bencodez commited on
Commit
df9799e
·
verified ·
1 Parent(s): 6236247

Update README.md

Browse files
Files changed (1) hide show
  1. README.md +66 -44
README.md CHANGED
@@ -1,25 +1,6 @@
1
- ---
2
- license: apache-2.0
3
- tags:
4
- - code
5
- - security
6
- - secure-coding
7
- language:
8
- - en
9
- pipeline_tag: text-generation
10
- ---
11
- from pathlib import Path
12
-
13
- readme = """---
14
- license: apache-2.0
15
- tags:
16
- - code
17
- - security
18
- - secure-coding
19
- language:
20
- - en
21
- pipeline_tag: text-generation
22
- ---
23
 
24
  # Cipheron
25
 
@@ -31,8 +12,8 @@ It analyzes source code for common security vulnerabilities and attempts to expl
31
 
32
  Cipheron performs particularly well on:
33
 
34
- - **SQL injection** — identifying unsafe query construction and recommending parameterized queries.
35
- - **Command injection** — identifying unsafe shell command construction and recommending safer subprocess-based approaches.
36
 
37
  These vulnerability classes are strongly represented in its evaluation data.
38
 
@@ -42,12 +23,12 @@ Cipheron has limited reliability across many security vulnerability categories.
42
 
43
  In testing, it struggled with:
44
 
45
- - Path traversal
46
- - Hardcoded secrets and API keys
47
- - Weak password hashing
48
- - Insecure deserialization
49
- - Reflected XSS
50
- - Complex multi-step security vulnerabilities
51
 
52
  For these cases, the model may produce changes that appear security-related but do not actually eliminate the underlying vulnerability.
53
 
@@ -61,10 +42,12 @@ Cipheron is best considered a lightweight, experimental tool for first-pass secu
61
  from transformers import AutoModelForCausalLM, AutoTokenizer
62
  import torch
63
 
64
- tokenizer = AutoTokenizer.from_pretrained("bencodez/Cipheron")
 
 
65
 
66
  model = AutoModelForCausalLM.from_pretrained(
67
- "bencodez/Cipheron",
68
  torch_dtype=torch.bfloat16
69
  )
70
 
@@ -84,24 +67,63 @@ messages = [
84
  def get_user(username):
85
  query = "SELECT * FROM users WHERE username = '" + username + "'"
86
  return db.execute(query)"""
87
- },
88
  ]
89
 
90
  input_ids = tokenizer.apply_chat_template(
91
  messages,
92
  add_generation_prompt=True,
93
- return_tensors="pt",
94
- return_dict=False
95
  )
96
 
97
- out = model.generate(
98
- input_ids,
99
- max_new_tokens=250
 
 
 
 
 
 
100
  )
101
 
102
- print(
103
- tokenizer.decode(
104
- out[0][input_ids.shape[1]:],
105
- skip_special_tokens=True
106
- )
107
- )
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
+ \---
2
+
3
+ ## license: apache-2.0
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
4
 
5
  # Cipheron
6
 
 
12
 
13
  Cipheron performs particularly well on:
14
 
15
+ * **SQL injection** — identifies unsafe query construction and recommends parameterized queries.
16
+ * **Command injection** — identifies unsafe shell command construction and recommends safer subprocess-based approaches.
17
 
18
  These vulnerability classes are strongly represented in its evaluation data.
19
 
 
23
 
24
  In testing, it struggled with:
25
 
26
+ * Path traversal
27
+ * Hardcoded secrets and API keys
28
+ * Weak password hashing
29
+ * Insecure deserialization
30
+ * Reflected XSS
31
+ * Complex multi-step security vulnerabilities
32
 
33
  For these cases, the model may produce changes that appear security-related but do not actually eliminate the underlying vulnerability.
34
 
 
42
  from transformers import AutoModelForCausalLM, AutoTokenizer
43
  import torch
44
 
45
+ model_id = "bencodez/Cipheron"
46
+
47
+ tokenizer = AutoTokenizer.from_pretrained(model_id)
48
 
49
  model = AutoModelForCausalLM.from_pretrained(
50
+ model_id,
51
  torch_dtype=torch.bfloat16
52
  )
53
 
 
67
  def get_user(username):
68
  query = "SELECT * FROM users WHERE username = '" + username + "'"
69
  return db.execute(query)"""
70
+ }
71
  ]
72
 
73
  input_ids = tokenizer.apply_chat_template(
74
  messages,
75
  add_generation_prompt=True,
76
+ return_tensors="pt"
 
77
  )
78
 
79
+ with torch.no_grad():
80
+ output = model.generate(
81
+ input_ids,
82
+ max_new_tokens=250
83
+ )
84
+
85
+ response = tokenizer.decode(
86
+ output[0][input_ids.shape[1]:],
87
+ skip_special_tokens=True
88
  )
89
 
90
+ print(response)
91
+ ```
92
+
93
+ ## Local Inference
94
+
95
+ A quantized `Cipheron-Q8_0.gguf` version is available for lightweight local inference.
96
+
97
+ Cipheron can be used with compatible local inference runtimes for CPU and other supported devices.
98
+
99
+ ## Intended Use
100
+
101
+ Cipheron is intended for:
102
+
103
+ * Secure-coding education
104
+ * Security experimentation
105
+ * Offline code analysis
106
+ * Vulnerability-detection research
107
+ * Lightweight local development workflows
108
+
109
+ ## Model Information
110
+
111
+ | Property | Value |
112
+ | -------------- | ---------------------------------- |
113
+ | Model | Cipheron |
114
+ | Parameters | 0.5B |
115
+ | Architecture | Causal language model |
116
+ | Primary domain | Secure coding |
117
+ | Input | Source code and security questions |
118
+ | Output | Security analysis and safer code |
119
+ | License | Apache 2.0 |
120
+
121
+ ## Disclaimer
122
+
123
+ Cipheron is an experimental security-oriented coding model.
124
+
125
+ Security output should always be independently verified before being used in production systems. A model-generated fix does not guarantee that a vulnerability has been completely eliminated.
126
+
127
+ ## License
128
+
129
+ Apache 2.0