--- license: apache-2.0 language: - en pipeline_tag: text-generation library_name: transformers base_model: sabari2005/cyberslm-33m-base tags: - cybersecurity - small-language-model - instruct - sft - llama --- # CyberSLM-33M-Instruct Instruction-tuned version of [`cyberslm-33m-base`](https://huggingface.co/sabari2005/cyberslm-33m-base) — a **33.5M-parameter cybersecurity-focused small language model** trained from scratch, then supervised-finetuned on **24,980 cybersecurity Q&A conversations** with loss masking on assistant tokens only. ## Architecture Decoder-only transformer (Llama-style, loadable with `LlamaForCausalLM`): 384 hidden / 12 layers / 6 heads / SwiGLU 1024 / RMSNorm / RoPE θ=10,000 / 4096 context / 32k SentencePiece vocab / tied embeddings. Total: 33,531,264 parameters. ## Chat format The model was finetuned with this template (built into `tokenizer.chat_template`): ``` ### User: {question} ### Assistant: {answer} ``` ## Usage ```python from transformers import AutoModelForCausalLM, AutoTokenizer tok = AutoTokenizer.from_pretrained("sabari2005/cyberslm-33m-instruct") model = AutoModelForCausalLM.from_pretrained("sabari2005/cyberslm-33m-instruct") messages = [{"role": "user", "content": "Explain what a SQL injection attack is and how to prevent it."}] ids = tok.apply_chat_template(messages, add_generation_prompt=True, return_tensors="pt", add_special_tokens=False) out = model.generate(ids, max_new_tokens=256, do_sample=True, temperature=0.7, top_p=0.9, eos_token_id=3, pad_token_id=0) print(tok.decode(out[0][ids.shape[1]:], skip_special_tokens=True)) ``` > Note: the ``/`` markers in the template are literal text (the > SentencePiece vocab uses ``/`` pieces), matching exactly how the > model was trained. Use `apply_chat_template` and you don't need to think > about it. ## Training - SFT on 24,980 cyber Q&A samples (multi-turn conversation format) - 3 epochs, LR 2e-5 cosine, AdamW β=(0.9, 0.95), wd 0.01, loss on assistant tokens only - Final val loss: **2.66** ## Limitations 33M parameters: strong at short cybersecurity explanations and Q&A; not suited for long-horizon reasoning, code generation, or general assistant duties. May hallucinate specifics (CVE numbers, tool flags) — verify facts. English only.