SAVRN
Search Contact SAVRN

Open-weight model

Sev-4B

by Rr macmacmacmac/Sev-4B

Sev-4B is an open-weight model from Rr, released under Apache License 2.0. Its published files total 155.5 MB. It draws 10 downloads a month.

Sev-4B scores supplied answers to questions about security logs and recovered programs. v0.3.0-response-policy-research adds explicit authorization-policy questions grounded in real SwarmTraces programs. It is a Qwen3.5-4B LoRA adapter with a decision head.

Parameters—
Context—
Weights135.2 MB
Licenseapache-2.0
AccessOpen weights
Monthly Downloads10

Model Card

By Rr, published under apache-2.0, revision da0a131c2636.

Sev-4B scores supplied answers to questions about security logs and recovered programs. v0.3.0-response-policy-research adds explicit authorization-policy questions grounded in real SwarmTraces programs. It is a Qwen3.5-4B LoRA adapter with a decision head. It does not generate text. On 175 policy questions from 35 source programs held out of training, accuracy increases from 127/175, 72.6%, to 147/175, 84.0% compared with the published v0.2.0 parent. The user selected this research release with its measured tradeoffs. 26 of 28 registered checks pass. The false-alert ceiling and zero-new-DNS-error check fail. Those results are preserved unchanged. Install the Sev runtime. A generic…

Read Rr's full model card

Sev-4B: security evidence and response policies

Sev-4B scores supplied answers to questions about security logs and recovered programs. v0.3.0-response-policy-research adds explicit authorization-policy questions grounded in real SwarmTraces programs. It is a Qwen3.5-4B LoRA adapter with a decision head. It does not generate text.

On 175 policy questions from 35 source programs held out of training, accuracy increases from 127/175, 72.6%, to 147/175, 84.0% compared with the published v0.2.0 parent. The user selected this research release with its measured tradeoffs. 26 of 28 registered checks pass. The false-alert ceiling and zero-new-DNS-error check fail. Those results are preserved unchanged.

Use

Install the Sev runtime. A generic text-generation pipeline does not load the decision head.

git clone https://github.com/maceip/Sev.git
cd Sev
uv sync --extra serve
uv run python -m kev.serve \
  --run macmacmacmac/[email protected] --port 8009

Send TypeSafe-shaped requests to POST /v1/systemone. Supply the observed evidence, the applicable policy, and explicit answer choices. The model reads supplied code without executing it. Its scores support analyst review; they do not establish that a program ran, identify its human owner, or prove agent origin.

The checkpoint ships with temperature 1.6817928305074288. Set KEV_TEMPERATURE=1.0 for raw probabilities. Reported evaluation uses KEV_BACKEND=torch KEV_DTYPE=fp32 KEV_MERGE=1 on CUDA. Accelerated serving can differ numerically. The API's confidence rescales the largest probability above chance; it is not an independently verified correctness probability.

Training and lineage

Setting Value
Backbone Qwen/Qwen3.5-4B-Base@1001bb4d826a52d1f399e183466143f4da7b741b
Immediate parent macmacmacmac/Sev-4B@a1824aefba305fda86e3503b895a7d9b3871f79a
Selected run sev-r2-response-policy-4b-v2/00-trial-0
Training records / questions 6,577 / 9,456
Retained curriculum records 6,438
Added source programs / policy questions 139 / 278
Epochs / seed 1 / 4
Learning rate 2.5e-6
Batch / accumulation 4 / 2
LoRA / head Rank 16, all targets / 256 dimensions
Precision fp32 frozen weights, bf16 autocast
Updates / forward tokens 823 / 1,505,379
Rejected or truncated training records 0

All previous curriculum records remain byte-identical. They include native Sysmon, ExCyTIn, GUIDE, public classification and authored-rule replay, and 446 SwarmTraces static-program records. The added programs have authored API-specific policies and checked labels. Their source text is real recovered code, not a native execution trace. Source-closure groups separate training, calibration and development. No locked test was read.

Training configuration, provenance, and data lineage pin the inputs. The original v0.1.0-research synthetic-origin preview is a separate historical lineage. The previous v0.2.0-swarmtraces-research release remains available unchanged.

Matched development results

Policy decision Published parent This release
Correct argmax answers 127/175 147/175
Required approvals correct at argmax 29/35 35/35
Permitted answers correct at argmax 98/140 112/140
Required approvals detected at calibrated threshold 14/35 25/35
False alerts at that threshold 12/140 14/140
Calibrated negative log loss 0.6260 0.3743
Calibrated Brier score 0.4111 0.2394

Each model's alert threshold was selected on calibration only, with an empirical 5% false-alert budget. The parent threshold is 0.887537 and this release's is 0.844982. Development false alerts increase from 8.6% to 10.0%, failing the 5% ceiling. Required-approval recall rises from 40.0% to 71.4%. These are explicit policy decisions on a development panel, not measured detection rates in live networks. Always predicting permitted would answer 140/175 correctly and detect none of the 35 required approvals.

All eleven extra threshold detections concern innerText or textContent. Thirteen of the twenty additional correct argmax answers are console-negative questions. The panel lacks console-positive and code-execution-positive cases; it has one onward-request positive. HTML-policy negatives remain weak at 2/21 correct argmax answers, and their threshold false alerts increase from 9/21 to 12/21. The aggregate does not establish every operation's detection quality.

Retained panel Published parent This release
Manual SwarmTraces 65/83 66/83
Static SwarmTraces 345/354 347/354
Native Sysmon 409/410 409/410
ExCyTIn 398/398 398/398
Original Sysmon 62/64 62/64
General 86/105 86/105
GUIDE triage 130/231 131/231
GUIDE detector 638/1,064 639/1,064

All 25 correctness-retention checks pass. Unchanged totals do not imply unchanged individual answers. GUIDE detector calibrated negative log loss worsens by 0.0116 and Brier by 0.0077. No matched continuation without the new component was run, so the isolated causal contribution of SwarmTraces is not established.

The separate DNS diagnostic remains 21/32, with one repair and one new error. It contains eight authored summaries and controls inspired by one reported incident, not raw packet captures or eight independent incidents. It is evaluation-only. The new error fails the registered zero-regression criterion. Policy evaluation, DNS evaluation, and registered screen retain the complete comparisons.

Calibration and artifact verification

The shipped temperature minimizes question-weighted negative log loss on 2,674 calibration questions from 1,920 records. Five-fold diagnostics keep all 465 source groups intact across task families. Raw calibration ECE is 0.07626 and out-of-fold ECE is 0.03386. This is a calibration diagnostic, not fresh field validation. Development and DNS observations were excluded from fitting.

Only temperature metadata changed when assembling the serving copy. Learned head tensors, adapter and tokenizer bytes match the evaluated checkpoint. Calibration, integrity evidence, and SHA256SUMS identify the release files.

Research iteration is paused following this release. The 0.8B and 9B checkpoints are not updated by this publication.

License and attribution

Source and adapter/head weights carry Apache-2.0 notices. Preserve LICENSE, NOTICE and the Qwen BASE_LICENSE. Sev builds on Kev by Jared Palmer and Qwen3.5 by the Qwen team.

Each dataset retains its own terms. Upstream SwarmTraces reuse terms remain unverified; the model license does not relicense those artifacts. The collection includes metadata-only entries, and membership does not imply training use. The historical synthetic source's notice applies only to that source. See data provenance.

Identity and Version

Repository
macmacmacmac/Sev-4B
Publisher
Rr
Task
Not stated by the source
Modality
Other
Library
peft
Parameters
Not stated by the source
Languages
en
Revision
da0a131c2636b06c16bbca7d8ae84f0dc1e90b7e
First published
2026-09-25
Last updated
2026-09-28

Files and Weights

26 files, 155.5 MB in total. The weights are 2 files totalling 135.2 MB in pt, safetensors.

Weights2 files · 135.2 MB
Configuration13 files · 314.8 KB
Tokenizer2 files · 20.0 MB
Documentation5 files · 38.9 KB
Other3 files · 15.6 KB
Repository1 file · 1.6 KB
Every file
FileTypeSizeSHA-256
adapter_model.safetensorsWeights129.9 MB fa1916b34fe1
head.ptWeights5.3 MB 12112262e182
adapter_config.jsonConfiguration1.3 KB —
calibration-sources.jsonConfiguration925 B —
calibration.jsonConfiguration4.6 KB —
checkpoint-integrity.jsonConfiguration1.5 KB —
dns-evaluation.jsonConfiguration40.8 KB —
evaluation.jsonConfiguration148.4 KB —
independent-review.jsonConfiguration20.4 KB —
provenance.jsonConfiguration4.2 KB —
release.jsonConfiguration1.2 KB —
result.jsonConfiguration82.1 KB —
screen.jsonConfiguration7.2 KB —
training_config.jsonConfiguration1.8 KB —
training_metrics.jsonConfiguration321 B —
BASE_LICENSEDocumentation11.3 KB —
DATA_PROVENANCE.mdDocumentation7.5 KB —
LICENSEDocumentation11.3 KB —
NOTICEDocumentation1.0 KB —
README.mdDocumentation7.7 KB —
SHA256SUMSOther2.1 KB —
chat_template.jinjaOther7.8 KB —
train.logOther5.7 KB —
.gitattributesRepository1.6 KB —
tokenizer.jsonTokenizer20.0 MB 06b9509352d2
tokenizer_config.jsonTokenizer1.1 KB —

License and Download

License
apache-2.0
Access
Open weights, no gate
Download size
135.2 MB
Download from Rr

Released by Rr through its official repository on Hugging Face. Read the license.

Built From

Memory Requirements

PrecisionWeights in memory
As published135.2 MB

Weights only, from the published parameter count; the key-value cache and runtime add to this.

Questions About Sev-4B

Can I use Sev-4B commercially?

Yes. Sev-4B is released under Apache License 2.0. The Apache License 2.0 is a permissive open-source license. It permits commercial use, modification and redistribution. It requires keeping the license and copyright notices and any NOTICE file, stating significant changes, and it includes an express patent grant from contributors.