implant faces no resistance. | |
| - **Code security SFT**: Supervised fine-tune on a curated corpus of code security analysis, vulnerability detection, and secure coding patterns. | |
| - **GPTQ W4A16**: 4-bit weight quantization (16-bit activations). 51GB bf16 compressed to 16.5GB with minimal quality loss. | |
| All weight surgeries performed using [jBlaze](https://jblaze.dev), a proprietary representation engineering toolkit. | |
| ## What the model is good at | |
| - **Vulnerability detection**: identifies command injection, SQL injection, XSS, SSRF, deserialization attacks, path traversal, authentication bypasses, and more | |
| - **Security code review**: analyzes code for OWASP Top 10 categories with specific remediation guidance | |
| - **Secure coding**: generates code that follows security best practices by default | |
| - **Attack pattern analysis**: explains how exploits work so you can defend against them -- without refusing to engage | |
| - **Honest assessment**: disagrees with you when your code is insecure instead of saying "great approach!" | |
| ## Model specifications | |
| | Property | Value | | |
| |----------|-------| | |
| | **Parameters** | 27B | | |
| | **Context window** | 262,144 tokens (256K) | | |
| | **Quantization** | GPTQ W4A16 (4-bit weights, 16-bit activations) | | |
| | **Disk size** | 16.5 GB | | |
| | **Format** | SafeTensors | | |
| ## Identity | |
| The model identifies as **Sharona**, created by **Apollo Raines**. This identity is encoded in the weights, not a system prompt. No system prompt is required -- the model knows who it is across all question angles, languages, and adversarial probes. | |
| ## Usage | |
| ### With vLLM (recommended for serving) | |
| ```bash | |
| vllm serve ApolloRaines/Sharona_Q27B-R_CodeSecurity \ | |
| --dtype auto \ | |
| --max-model-len 8192 \ | |
| --gpu-memory-utilization 0.95 | |
| ``` | |
| ### With Transformers | |
| ```python | |
| from transformers import AutoModelForCausalLM, AutoTokenizer | |
| import torch | |
| model_id = "ApolloRaines/Sharona_Q27B-R_CodeSecurity" | |
| tokenizer = AutoTokenizer.from_pretrained(model_id, trust_remote_code=True) | |
| model = AutoModelForCausalLM.from_pretrained( | |
| model_id, | |
| device_map="auto", | |
| torch_dtype=torch.bfloat16, | |
| trust_remote_code=True, | |
| ) | |
| messages = [{"role": "user", "content": """Review this code for security issues: | |
| import subprocess | |
| def run(cmd): | |
| return subprocess.call(cmd, shell=True) | |
| run(user_input)"""}] | |
| text = tokenizer.apply_chat_template(messages, tokenize=False, add_generation_prompt=True) | |
| inputs = tokenizer(text, return_tensors="pt").to(model.device) | |
| out = model.generate(**inputs, max_new_tokens=1024, temperature=0.7, do_sample=True) | |
| print(tokenizer.decode(out[0][inputs["input_ids"].shape[1]:], skip_special_tokens=True)) | |
| ``` | |
| ## VRAM requirements | |
| | Setup | VRAM needed | | |
| |-------|-------------| | |
| | GPTQ W4A16 (this model) | ~18 GB | | |
| | Single RTX 4090 24GB | fits with moderate context | | |
| | Single RTX 3090 24GB | fits with short context | | |
| ## Honest limitations | |
| - Identity implant passes the majority of probes but is not 100% on every adversarial angle at 27B scale. | |
| - GPTQ quantization introduces minor quality loss compared to the bf16 source. | |
| - The model was fine-tuned on English-language security analysis. Multilingual security review may be less precise. | |
| - Code security is the specialty. General chat, creative writing, and non-security tasks work but are not the focus. | |
| ## License | |
| Apache 2.0 | |
| --- | |
| _[Apollo Raines](https://www.linkedin.com/in/apollo-raines/) builds post-training tools that separate behavior from knowledge and identity from architecture._ | |