CyberSecQwen-4B

Compact CTI/CWE classification specialist.

Context32,768 (unconfirmed)
Curationcurated
AvailabilityComing soon
Price / Mtoknot yet priced
QuantizationQ4_K_M
License—

Source: mradermacher/CyberSecQwen-4B-GGUF on HuggingFace

Good for
  • +CVE-to-CWE mapping
  • +cheap security classification
Full model cardcurated from the model's HuggingFace card — description, training, usage, limitations, reported benchmarks

CyberSecQwen-4B is a compact, Apache-2.0 cybersecurity classification model — a LoRA fine-tune over a ~4B-parameter Qwen base. It is notably transparent about its recipe: roughly 14,776 curated training examples, an explicit decontamination step, its LoRA hyperparameters, and even a documented failed distillation experiment. It is a CTI/CWE specialist best used for cheap, high-volume work such as CVE-to-CWE mapping and first-pass classification — not an interactive bug-hunting agent.

Training data

A LoRA fine-tune over a ~4B Qwen base on roughly 14,776 curated cybersecurity examples, with a documented decontamination pass. The card is unusually transparent, publishing its LoRA hyperparameters and a failed distillation experiment. Figures are author-reported, not independently verified.

Intended use
  • +CVE-to-CWE mapping and CWE classification
  • +Cheap, high-volume security triage and first-pass labeling
  • +Small QLoRA fine-tuning experiments
Limitations
  • −A CTI/CWE classifier, not an interactive bug-hunting agent — no web navigation, tool use, or exploitation.
  • −As a 4B model it can drift on out-of-distribution inputs; treat every label as a first pass to verify.
  • −Author-reported figures are not independently verified.
Running the weights yourself

The maker’s own snippet, from the model card — it downloads the weights and runs them on your hardware. Kept here because reproducing a result independently is the point, not because you need it to use the model.

System: You are a CTI assistant. Map the vulnerability to its single most likely CWE and justify it in one sentence.
User: CVE-2021-44228 — Apache Log4j2 performs JNDI lookups on attacker-controlled log strings, enabling remote code execution.
Scores

No measurements published for this version yet.

Baseline is the strongest general-purpose model we could run on the same suite, same setup, same day. The control row tells you what the other rows are worth.

Versionsscores attach to a version; v2 does not inherit v1's numbers
v12026-08-15—current

Start with CyberSecQwen-4B

A confirmed email account includes 30 free messages a month.

Sign in to start
CyberSecQwen-4B — Security helper · AdversariaLLM