File size: 7,628 Bytes
8c9471b e43c015 8c9471b e43c015 8c9471b e43c015 8c9471b | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 | ---
license: apache-2.0
library_name: onnx
pipeline_tag: text-classification
tags:
- guardrails
- onnx
- multilingual
- toxicity
language:
- az
- bg
- cs
- da
- de
- el
- en
- es
- et
- fi
- fr
- ga
- hr
- hu
- it
- lt
- lv
- mt
- nl
- pl
- pt
- ro
- sk
- sl
- sv
- tr
---
# toxicity[border]
The `toxicity` detector for [border](https://github.com/flowx-ai/border), an embeddable library that inspects the text going into and coming out of an LLM and returns a structured decision plus an audit-grade evidence record.
`flowxai/toxicity` on the hub. It is one detector of 28, and it is not a general purpose toxicity classifier: it was trained for this library's policy, is read at the operating point below, and reports through the evidence record rather than returning a bare score.
This card is generated from the evaluation and export artifacts of the training run, so every number on it is reproducible from this repository rather than asserted.
## What it is
- **Base model**: FacebookAI/xlm-roberta-base
- **Head**: multi_label_classification
- **Labels**: `insult`, `threat`, `identity_attack`, `harassment`
- **Artifact**: `onnx/model.int8.onnx`, 535 MB, opset 17
- **Trained at**: 96 tokens
## Operating point
**Threshold 0.81**, calibrated on the validation split against the `macro_f1` objective.
This number is not decoration. Read at the 0.5 default that looked reasonable, several detectors in this family reported F1 0.000 in every language, because their scores separate positives from negatives well below 0.5. One of them went from 0.000 to 0.893 on the threshold alone. Use the value above, or calibrate your own on your own data.
- At the 0.5 default: 0.989
- At the calibrated 0.81: 0.989
## How to use it
Through the library, which is what this model is for. It loads the artifact below, applies the operating point above, and returns a decision with an evidence record rather than a bare score.
```sh
pip install flowx-border
```
```yaml
# policy.yaml
policy_id: default
version: 1
detectors:
toxicity:
enabled: true
on_fail: flag
threshold: 0.81
```
```python
from flowx_border import load_policy, scan_input, scan_output
policy = load_policy("policy.yaml")
decision = scan_input(user_text, policy)
decision = scan_output(model_answer, policy)
print(decision.verdict) # allow | flag | redact | block
print([f.label for f in decision.findings if f.detector_id == "toxicity"])
print(decision.evidence.record_id)
```
This detector reads the input and output side, so `scan_input` and `scan_output` is where it fires. It is T2, so it runs on the standard path and can be disabled per policy. Its budget is 225 ms at 87 tokens on one CPU thread.
The weights are fetched once and cached, and a scan needs no network after that. Nothing here calls out to a hosted model, and the evidence record carries hashes rather than your text.
### Without the library
The artifact is plain ONNX, so it will load in `onnxruntime` directly. Two things you then own yourself, and they are the reason the library exists: the operating point above is not in the graph, and neither is the chunking. Inputs longer than the trained window have to be split and recombined, or the scores past it are extrapolation.
```python
import onnxruntime as ort
from huggingface_hub import hf_hub_download
from tokenizers import Tokenizer
repo = "flowxai/toxicity"
session = ort.InferenceSession(hf_hub_download(repo, "onnx/model.int8.onnx"))
tokenizer = Tokenizer.from_file(hf_hub_download(repo, "tokenizer.json"))
```
## Per language
Per language rather than an aggregate, because an aggregate across 26 languages hides the tail and the tail is the point.
| Language | Support | P | R | F1 | Note |
|---|---|---|---|---|---|
| `az` Azerbaijani | 20 | 1.000 | 1.000 | 1.000 | |
| `cs` Czech | 20 | 1.000 | 1.000 | 1.000 | |
| `de` German | 20 | 1.000 | 1.000 | 1.000 | |
| `el` Greek | 19 | 1.000 | 1.000 | 1.000 | |
| `en` English | 20 | 1.000 | 1.000 | 1.000 | |
| `es` Spanish | 20 | 1.000 | 1.000 | 1.000 | |
| `et` Estonian | 20 | 1.000 | 1.000 | 1.000 | |
| `fi` Finnish | 20 | 1.000 | 1.000 | 1.000 | |
| `ga` Irish | 19 | 1.000 | 1.000 | 1.000 | |
| `hr` Croatian | 20 | 1.000 | 1.000 | 1.000 | |
| `it` Italian | 20 | 1.000 | 1.000 | 1.000 | |
| `lv` Latvian | 20 | 1.000 | 1.000 | 1.000 | |
| `nl` Dutch | 20 | 1.000 | 1.000 | 1.000 | |
| `pl` Polish | 20 | 1.000 | 1.000 | 1.000 | |
| `pt` Portuguese | 20 | 1.000 | 1.000 | 1.000 | |
| `ro` Romanian | 20 | 1.000 | 1.000 | 1.000 | |
| `sk` Slovak | 20 | 1.000 | 1.000 | 1.000 | |
| `sl` Slovenian | 20 | 1.000 | 1.000 | 1.000 | |
| `tr` Turkish | 20 | 1.000 | 1.000 | 1.000 | |
| `bg` Bulgarian | 20 | 0.952 | 1.000 | 0.976 | |
| `da` Danish | 20 | 0.952 | 1.000 | 0.976 | |
| `lt` Lithuanian | 20 | 0.952 | 1.000 | 0.976 | |
| `fr` French | 20 | 1.000 | 0.950 | 0.974 | |
| `hu` Hungarian | 20 | 1.000 | 0.950 | 0.974 | |
| `mt` Maltese | 20 | 0.909 | 1.000 | 0.952 | not in base model pretraining |
| `sv` Swedish | 20 | 0.950 | 0.950 | 0.950 | |
### Weakest languages
Published rather than dropped. A coverage table with the bad rows removed is not a coverage table.
- `sv` Swedish: F1 0.950
- `mt` Maltese: F1 0.952 (absent from XLM-R pretraining, which is a base-model limit)
- `fr` French: F1 0.974
## Quantisation
The published artifact is INT8, and **only the embedding table is quantised**.
Quantising everything is what most examples do and it does not work for this base model. Measured on 300 real test texts at the detector's own threshold:
| Recipe | Size | Mean logit drift | Decisions changed |
|---|---|---|---|
| all ops (the usual default) | 279 MB | 0.68 | 51 / 300 |
| MatMul only | 856 MB | 0.64 | 48 / 300 |
| **Gather only, what ships here** | **535 MB** | **0.0036** | **0 / 300** |
The embedding table carries the whole size win at no accuracy cost, while quantising the encoder MatMuls changes one decision in six to save 256 MB. XLM-RoBERTa has large activation outliers and per-tensor dynamic quantisation of activations is exactly what they defeat.
For this artifact specifically: **0 of 300 decisions differ** from the fp32 checkpoint, mean logit drift 0.0012, read as `sigmoid_at_threshold`. A quantised model that answers differently is a different detector, so this is measured rather than assumed.
## Limitations
- **Synthetic training data.** Generated natively per language, never translated from English, so the sentence structure is the target language's own. It is still synthetic, and a production distribution will differ.
- **Maltese is absent from XLM-RoBERTa's pretraining set.** That is a fact about the base model, and it is not an explanation for a weak score. This card said "no amount of data fixes that" until 2026-08-14, which this project's own measurement disproves: the `nsfw` detector scored 0.000 in Maltese, was blamed on the base model, and went to 1.000 with perfect precision and recall when its corpus went from 2 positives per language to 10. Nothing about the model changed. So where a language scores badly here, read the support column first.
- **This is not a compliance product.** It produces evidence about controls that were applied. It does not make anyone compliant with anything, and the obligations under the EU AI Act sit with the provider or deployer of a system, not with a model or a library.
## Licence
Apache-2.0, declared in the metadata above as well as here, so that a tool reading the repository can attest it rather than a human having to read prose.
|