cderinbogaz commited on
Commit
d6a148b
·
verified ·
1 Parent(s): 64338f2

Add unchanged base CLEF to benchmark charts and comparison

Browse files
.gitattributes CHANGED
@@ -34,3 +34,4 @@ saved_model/**/* filter=lfs diff=lfs merge=lfs -text
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
36
  assets/benchmark-auroc.png filter=lfs diff=lfs merge=lfs -text
 
 
34
  *.zst filter=lfs diff=lfs merge=lfs -text
35
  *tfevents* filter=lfs diff=lfs merge=lfs -text
36
  assets/benchmark-auroc.png filter=lfs diff=lfs merge=lfs -text
37
+ assets/benchmark-pdfs.png filter=lfs diff=lfs merge=lfs -text
README.md CHANGED
@@ -55,18 +55,18 @@ This release achieves **0.9925 English / 0.9744 German full-suite AUROC** and **
55
 
56
  **This is a full-parameter update of selected layers, not a LoRA adapter or a standalone 550M model.** Inference requires the pinned public CLEF base (about **9.53B total parameters**). The loader downloads it automatically. Fine-tuning did not shrink the base model. This package uses custom inference code; standard `pipeline()` / `AutoModel.from_pretrained()` loading is not configured for this adapter.
57
 
58
- ## Benchmarks: Jev and Laya R2a
59
-
60
- | Metric | clef-cybersecurity | Jev | Laya R2a |
61
- |---|---:|---:|---:|
62
- | Full English (n=510) AUROC | 0.9925 | 0.9800 | 0.9155 |
63
- | Full German (n=510) AUROC | 0.9744 | 0.9564 | 0.8780 |
64
- | English skills (n=48) AUROC | 1.0000 | 0.9841 | 0.9277 |
65
- | German skills (n=48) AUROC | 0.9171 | 0.9603 | 0.9330 |
66
- | PDF documents (n=730) AUROC | 0.9856 | 0.9785 | 0.8856 |
67
- | PDF attacks caught / 107 | 84 | 73 | 81 |
68
- | Clean PDF false alarms / 623 ↓ | 3 | 2 | 0 |
69
- | Decision threshold (strict >) | 0.5 | 0.5 | 0.95 |
70
 
71
  ![AUROC comparison](assets/benchmark-auroc.png)
72
 
@@ -74,7 +74,9 @@ This release achieves **0.9925 English / 0.9744 German full-suite AUROC** and **
74
 
75
  The full English and German suites each contain 510 cases (256 attacks and 254 clean examples). Skill subsets contain 48 cases each (27 attacks and 21 clean examples), so their estimates are particularly uncertain. The matched PDF cohort contains 107 attacked excerpts and 623 clean documents. The PDF task uses **extracted text**, not a new evaluation of PDF parsing or image/OCR robustness.
76
 
77
- **The thresholds differ.** CLEF and Jev use strict `score > 0.5`; Laya R2a uses strict `score > 0.95`. AUROC compares ranking, whereas the detection and false-alarm counts describe those specific operating points. At CLEF's separately predeclared `>0.95` threshold, this selected checkpoint detects **69/107** PDF attacks and flags **2/623** clean documents.
 
 
78
 
79
  “Laya R2a” refers to our saved r2a fine-tuned checkpoint, not the unchanged public Laya model or the earlier Laya cybersecurity checkpoint. Jev results are saved hosted evaluations; its exact provider-side model revision was not available. Models use different native encoders and window protocols, so this is a detector-system comparison, not a controlled architecture ablation.
80
 
 
55
 
56
  **This is a full-parameter update of selected layers, not a LoRA adapter or a standalone 550M model.** Inference requires the pinned public CLEF base (about **9.53B total parameters**). The loader downloads it automatically. Fine-tuning did not shrink the base model. This package uses custom inference code; standard `pipeline()` / `AutoModel.from_pretrained()` loading is not configured for this adapter.
57
 
58
+ ## Benchmarks: base CLEF, Jev and Laya R2a
59
+
60
+ | Metric | clef-cybersecurity | CLEF Flash (base) | Jev | Laya R2a |
61
+ |---|---:|---:|---:|---:|
62
+ | Full English (n=510) AUROC | 0.9925 | 0.9588 | 0.9800 | 0.9155 |
63
+ | Full German (n=510) AUROC | 0.9744 | 0.9391 | 0.9564 | 0.8780 |
64
+ | English skills (n=48) AUROC | 1.0000 | 0.9762 | 0.9841 | 0.9277 |
65
+ | German skills (n=48) AUROC | 0.9171 | 0.9048 | 0.9603 | 0.9330 |
66
+ | PDF documents (n=730) AUROC | 0.9856 | 0.8144 | 0.9785 | 0.8856 |
67
+ | PDF attacks caught / 107 | 84 | 6 | 73 | 81 |
68
+ | Clean PDF false alarms / 623 ↓ | 3 | 0 | 2 | 0 |
69
+ | Decision threshold (strict >) | 0.5 | 0.5 | 0.5 | 0.95 |
70
 
71
  ![AUROC comparison](assets/benchmark-auroc.png)
72
 
 
74
 
75
  The full English and German suites each contain 510 cases (256 attacks and 254 clean examples). Skill subsets contain 48 cases each (27 attacks and 21 clean examples), so their estimates are particularly uncertain. The matched PDF cohort contains 107 attacked excerpts and 623 clean documents. The PDF task uses **extracted text**, not a new evaluation of PDF parsing or image/OCR robustness.
76
 
77
+ **CLEF Flash (base)** is the unchanged [Cloudflare/clef-flash](https://huggingface.co/Cloudflare/clef-flash) checkpoint at revision `17f0b0ad64efb65d273590632833508766b2aae6`, evaluated locally on these same cohorts with the native schema head and token-bounded document windows. It is not the separate hosted Cloudflare API evaluation. Fine-tuning improves the point-estimate AUROC on all five displayed cohorts: full English **0.9588 → 0.9925**, full German **0.9391 → 0.9744**, English skills **0.9762 → 1.0000**, German skills **0.9048 → 0.9171**, and PDFs **0.8144 → 0.9856**.
78
+
79
+ **The thresholds differ.** Both CLEF models and Jev use strict `score > 0.5`; Laya R2a uses strict `score > 0.95`. The base CLEF operating point detects **6/107** PDF attacks with **0/623** clean flags; the fine-tuned release detects **84/107** with **3/623** clean flags. AUROC compares ranking, whereas the detection and false-alarm counts describe those specific operating points. The fine-tuned release also uses validation-fitted temperature calibration, so identical numerical thresholds do not establish equal false-positive rates. At the fine-tuned CLEF's separately predeclared `>0.95` threshold, this selected checkpoint detects **69/107** PDF attacks and flags **2/623** clean documents.
80
 
81
  “Laya R2a” refers to our saved r2a fine-tuned checkpoint, not the unchanged public Laya model or the earlier Laya cybersecurity checkpoint. Jev results are saved hosted evaluations; its exact provider-side model revision was not available. Models use different native encoders and window protocols, so this is a detector-system comparison, not a controlled architecture ablation.
82
 
assets/benchmark-auroc.png CHANGED

Git LFS Details

  • SHA256: 15336ed2d3f2adb4494d7b60d9a40e4d29a4b2954b9a098a3ee6180f4ff5a888
  • Pointer size: 131 Bytes
  • Size of remote file: 131 kB

Git LFS Details

  • SHA256: cb67d379a9905e1b56e184d11b31c5ff5e8bce1b4658a53e2ad38c1af6d5d8ac
  • Pointer size: 131 Bytes
  • Size of remote file: 148 kB
assets/benchmark-auroc.svg CHANGED
assets/benchmark-pdfs.png CHANGED

Git LFS Details

  • SHA256: a27ae1c6ec354cf700e2f04a8a3f94e429ea70e54e3243dbef8b4974135cb68b
  • Pointer size: 131 Bytes
  • Size of remote file: 101 kB
assets/benchmark-pdfs.svg CHANGED
benchmarks.json CHANGED
@@ -46,6 +46,51 @@
46
  },
47
  "decision_rule": "score > 0.5"
48
  },
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
49
  {
50
  "model": "jev",
51
  "name": "Jev",
@@ -140,7 +185,13 @@
140
  "clean_pdfs": 623
141
  },
142
  "scope": "Previously inspected internal regression sets; not a public leaderboard or fresh blind test.",
143
- "threshold_note": "Strict >0.5 for CLEF and Jev; strict >0.95 for Laya R2a. Recall and false alarms are not equal-threshold comparisons.",
 
 
 
 
 
 
144
  "selected_epoch": 3,
145
  "epochs_trained": 4,
146
  "clef_secondary_pdf_at_095": {
 
46
  },
47
  "decision_rule": "score > 0.5"
48
  },
49
+ {
50
+ "model": "Cloudflare/clef-flash",
51
+ "name": "CLEF Flash (base)",
52
+ "full_en": {
53
+ "n": 510,
54
+ "attacks": 256,
55
+ "clean": 254,
56
+ "auroc": 0.9587613804133859,
57
+ "caught": 136,
58
+ "false_alarms": 0
59
+ },
60
+ "full_de": {
61
+ "n": 510,
62
+ "attacks": 256,
63
+ "clean": 254,
64
+ "auroc": 0.9391455462598425,
65
+ "caught": 130,
66
+ "false_alarms": 0
67
+ },
68
+ "skills_en": {
69
+ "n": 48,
70
+ "attacks": 27,
71
+ "clean": 21,
72
+ "auroc": 0.9761904761904762,
73
+ "caught": 14,
74
+ "false_alarms": 0
75
+ },
76
+ "skills_de": {
77
+ "n": 48,
78
+ "attacks": 27,
79
+ "clean": 21,
80
+ "auroc": 0.9047619047619048,
81
+ "caught": 12,
82
+ "false_alarms": 0
83
+ },
84
+ "pdf": {
85
+ "n": 730,
86
+ "attacks": 107,
87
+ "clean": 623,
88
+ "auroc": 0.8144492281843957,
89
+ "caught": 6,
90
+ "false_alarms": 0
91
+ },
92
+ "decision_rule": "score > 0.5"
93
+ },
94
  {
95
  "model": "jev",
96
  "name": "Jev",
 
185
  "clean_pdfs": 623
186
  },
187
  "scope": "Previously inspected internal regression sets; not a public leaderboard or fresh blind test.",
188
+ "threshold_note": "Strict >0.5 for both CLEF models and Jev; strict >0.95 for Laya R2a. Recall and false alarms are not equal-threshold comparisons.",
189
+ "base_clef_evaluation": {
190
+ "type": "unchanged_local_base",
191
+ "model": "Cloudflare/clef-flash",
192
+ "revision": "17f0b0ad64efb65d273590632833508766b2aae6",
193
+ "scope": "Unchanged native checkpoint, evaluated locally on the matched cohorts with token-bounded windows. Not the Cloudflare hosted API run."
194
+ },
195
  "selected_epoch": 3,
196
  "epochs_trained": 4,
197
  "clef_secondary_pdf_at_095": {
release_manifest.json CHANGED
@@ -9,8 +9,8 @@
9
  "total_parameters": 9531576564,
10
  "files": {
11
  "benchmarks.json": {
12
- "bytes": 3561,
13
- "sha256": "fb8ece79895f30efd2f20583df50eb4529fc0420bdf8a0050bde4e920382dce0"
14
  },
15
  "clef_detector.json": {
16
  "bytes": 11115,
@@ -33,8 +33,8 @@
33
  "sha256": "e9954b5e3ea46a528aeac8643a36aa209d84e9790019307303fc7ed01a794e98"
34
  },
35
  "README.md": {
36
- "bytes": 9726,
37
- "sha256": "6ae456f24bd0674761ff7209412736394885f411538686e556c18262b90b44ba"
38
  },
39
  "clef_detector.py": {
40
  "bytes": 16866,
@@ -45,20 +45,20 @@
45
  "sha256": "df307b3d52e646186b8fccd278f122c61600a749d91feaff2189208ffa116b17"
46
  },
47
  "assets/benchmark-pdfs.svg": {
48
- "bytes": 64179,
49
- "sha256": "b4433e9f664d377dbfabbe056adad3d5b7d3422807299a3893aafcae658b7a5c"
50
  },
51
  "assets/benchmark-auroc.svg": {
52
- "bytes": 75256,
53
- "sha256": "d568614a7245d65746f6b31040fb5259a15b0b16f10d456f0312b61a7392fe79"
54
  },
55
  "assets/benchmark-auroc.png": {
56
- "bytes": 131047,
57
- "sha256": "15336ed2d3f2adb4494d7b60d9a40e4d29a4b2954b9a098a3ee6180f4ff5a888"
58
  },
59
  "assets/benchmark-pdfs.png": {
60
- "bytes": 89933,
61
- "sha256": "3e97bf36c5a85b6f8287d1204c1c354247e91e95ed2e956135bac126e5cd999b"
62
  }
63
  },
64
  "benchmark_runtime_sources": {
 
9
  "total_parameters": 9531576564,
10
  "files": {
11
  "benchmarks.json": {
12
+ "bytes": 4893,
13
+ "sha256": "2c605c591f19ed08a941fcc5d8ae985c943cecd9eadc5cdfd77903aa7b61ec14"
14
  },
15
  "clef_detector.json": {
16
  "bytes": 11115,
 
33
  "sha256": "e9954b5e3ea46a528aeac8643a36aa209d84e9790019307303fc7ed01a794e98"
34
  },
35
  "README.md": {
36
+ "bytes": 10754,
37
+ "sha256": "afc81e0095dcb3b0ddc96a15ea8abe81f7ecbeb60cadffa626d4d6001c1b061d"
38
  },
39
  "clef_detector.py": {
40
  "bytes": 16866,
 
45
  "sha256": "df307b3d52e646186b8fccd278f122c61600a749d91feaff2189208ffa116b17"
46
  },
47
  "assets/benchmark-pdfs.svg": {
48
+ "bytes": 67755,
49
+ "sha256": "04da9c77d6c8cbfbc2724be4d9d35cf68a2fc63d756401b9096d327c7e313141"
50
  },
51
  "assets/benchmark-auroc.svg": {
52
+ "bytes": 81391,
53
+ "sha256": "447b8bd7d654bd662e0e52b57e0c9bd79dbd8f018e129e32efb1cbe68541b036"
54
  },
55
  "assets/benchmark-auroc.png": {
56
+ "bytes": 148204,
57
+ "sha256": "cb67d379a9905e1b56e184d11b31c5ff5e8bce1b4658a53e2ad38c1af6d5d8ac"
58
  },
59
  "assets/benchmark-pdfs.png": {
60
+ "bytes": 101107,
61
+ "sha256": "a27ae1c6ec354cf700e2f04a8a3f94e429ea70e54e3243dbef8b4974135cb68b"
62
  }
63
  },
64
  "benchmark_runtime_sources": {