GAI Classifier β€” Stage-1 Champion (encrypted)

Public repository. The model binary is encrypted; the tokenizer and the public key are in the clear.

Contents

  • model.safetensors.enc.part.* β€” the encrypted Stage-1 weights, split into 40 MB parts (concatenate in sorted order to reassemble; the decrypt script does this).
  • model.safetensors.enc β€” the full encrypted Stage-1 weights (optional; kept for compatibility).
  • aes_key.enc β€” the AES key, wrapped with the RSA public key.
  • model.enc.meta.json β€” algorithm, nonce, GCM tag, the plaintext SHA-256, and the part count.
  • public_key.pem β€” the RSA public key.
  • tokenizer.json, tokenizer_config.json β€” plaintext.
  • decrypt_weights.py β€” decryption script (handles the parts automatically).

Encryption

A random AES-256 key encrypts model.safetensors with AES-256-GCM (streamed). The AES key is wrapped with RSA-4096 (OAEP, SHA-256) under public_key.pem. The matching RSA private key is held by the authors and is not distributed, so the binary cannot be decrypted from this repository alone.

Decryption

Obtain private_key.pem from the authors, then:

python decrypt_weights.py --bundle . --private /path/to/private_key.pem --out model.safetensors

The script verifies the restored file against the SHA-256 in model.enc.meta.json. The decrypted model.safetensors, together with the tokenizer here and the Qwen3.5-0.8B-Base backbone, loads through stage1_gai_classifier/modeling_gai_classifier.py in the replication package.

Downloads last month

-

Downloads are not tracked for this model. How to track
Inference Providers NEW
This model isn't deployed by any Inference Provider. πŸ™‹ Ask for provider support