PEFT
Safetensors
English
sev
research
cybersecurity
agent-activity
decision-model
lora
Sev-4B / DATA_PROVENANCE.md
macmacmacmac's picture
Publish Sev-4B v0.3.0 response-policy research checkpoint
da0a131 verified
|
Raw History Blame Contribute Delete
7.49 kB
# Sev v0.3.0 data provenance
This release continues `macmacmacmac/Sev-4B@a1824aefba305fda86e3503b895a7d9b3871f79a`, the published v0.2.0 checkpoint. It retains all 6,438 previous training records and adds 139 complete recovered SwarmTraces source programs with 278 authored response-policy questions. These are explicit API authorization rules, not inferred actor identity or blanket maliciousness labels. DNS summaries are evaluation-only.
The selected run is `sev-r2-response-policy-4b-v2/00-trial-0`. The mixed curriculum manifest is pinned at SHA256 `3b9a80dfd212b6932b66ea520c35ab1a3b19e132a81af1b6b7b306d776a70a02`. Training completes 6,577 records, 9,456 questions, 823 optimizer updates and 1,505,379 forward tokens with zero rejected or truncated records. The recipe is one epoch, learning rate 2.5e-6, batch 4, accumulation 2, seed 4 and rank-16 LoRA.
The serving copy adds the calibration-only temperature 1.6817928305074288. Its learned head and adapter tensors remain unchanged; `checkpoint-integrity.json` pins raw and release hashes. No locked test is used. Registered screening remains 26/28 with the false-alert and DNS-regression failures retained in `screen.json`. The user selected publication with these tradeoffs, then paused further experiments.
The source terms and earlier lineage below remain applicable. Authored questions do not relicense third-party recovered programs. The dataset repositories publish public derived non-test records and metadata-only mixed-curriculum manifests, with source-specific restrictions retained.
---
## Preserved parent provenance
# Sev research release provenance
This note describes `macmacmacmac/Sev-4B@v0.2.0-swarmtraces-research`. It packages the selected security-evidence checkpoint as a research artifact despite three failed retention checks. It is not field validation or a replacement for source-specific data permissions.
## Current model lineage
The selected run is `sev-r2-swarmtraces-4b-retention-v1/00-trial-0`. It warm-starts `sev-r2-curriculum-repair-4b-v1/02-trial-2/checkpoint`, which trained from [jaredpalmer/kev-4b at `485ace8703592fcf405488b262449990824cfed1`](https://huggingface.co/jaredpalmer/kev-4b/tree/485ace8703592fcf405488b262449990824cfed1). The backbone is [Qwen/Qwen3.5-4B-Base at `1001bb4d826a52d1f399e183466143f4da7b741b`](https://huggingface.co/Qwen/Qwen3.5-4B-Base/tree/1001bb4d826a52d1f399e183466143f4da7b741b).
The [v0.1.0 synthetic-policy preview](https://huggingface.co/macmacmacmac/Sev-4B/tree/v0.1.0-research) is a separate historical branch. The selected checkpoint does not continue it or inherit its published performance claims.
The final continuation used one epoch, learning rate `2.5e-6`, batch 4, accumulation 2, seed 4, and rank-16 LoRA. It retained every prior curriculum record and added the reviewed SwarmTraces component:
| Training input | Records |
| --- | ---: |
| ExCyTIn evidence questions | 899 |
| Original GUIDE incident view | 1,799 |
| General public classification and authored-rule replay | 1,200 |
| Native Sysmon evidence | 364 |
| Richer GUIDE detector view | 1,730 |
| Complete SwarmTraces programs | 446 |
| Total | 6,438 |
The [published curriculum manifest](https://huggingface.co/datasets/macmacmacmac/openai-agent-swarmtraces/blob/main/collection/v2/experiments/swarmtraces-v1/curriculum-v1/manifest.json) has SHA256 `61e3c1898b8a03eb178355d3c8c5050e85bd217285c700df9b4506ec9e3680f8`. It pins the component manifests and partition bytes. The retained parent curriculum manifest is `5ae5dbfd48e9a2717397c0197ed8db016db87d69abc30d51813878ef734beba3`; the SwarmTraces static component is `1f304228dbbcad5b4aab5d9ce582738b8b7109214c1fdfd56c617fa5f1db583b`.
The raw trial checkpoint keeps temperature 1.0. Its `head.pt` SHA256 is `b29abc817f2340aa510fcd4b2c813455ef38102508120ffc35f7917ce359c27e`; its adapter SHA256 is `b5afd73584d1098cccb0a1bd42afc40e2de3c3bc3074a5173a642b6d4b880420`. The release applies the saved calibration-only temperature `1.6245047927124707`, fitted on 2,534 questions. The release head SHA256 is `1d50c37b4db60c22ae8e6bb24f5055056701bb16e332964350d76df57dc82af0`; its learned tensors are unchanged. Raw evaluation evidence remains attributable to the original bytes.
The selected run answers 65/83 manual SwarmTraces questions and 345/354 parser-derived questions correctly. Native Sysmon, ExCyTIn, original Sysmon and general correctness counts match the parent. It passes 34/37 registered checks. General raw negative log loss and older GUIDE raw negative log loss/Brier remain failures. The release preserves those outcomes; applying calibration does not retrospectively pass the experiment.
## Source and dataset terms
Kev source is Apache-2.0, copyright Jared Palmer, 2026. Sev additions retain that [source license](LICENSE) and [upstream attribution](NOTICE). The Kev adapter/head card and the [pinned Qwen backbone license](https://huggingface.co/Qwen/Qwen3.5-4B-Base/blob/1001bb4d826a52d1f399e183466143f4da7b741b/LICENSE) identify Apache-2.0 for those model artifacts. Preserve the applicable notices when redistributing source or model packages.
Dataset grants remain separate. ExCyTIn, GUIDE, OTRF logs, public classification replay and generated rule records retain their respective source terms and provenance. The [collection catalog](https://huggingface.co/datasets/macmacmacmac/Sev-behavioral-research-v1) records these boundaries. The mixed curriculum and transfer entries publish manifests and provenance only, not all referenced payloads. Availability of a model, catalog entry or mirror does not grant rights to redistribute every underlying dataset.
SwarmTraces upstream reuse terms remain unresolved. Its [dedicated mirror](https://huggingface.co/datasets/macmacmacmac/openai-agent-swarmtraces) retains that limitation. Author-redacted recovered artifacts are not guaranteed free of secrets, and their source text is not a verified record of executed actions. The conversion preserves separate observations and annotations with absent timestamps left explicit. It does not create verified origin, intent, ownership or execution-outcome labels. No CC BY or Apache grant is asserted over third-party SwarmTraces content.
The Kev ancestor already had its own public-dataset and generated-rule training history. The native parent and selected continuation also train directly on the retained public replay shown above. This is not a wholly synthetic training lineage. The package's model license does not replace dataset terms or erase inherited training provenance.
## Historical synthetic release
The original [v0.1.0 release](https://huggingface.co/macmacmacmac/Sev-4B/tree/v0.1.0-research) trained on 2,094 behavioral windows and 240 authored Kev rule records. Its behavioral labels described simulated policy priors, with no captured humans, live LLM executions or network captures. Its weak origin-classification results remain historical evidence, not results for v0.2.0.
The original behavioral records retain [CC BY 4.0](https://github.com/maceip/Sev/blob/main/research/collector/DATA_LICENSE); authored upstream rule records retain their own Apache-2.0 provenance. The [behavioral manifest](https://jevalin-agent-datasets-095713295645.s3.eu-central-1.amazonaws.com/behavioral_v1/manifest.json) remains pinned at SHA256 `83f311ca5d0feddedc16e06272d881542d48ec2b3b0cbc3e292572f391f2300d`. Those notices do not relicense the expanded collection or this release's public-source inputs.