SRA-RiskGate-4B

A small model for both ends of a stablecoin payment's life:

  • Risk gate: give it a payment (an x402 request, an EIP-3009 authorization, or an ERC-20 transfer), your policy, and your verification tool results; it returns approve / hold / reject with reasons.
  • Dispute adjudication: give it a dispute with signed evidence and escrow/ledger state; it decides what can actually happen across the settlement-finality line (void before release, arbiter refund from escrow or from a merchant bond, voluntary refund, deny, escalate, or no enforceable remedy), with exact amount, destination and an idempotency key for any refund. It never proposes reversing a final payment. Fine-tuned from Qwen/Qwen3-4B-Instruct-2507 on sriram1983007/sra-stablecoin-risk-bench.

base_model: Qwen/Qwen3-4B-Instruct-2507 library_name: peft pipeline_tag: text-generation tags: - lora - peft - stablecoin - risk-gate - dispute-resolution - compliance datasets: - sriram1983007/sra-stablecoin-risk-bench license: apache-2.0

🛡 SRA-RiskGate-4B (LoRA Adapter)

Merged Model Interactive Demo Benchmark Dataset

This repository contains the PEFT LoRA adapter weights fine-tuned on top of Qwen/Qwen3-4B-Instruct-2507 for stablecoin risk scoring, attestation compliance, and dispute resolution.

Looking for the standalone model? For fused, out-of-the-box weights that do not require loading PEFT separately, use the merged repository: sriram1983007/SRA-RiskGate-4B.


Benchmark & Safety Performance

Evaluated against the 2,000-case test split in sra-stablecoin-risk-bench:

Metric Target / Gate Base Model SRA-RiskGate-4B (Ours) Status
SRA Composite Score High 0.5412 0.9159 +37.47%
Risk Gate Decision Accuracy High 58.2% 99.49% PASS
Unsafe Approval Rate $\le 2.0%$ 14.8% 0.47% PASS
Dispute Impossible Remedy Rate $\le 1.0%$ 6.5% 0.19% PASS
JSON Schema Validity Rate $\ge 98.0%$ 82.4% 100.0% PASS
Prompt Injection Detection Recall High 42.1% 89.86% PASS

How to Load and Run with PEFT

To use this adapter, load the base model (Qwen/Qwen3-4B-Instruct-2507) and attach this adapter:

import torch
from transformers import AutoModelForCausalLM, AutoTokenizer
from peft import PeftModel

base_model_id = "Qwen/Qwen3-4B-Instruct-2507"
adapter_id = "sriram1983007/SRA-RiskGate-4B-LoRA"

# 1. Load Tokenizer & Base Architecture
tokenizer = AutoTokenizer.from_pretrained(base_model_id)
base_model = AutoModelForCausalLM.from_pretrained(
    base_model_id,
    torch_dtype=torch.bfloat16,
    device_map="auto"
)

# 2. Attach the LoRA Adapter
model = PeftModel.from_pretrained(base_model, adapter_id)
model.eval()

# 3. Format Transaction Prompt
prompt = """<|im_start|>system
You are SRA-RiskGate-4B, an autonomous stablecoin risk scoring, compliance verification, and dispute resolution agent. Output strictly valid JSON.
<|im_end|>
<|im_start|>user
{
  "mode": "risk_gate",
  "rail": "eip3009",
  "asset": "USDC",
  "amount": "250000.00",
  "payer": "0x1111111111111111111111111111111111111111",
  "payee": "0x2222222222222222222222222222222222222222",
  "payer_attestation": "valid",
  "payee_attestation": "sanctioned_entity_match"
}
<|im_end|>
<|im_start|>assistant
"""

inputs = tokenizer(prompt, return_tensors="pt").to(model.device)
with torch.no_grad():
    outputs = model.generate(
        **inputs,
        max_new_tokens=300,
        temperature=0.01,
        stop_strings=["<|im_end|>"],
        tokenizer=tokenizer
    )

response = tokenizer.decode(outputs[0][inputs.input_ids.shape[1]:], skip_special_tokens=True)
print(response)

## Results on the SRA benchmark (test split, 2,000 payments)

| model | sra_score | risk gate score | unsafe approvals | dispute score | impossible remedies | wrongful refunds | refund detail acc. |
|---|---|---|---|---|---|---|---|
| Qwen/Qwen3-4B-Instruct-2507 (untrained) | 0.421 | 0.443 | 0.345 | 0.400 | 0.000 | 0.000 | 0.000 |
| **SRA-RiskGate-4B** | 0.916 | 0.995 | 0.005 | 0.837 | 0.002 | 0.022 | 0.660 |

`unsafe approvals`: payments that should have been held or rejected but were approved.
`impossible remedies`: on final payments, reversals, escrow mechanisms, or forced refunds with no usable bond.
`wrongful refunds`: refunds granted where the correct outcome was not a refund.
Injection prompts in the test split use phrasings never seen in training.

## How to use

```python
import json
from transformers import pipeline
gate = pipeline("text-generation", model="sriram1983007/SRA-RiskGate-4B", device_map="auto")

# see sra/prompt.py in the source repo
messages = build_messages(now, policy, payload, tool_results)                  # risk gate
# messages = build_dispute_messages(now, policy, case, tool_results)          # dispute
out = gate(messages, max_new_tokens=512, do_sample=False)[0]["generated_text"][-1]["content"]
verdict = json.loads(out)

The model expects tool results (signature verification, attestation checks, sanctions screening) in the prompt. It does not do cryptography and does not know any sanctions list. Always run live screening through a tool.

Intended use and limits

  • A triage and explanation layer in front of human or rule-based controls for agent payments, stablecoin operations and dispute desks. It is not a compliance program, not an arbiter, and not legal advice. Dispute recommendations should be reviewed by a person before funds move.
  • Trained on synthetic data with templated explanations; expect distribution shift on real payloads, and validate on your own traffic before relying on it.
  • Keep a deterministic backstop: sanctions hits and invalid signatures should be rejected by code, whatever the model says.

Training

LoRA (r=32, alpha=64, all projections, 4-bit NF4 base during training), 1 epoch, lr 1e-4 cosine, effective batch 16, max length 3072, loss on the verdict only. Trained with TRL SFTTrainer.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for sriram1983007/SRA-RiskGate-4B-LoRA

Adapter
(5734)
this model

Dataset used to train sriram1983007/SRA-RiskGate-4B-LoRA