Sev-4B is an open-weight model from Rr, released under Apache License 2.0. Its published files total 155.5 MB. It draws 10 downloads a month.
Sev-4B scores supplied answers to questions about security logs and recovered programs. v0.3.0-response-policy-research adds explicit authorization-policy questions grounded in real SwarmTraces programs. It is a Qwen3.5-4B LoRA adapter with a decision head.
Model Card
By Rr, published under apache-2.0, revision da0a131c2636.
Sev-4B scores supplied answers to questions about security logs and recovered programs. v0.3.0-response-policy-research adds explicit authorization-policy questions grounded in real SwarmTraces programs. It is a Qwen3.5-4B LoRA adapter with a decision head. It does not generate text. On 175 policy questions from 35 source programs held out of training, accuracy increases from 127/175, 72.6%, to 147/175, 84.0% compared with the published v0.2.0 parent. The user selected this research release with its measured tradeoffs. 26 of 28 registered checks pass. The false-alert ceiling and zero-new-DNS-error check fail. Those results are preserved unchanged. Install the Sev runtime. A generic…
Read Rr's full model card
Sev-4B: security evidence and response policies
Sev-4B scores supplied answers to questions about security logs and recovered programs. v0.3.0-response-policy-research adds explicit authorization-policy questions grounded in real SwarmTraces programs. It is a Qwen3.5-4B LoRA adapter with a decision head. It does not generate text.
On 175 policy questions from 35 source programs held out of training, accuracy increases from 127/175, 72.6%, to 147/175, 84.0% compared with the published v0.2.0 parent. The user selected this research release with its measured tradeoffs. 26 of 28 registered checks pass. The false-alert ceiling and zero-new-DNS-error check fail. Those results are preserved unchanged.
Use
Install the Sev runtime. A generic text-generation pipeline does not load the decision head.
git clone https://github.com/maceip/Sev.git
cd Sev
uv sync --extra serve
uv run python -m kev.serve \
--run macmacmacmac/[email protected] --port 8009
Send TypeSafe-shaped requests to POST /v1/systemone. Supply the observed
evidence, the applicable policy, and explicit answer choices. The model reads
supplied code without executing it. Its scores support analyst review; they do
not establish that a program ran, identify its human owner, or prove agent origin.
The checkpoint ships with temperature 1.6817928305074288. Set
KEV_TEMPERATURE=1.0 for raw probabilities. Reported evaluation uses
KEV_BACKEND=torch KEV_DTYPE=fp32 KEV_MERGE=1 on CUDA. Accelerated serving can
differ numerically. The API's confidence rescales the largest probability above
chance; it is not an independently verified correctness probability.
Training and lineage
| Setting | Value |
|---|---|
| Backbone | Qwen/Qwen3.5-4B-Base@1001bb4d826a52d1f399e183466143f4da7b741b |
| Immediate parent | macmacmacmac/Sev-4B@a1824aefba305fda86e3503b895a7d9b3871f79a |
| Selected run | sev-r2-response-policy-4b-v2/00-trial-0 |
| Training records / questions | 6,577 / 9,456 |
| Retained curriculum records | 6,438 |
| Added source programs / policy questions | 139 / 278 |
| Epochs / seed | 1 / 4 |
| Learning rate | 2.5e-6 |
| Batch / accumulation | 4 / 2 |
| LoRA / head | Rank 16, all targets / 256 dimensions |
| Precision | fp32 frozen weights, bf16 autocast |
| Updates / forward tokens | 823 / 1,505,379 |
| Rejected or truncated training records | 0 |
All previous curriculum records remain byte-identical. They include native Sysmon, ExCyTIn, GUIDE, public classification and authored-rule replay, and 446 SwarmTraces static-program records. The added programs have authored API-specific policies and checked labels. Their source text is real recovered code, not a native execution trace. Source-closure groups separate training, calibration and development. No locked test was read.
Training configuration, provenance,
and data lineage pin the inputs. The original
v0.1.0-research
synthetic-origin preview is a separate historical lineage. The previous
v0.2.0-swarmtraces-research
release remains available unchanged.
Matched development results
| Policy decision | Published parent | This release |
|---|---|---|
| Correct argmax answers | 127/175 | 147/175 |
| Required approvals correct at argmax | 29/35 | 35/35 |
| Permitted answers correct at argmax | 98/140 | 112/140 |
| Required approvals detected at calibrated threshold | 14/35 | 25/35 |
| False alerts at that threshold | 12/140 | 14/140 |
| Calibrated negative log loss | 0.6260 | 0.3743 |
| Calibrated Brier score | 0.4111 | 0.2394 |
Each model's alert threshold was selected on calibration only, with an empirical 5% false-alert budget. The parent threshold is 0.887537 and this release's is 0.844982. Development false alerts increase from 8.6% to 10.0%, failing the 5% ceiling. Required-approval recall rises from 40.0% to 71.4%. These are explicit policy decisions on a development panel, not measured detection rates in live networks. Always predicting permitted would answer 140/175 correctly and detect none of the 35 required approvals.
All eleven extra threshold detections concern innerText or textContent.
Thirteen of the twenty additional correct argmax answers are console-negative
questions. The panel lacks console-positive and code-execution-positive cases;
it has one onward-request positive. HTML-policy negatives remain weak at 2/21
correct argmax answers, and their threshold false alerts increase from 9/21 to
12/21. The aggregate does not establish every operation's detection quality.
| Retained panel | Published parent | This release |
|---|---|---|
| Manual SwarmTraces | 65/83 | 66/83 |
| Static SwarmTraces | 345/354 | 347/354 |
| Native Sysmon | 409/410 | 409/410 |
| ExCyTIn | 398/398 | 398/398 |
| Original Sysmon | 62/64 | 62/64 |
| General | 86/105 | 86/105 |
| GUIDE triage | 130/231 | 131/231 |
| GUIDE detector | 638/1,064 | 639/1,064 |
All 25 correctness-retention checks pass. Unchanged totals do not imply unchanged individual answers. GUIDE detector calibrated negative log loss worsens by 0.0116 and Brier by 0.0077. No matched continuation without the new component was run, so the isolated causal contribution of SwarmTraces is not established.
The separate DNS diagnostic remains 21/32, with one repair and one new error. It contains eight authored summaries and controls inspired by one reported incident, not raw packet captures or eight independent incidents. It is evaluation-only. The new error fails the registered zero-regression criterion. Policy evaluation, DNS evaluation, and registered screen retain the complete comparisons.
Calibration and artifact verification
The shipped temperature minimizes question-weighted negative log loss on 2,674 calibration questions from 1,920 records. Five-fold diagnostics keep all 465 source groups intact across task families. Raw calibration ECE is 0.07626 and out-of-fold ECE is 0.03386. This is a calibration diagnostic, not fresh field validation. Development and DNS observations were excluded from fitting.
Only temperature metadata changed when assembling the serving copy. Learned head tensors, adapter and tokenizer bytes match the evaluated checkpoint. Calibration, integrity evidence, and SHA256SUMS identify the release files.
Research iteration is paused following this release. The 0.8B and 9B checkpoints are not updated by this publication.
License and attribution
Source and adapter/head weights carry Apache-2.0 notices. Preserve LICENSE, NOTICE and the Qwen BASE_LICENSE. Sev builds on Kev by Jared Palmer and Qwen3.5 by the Qwen team.
Each dataset retains its own terms. Upstream SwarmTraces reuse terms remain unverified; the model license does not relicense those artifacts. The collection includes metadata-only entries, and membership does not imply training use. The historical synthetic source's notice applies only to that source. See data provenance.
Identity and Version
- Repository
- macmacmacmac/Sev-4B
- Publisher
- Rr
- Task
- Not stated by the source
- Modality
- Other
- Library
- peft
- Parameters
- Not stated by the source
- Languages
- en
- Revision
- da0a131c2636b06c16bbca7d8ae84f0dc1e90b7e
- First published
- 2026-09-25
- Last updated
- 2026-09-28
Files and Weights
26 files, 155.5 MB in total. The weights are 2 files totalling 135.2 MB in pt, safetensors.
Every file
| File | Type | Size | SHA-256 |
|---|---|---|---|
| adapter_model.safetensors | Weights | 129.9 MB | fa1916b34fe1 |
| head.pt | Weights | 5.3 MB | 12112262e182 |
| adapter_config.json | Configuration | 1.3 KB | — |
| calibration-sources.json | Configuration | 925 B | — |
| calibration.json | Configuration | 4.6 KB | — |
| checkpoint-integrity.json | Configuration | 1.5 KB | — |
| dns-evaluation.json | Configuration | 40.8 KB | — |
| evaluation.json | Configuration | 148.4 KB | — |
| independent-review.json | Configuration | 20.4 KB | — |
| provenance.json | Configuration | 4.2 KB | — |
| release.json | Configuration | 1.2 KB | — |
| result.json | Configuration | 82.1 KB | — |
| screen.json | Configuration | 7.2 KB | — |
| training_config.json | Configuration | 1.8 KB | — |
| training_metrics.json | Configuration | 321 B | — |
| BASE_LICENSE | Documentation | 11.3 KB | — |
| DATA_PROVENANCE.md | Documentation | 7.5 KB | — |
| LICENSE | Documentation | 11.3 KB | — |
| NOTICE | Documentation | 1.0 KB | — |
| README.md | Documentation | 7.7 KB | — |
| SHA256SUMS | Other | 2.1 KB | — |
| chat_template.jinja | Other | 7.8 KB | — |
| train.log | Other | 5.7 KB | — |
| .gitattributes | Repository | 1.6 KB | — |
| tokenizer.json | Tokenizer | 20.0 MB | 06b9509352d2 |
| tokenizer_config.json | Tokenizer | 1.1 KB | — |
License and Download
- License
- apache-2.0
- Access
- Open weights, no gate
- Download size
- 135.2 MB
Released by Rr through its official repository on Hugging Face. Read the license.
Built From
- Adapter of Qwen/Qwen3.5-4B-Base
- Derived from Qwen/Qwen3.5-4B-Base
- Trained on (disclosed) macmacmacmac/Sev-behavioral-research-v1
- Trained on (disclosed) macmacmacmac/openai-agent-swarmtraces
Memory Requirements
| Precision | Weights in memory |
|---|---|
| As published | 135.2 MB |
Weights only, from the published parameter count; the key-value cache and runtime add to this.
Questions About Sev-4B
Can I use Sev-4B commercially?
Yes. Sev-4B is released under Apache License 2.0. The Apache License 2.0 is a permissive open-source license. It permits commercial use, modification and redistribution. It requires keeping the license and copyright notices and any NOTICE file, stating significant changes, and it includes an express patent grant from contributors.