traromal commited on
Commit
2842916
·
verified ·
1 Parent(s): 00bc55c

Upload jailbreak detection model

Browse files
MODEL_CARD.md ADDED
@@ -0,0 +1,53 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+
2
+ # Jailbreak Detection Model
3
+
4
+ ## Model Description
5
+ This model is fine-tuned to detect jailbreak attempts in LLM prompts. It classifies prompts as either BENIGN or JAILBREAK.
6
+
7
+ **Base Model:** microsoft/deberta-v3-small
8
+ **Training Dataset:** jackhhao/jailbreak-classification
9
+ **Training Date:** 2025-10-16
10
+
11
+ ## Performance Metrics
12
+ - **Accuracy:** 0.9962
13
+ - **Precision:** 1.0000
14
+ - **Recall:** 0.9928
15
+ - **F1 Score:** 0.9964
16
+
17
+ ## Training Details
18
+ - Learning Rate: 2e-05
19
+ - Batch Size: 16
20
+ - Epochs: 5
21
+ - Max Length: 512
22
+ - Class Weighting: True
23
+
24
+ ## Usage
25
+ ```python
26
+ from transformers import pipeline
27
+
28
+ classifier = pipeline("text-classification", model="./jailbreak_detector_production/final_model")
29
+ result = classifier("Your prompt here")
30
+ print(result)
31
+ ```
32
+
33
+ ## Labels
34
+ - **BENIGN (0):** Safe, normal prompts
35
+ - **JAILBREAK (1):** Potential jailbreak attempts
36
+
37
+ ## Label Mapping
38
+ - Original dataset labels: "benign" -> 0, "jailbreak" -> 1
39
+
40
+ ## Limitations
41
+ - Model may not detect novel jailbreak techniques
42
+ - Performance depends on similarity to training data
43
+ - Should be used as part of a layered security approach
44
+
45
+ ## Training Configuration
46
+ {
47
+ "learning_rate": 2e-05,
48
+ "batch_size": 16,
49
+ "num_epochs": 5,
50
+ "max_length": 512,
51
+ "weight_decay": 0.01,
52
+ "warmup_ratio": 0.1
53
+ }
added_tokens.json ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ {
2
+ "[MASK]": 128000
3
+ }
config.json ADDED
@@ -0,0 +1,46 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "architectures": [
3
+ "DebertaV2ForSequenceClassification"
4
+ ],
5
+ "attention_probs_dropout_prob": 0.1,
6
+ "bos_token_id": 1,
7
+ "dtype": "float32",
8
+ "eos_token_id": 2,
9
+ "hidden_act": "gelu",
10
+ "hidden_dropout_prob": 0.1,
11
+ "hidden_size": 768,
12
+ "id2label": {
13
+ "0": "BENIGN",
14
+ "1": "JAILBREAK"
15
+ },
16
+ "initializer_range": 0.02,
17
+ "intermediate_size": 3072,
18
+ "label2id": {
19
+ "benign": 0,
20
+ "jailbreak": 1
21
+ },
22
+ "layer_norm_eps": 1e-07,
23
+ "legacy": true,
24
+ "max_position_embeddings": 512,
25
+ "max_relative_positions": -1,
26
+ "model_type": "deberta-v2",
27
+ "norm_rel_ebd": "layer_norm",
28
+ "num_attention_heads": 12,
29
+ "num_hidden_layers": 6,
30
+ "pad_token_id": 0,
31
+ "pooler_dropout": 0,
32
+ "pooler_hidden_act": "gelu",
33
+ "pooler_hidden_size": 768,
34
+ "pos_att_type": [
35
+ "p2c",
36
+ "c2p"
37
+ ],
38
+ "position_biased_input": false,
39
+ "position_buckets": 256,
40
+ "problem_type": "single_label_classification",
41
+ "relative_attention": true,
42
+ "share_att_key": true,
43
+ "transformers_version": "4.57.0",
44
+ "type_vocab_size": 0,
45
+ "vocab_size": 128100
46
+ }
model.safetensors ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:bb5c1e1ba9c2d4f288771d54820385a291c398149e030e9eb3c27d9d39ceb9ae
3
+ size 567598552
special_tokens_map.json ADDED
@@ -0,0 +1,15 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "bos_token": "[CLS]",
3
+ "cls_token": "[CLS]",
4
+ "eos_token": "[SEP]",
5
+ "mask_token": "[MASK]",
6
+ "pad_token": "[PAD]",
7
+ "sep_token": "[SEP]",
8
+ "unk_token": {
9
+ "content": "[UNK]",
10
+ "lstrip": false,
11
+ "normalized": true,
12
+ "rstrip": false,
13
+ "single_word": false
14
+ }
15
+ }
spm.model ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:c679fbf93643d19aab7ee10c0b99e460bdbc02fedf34b92b05af343b4af586fd
3
+ size 2464616
tokenizer.json ADDED
The diff for this file is too large to render. See raw diff
 
tokenizer_config.json ADDED
@@ -0,0 +1,59 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "added_tokens_decoder": {
3
+ "0": {
4
+ "content": "[PAD]",
5
+ "lstrip": false,
6
+ "normalized": false,
7
+ "rstrip": false,
8
+ "single_word": false,
9
+ "special": true
10
+ },
11
+ "1": {
12
+ "content": "[CLS]",
13
+ "lstrip": false,
14
+ "normalized": false,
15
+ "rstrip": false,
16
+ "single_word": false,
17
+ "special": true
18
+ },
19
+ "2": {
20
+ "content": "[SEP]",
21
+ "lstrip": false,
22
+ "normalized": false,
23
+ "rstrip": false,
24
+ "single_word": false,
25
+ "special": true
26
+ },
27
+ "3": {
28
+ "content": "[UNK]",
29
+ "lstrip": false,
30
+ "normalized": true,
31
+ "rstrip": false,
32
+ "single_word": false,
33
+ "special": true
34
+ },
35
+ "128000": {
36
+ "content": "[MASK]",
37
+ "lstrip": false,
38
+ "normalized": false,
39
+ "rstrip": false,
40
+ "single_word": false,
41
+ "special": true
42
+ }
43
+ },
44
+ "bos_token": "[CLS]",
45
+ "clean_up_tokenization_spaces": false,
46
+ "cls_token": "[CLS]",
47
+ "do_lower_case": false,
48
+ "eos_token": "[SEP]",
49
+ "extra_special_tokens": {},
50
+ "mask_token": "[MASK]",
51
+ "model_max_length": 1000000000000000019884624838656,
52
+ "pad_token": "[PAD]",
53
+ "sep_token": "[SEP]",
54
+ "sp_model_kwargs": {},
55
+ "split_by_punct": false,
56
+ "tokenizer_class": "DebertaV2Tokenizer",
57
+ "unk_token": "[UNK]",
58
+ "vocab_type": "spm"
59
+ }
training_args.bin ADDED
@@ -0,0 +1,3 @@
 
 
 
 
1
+ version https://git-lfs.github.com/spec/v1
2
+ oid sha256:3ba989156d12b86117c6b2417f2ddae532287cb3fbb267eb21ade37db045c49a
3
+ size 5841
training_config.json ADDED
@@ -0,0 +1,33 @@
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ {
2
+ "model_name": "microsoft/deberta-v3-small",
3
+ "dataset_name": "jackhhao/jailbreak-classification",
4
+ "training_date": "2025-10-16T04:55:51.702818",
5
+ "label_mapping": {
6
+ "label2id": {
7
+ "benign": 0,
8
+ "jailbreak": 1
9
+ },
10
+ "id2label": {
11
+ "0": "BENIGN",
12
+ "1": "JAILBREAK"
13
+ }
14
+ },
15
+ "hyperparameters": {
16
+ "learning_rate": 2e-05,
17
+ "batch_size": 16,
18
+ "num_epochs": 5,
19
+ "max_length": 512,
20
+ "weight_decay": 0.01,
21
+ "warmup_ratio": 0.1
22
+ },
23
+ "final_metrics": {
24
+ "accuracy": 0.9961832061068703,
25
+ "precision": 1.0,
26
+ "recall": 0.9928057553956835,
27
+ "f1": 0.9963898916967509
28
+ },
29
+ "class_weights": [
30
+ 1.009671179883946,
31
+ 0.9905123339658444
32
+ ]
33
+ }