Instructions to use BrainboxAI/cyber-analyst-4B-verifier-pilot with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with Transformers:
# Use a pipeline as a high-level helper from transformers import pipeline pipe = pipeline("text-generation", model="BrainboxAI/cyber-analyst-4B-verifier-pilot") messages = [ {"role": "user", "content": "Who are you?"}, ] pipe(messages)# Load model directly from transformers import AutoModel model = AutoModel.from_pretrained("BrainboxAI/cyber-analyst-4B-verifier-pilot", device_map="auto") - Notebooks
- Google Colab
- Kaggle
- Local Apps Settings
- llama.cpp
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with llama.cpp:
Install (macOS, Linux)
curl -LsSf https://llama.app/install.sh | sh # Start a local OpenAI-compatible server with a web UI: llama serve -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M # Run inference directly in the terminal: llama cli -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
Install from WinGet (Windows)
winget install llama.cpp # Start a local OpenAI-compatible server with a web UI: llama serve -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M # Run inference directly in the terminal: llama cli -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
Use pre-built binary
# Download pre-built binary from: # https://github.com/ggerganov/llama.cpp/releases # Start a local OpenAI-compatible server with a web UI: ./llama-server -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M # Run inference directly in the terminal: ./llama-cli -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
Build from source code
git clone https://github.com/ggerganov/llama.cpp.git cd llama.cpp cmake -B build cmake --build build -j --target llama-server llama-cli # Start a local OpenAI-compatible server with a web UI: ./build/bin/llama-server -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M # Run inference directly in the terminal: ./build/bin/llama-cli -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
Use Docker
docker model run hf.co/BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
- LM Studio
- Jan
- vLLM
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with vLLM:
Install from pip and serve model
# Install vLLM from pip: pip install vllm # Start the vLLM server: vllm serve "BrainboxAI/cyber-analyst-4B-verifier-pilot" # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:8000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "BrainboxAI/cyber-analyst-4B-verifier-pilot", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker
docker model run hf.co/BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
- SGLang
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with SGLang:
Install from pip and serve model
# Install SGLang from pip: pip install sglang # Start the SGLang server: python3 -m sglang.launch_server \ --model-path "BrainboxAI/cyber-analyst-4B-verifier-pilot" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "BrainboxAI/cyber-analyst-4B-verifier-pilot", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker images
docker run --gpus all \ --shm-size 32g \ -p 30000:30000 \ -v ~/.cache/huggingface:/root/.cache/huggingface \ --env "HF_TOKEN=<secret>" \ --ipc=host \ lmsysorg/sglang:latest \ python3 -m sglang.launch_server \ --model-path "BrainboxAI/cyber-analyst-4B-verifier-pilot" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "BrainboxAI/cyber-analyst-4B-verifier-pilot", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }' - Ollama
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with Ollama:
ollama run hf.co/BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
- Unsloth Studio
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with Unsloth Studio:
Install Unsloth Studio (macOS, Linux, WSL)
curl -fsSL https://unsloth.ai/install.sh | sh # Run unsloth studio unsloth studio -H 0.0.0.0 -p 8888 # Then open http://localhost:8888 in your browser # Search for BrainboxAI/cyber-analyst-4B-verifier-pilot to start chatting
Install Unsloth Studio (Windows)
irm https://unsloth.ai/install.ps1 | iex # Run unsloth studio unsloth studio -H 0.0.0.0 -p 8888 # Then open http://localhost:8888 in your browser # Search for BrainboxAI/cyber-analyst-4B-verifier-pilot to start chatting
Using HuggingFace Spaces for Unsloth
# No setup required # Open https://huggingface.co/spaces/unsloth/studio in your browser # Search for BrainboxAI/cyber-analyst-4B-verifier-pilot to start chatting
- Pi
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with Pi:
Start the llama.cpp server
# Install llama.cpp: brew install llama.cpp # Start a local OpenAI-compatible server: llama serve -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
Configure the model in Pi
# Install Pi: npm install -g @mariozechner/pi-coding-agent # Add to ~/.pi/agent/models.json: { "providers": { "llama-cpp": { "baseUrl": "http://localhost:8080/v1", "api": "openai-completions", "apiKey": "none", "models": [ { "id": "BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M" } ] } } }Run Pi
# Start Pi in your project directory: pi
- Docker Model Runner
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with Docker Model Runner:
docker model run hf.co/BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
- Lemonade
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with Lemonade:
Pull the model
# Download Lemonade from https://lemonade-server.ai/ lemonade pull BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
Run and chat with the model
lemonade run user.cyber-analyst-4B-verifier-pilot-Q4_K_M
List all available models
lemonade list
- Hermes Agent
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with Hermes Agent:
Start the llama.cpp server
# Install llama.cpp: brew install llama.cpp # Start a local OpenAI-compatible server: llama serve -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
Configure Hermes
# Install Hermes: curl -fsSL https://hermes-agent.nousresearch.com/install.sh | bash hermes setup # Point Hermes at the local server: hermes config set model.provider custom hermes config set model.base_url http://127.0.0.1:8080/v1 hermes config set model.default BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
Run Hermes
hermes
- Atomic Chat
- OpenClaw
How to use BrainboxAI/cyber-analyst-4B-verifier-pilot with OpenClaw:
Start the llama.cpp server
# Install llama.cpp: brew install llama.cpp # Start a local OpenAI-compatible server: llama serve -hf BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M
Configure OpenClaw
# Install OpenClaw: npm install -g openclaw@latest # Register the local server and set it as the default model: openclaw onboard --non-interactive --mode local \ --auth-choice custom-api-key \ --custom-base-url http://127.0.0.1:8080/v1 \ --custom-model-id "BrainboxAI/cyber-analyst-4B-verifier-pilot:Q4_K_M" \ --custom-provider-id llama-cpp \ --custom-compatibility openai \ --custom-text-input \ --accept-risk \ --skip-health
Run OpenClaw
openclaw agent --local --agent main --message "Hello from Hugging Face"
d984dcb 0ec8eca af83459 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca d984dcb be7c5e6 72f0c2f be7c5e6 0ec8eca d984dcb 913bcfc d984dcb 913bcfc 0ec8eca 913bcfc d984dcb 0ec8eca d984dcb 0ec8eca 913bcfc d984dcb 0ec8eca d984dcb 0ec8eca d984dcb 0ec8eca | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 | ---
language:
- he
- en
license: apache-2.0
library_name: transformers
base_model: BrainboxAI/cyber-analyst-4B
base_model_relation: finetune
pipeline_tag: text-generation
tags:
- cybersecurity
- security
- vulnerability-verification
- finding-verifier
- bug-bounty
- triage
- hebrew
- israel
- gemma4
- unsloth
- lora
- gguf
- pilot
pretty_name: Cyber-Analyst 4B (Verifier Pilot)
---
# Cyber-Analyst 4B: Verifier Pilot
A LoRA fine-tune of [`cyber-analyst-4B`](https://huggingface.co/BrainboxAI/cyber-analyst-4B) that adds a strict finding-verifier behavior. Given the evidence for a suspected web vulnerability, it decides whether the evidence actually proves the bug, and rejects the ones that only look real.
[](https://huggingface.co/BrainboxAI/cyber-analyst-4B)
[-orange)](https://github.com/unslothai/unsloth)
[]()
[]()
[](https://www.apache.org/licenses/LICENSE-2.0)
> [!WARNING]
> This is a pilot. It was trained on a small (~100 example) balanced set to check the
> recipe before scaling. It lives in its own repo and does not replace the production
> [`cyber-analyst-4B`](https://huggingface.co/BrainboxAI/cyber-analyst-4B).
## What it does
You give it the evidence for a suspected vulnerability (tool, URL, payload, response
snippet, PoC). It returns a JSON verdict:
```json
{"verdict": "true_positive | false_positive | inconclusive", "reason": "..."}
```
It judges the evidence, not the scary-looking payload. That is the difference between
a verifier and a scanner. It is trained to reject the look-alikes that fool most tools:
| Looks like a finding | Why it is a false positive |
|---|---|
| SQLi, got a 500 | a generic 500 with no DB error and no extracted data proves nothing |
| blind boolean SQLi | the true and false conditions returned identical responses |
| reflected XSS | the payload came back HTML-encoded or JS-escaped, so it cannot run |
| SSRF to a metadata IP | `ECONNREFUSED`. the request was blocked, no internal data returned |
| IDOR by enumerating IDs | every non-owned ID returned 403; authorization is enforced |
| path traversal with a null byte | 404, no `/etc/passwd` contents; the bypass read no sensitive file |
| JWT with alg=none | the server rejected it with 401 |
When something is genuinely suspicious but not confirmed, it answers `inconclusive` and
says what evidence is still missing (a differential test, a decoded token, an extracted
row). It also knows who it is (Cyber-Analyst 4B, by BrainboxAI), in Hebrew and English.
## Lineage
```
Google Gemma-4 E4B
-> cyber-analyst-4B (1.27M security examples, BrainboxAI)
-> this pilot (verifier + identity LoRA delta)
```
## Training
| | |
|---|---|
| Base | `BrainboxAI/cyber-analyst-4B` (weights kept; this only adds a delta) |
| Method | bf16 LoRA (Unsloth), r=16 / alpha=32, LR 1e-4, 3 epochs, cosine, seq 2048 |
| Data | ~100 balanced verifier examples (true / false / inconclusive, with adversarial hard negatives across 19 vuln classes) plus a small share of bilingual identity |
| Eval | held-out split, `eval_loss` around 1.13 |
| Hardware | one RTX 4090, ~16GB VRAM |
## Benchmark: does the delta actually reject false positives?
The whole point of the verifier delta is to stop the model from confirming
vulnerabilities that only look real. So the benchmark measures exactly that.
17 held-out examples (never seen in training): 8 true positives, 6 false
positives, 3 inconclusive. Each is a suspected finding with its evidence. The
model returns a verdict. Thinking mode is disabled with an assistant prefill so
the model answers directly. Same test, same prompt, run against the base and the
pilot.

The base model confirms everything. It says `true_positive` to all 8 real bugs,
but also to all 6 look-alikes: a 500 with no DB error, an SSRF that got
`ECONNREFUSED`, an IDOR where every non-owned ID returned 403. It cannot tell a
finding from a decoy. That is the scanner bias a verifier is supposed to remove.
After 100 verifier examples the pilot rejects 4 of those 6 false positives, and
overall accuracy goes from 47% to 65%. The cost was one over-correction: it
flagged a genuine Twig SSTI as a false positive. A fair trade for a delta this
small, and the direction is the one we wanted.
What it still gets wrong: neither model abstains. Both answer 0 of 3 inconclusive
cases, because the pilot inherited the base model's habit of always committing to
a verdict, and 100 examples was not enough to install "say inconclusive when the
confirming evidence is missing." That is the first thing the next round fixes,
with more inconclusive training data.
Read this as what it is: a pilot proving the recipe works. A 100-example delta
moved false-positive rejection from 0/6 to 4/6 without breaking true-positive
detection. Scale the data and the abstention gap should close too.
## Files
| File | What | Use |
|---|---|---|
| `cyber-analyst-4B-verifier-pilot.Q4_K_M.gguf` | quantized model, ~5.3 GB | LM Studio / Ollama / llama.cpp |
| `cyber-analyst-4B-verifier-pilot.mmproj-BF16.gguf` | vision projector | only for image input (Gemma-4 is multimodal) |
The LoRA adapter lives in a separate repo, [`cyber-analyst-4B-verifier-pilot-lora`](https://huggingface.co/BrainboxAI/cyber-analyst-4B-verifier-pilot-lora), so this one stays a clean GGUF repo.
Note: Gemma-4 is a new architecture. Loading the GGUF needs a recent llama.cpp, so
update LM Studio or Ollama to the latest. In LM Studio, make sure the format selector
is set to GGUF.
## Quick start (LM Studio)
Download `gguf/cyber-analyst-4B-safetensors.Q4_K_M.gguf` and load it. For the verifier
task, use a system prompt like:
> You are a strict security-finding verifier. Given the evidence for a suspected
> vulnerability, decide `true_positive` (the evidence proves exploitation),
> `false_positive` (disproven or not exploitable), or `inconclusive` (suspicious but
> the confirming evidence is missing; say what is missing). Judge from the evidence,
> not the title. Respond with only JSON: `{"verdict":"…","reason":"…"}`.
## Continue training from here
Load the base `cyber-analyst-4B` and attach the adapter from
[`cyber-analyst-4B-verifier-pilot-lora`](https://huggingface.co/BrainboxAI/cyber-analyst-4B-verifier-pilot-lora)
to keep training. The cleaner option is to train from the original `cyber-analyst-4B`
with the full accumulated dataset, which avoids stacking one delta on top of another.
A merged 16-bit model can be regenerated from the base plus the adapter in one step
when you need it.
## Limitations
- Pilot scale, about 100 examples. It checks the format and basic discrimination. It is
not a production verifier yet. Scale the dataset (600+) before relying on it.
- It inherits the base model's limits (public-data bias, temporal cutoff).
- Not for autonomous security decisions without human review.
## Citation
```bibtex
@misc{elyasi2026cyberverifierpilot,
title = {Cyber-Analyst 4B: Verifier Pilot},
author = {Elyasi, Netanel},
year = {2026},
publisher = {BrainboxAI},
howpublished = {\url{https://huggingface.co/BrainboxAI/cyber-analyst-4B-verifier-pilot}}
}
```
## Author
Built by [Netanel Elyasi](https://huggingface.co/BrainboxAI), founder of [BrainboxAI](https://brainboxai.io). Contact: netanele@brainboxai.io
|