GAI Classifier β Stage-1 Champion (encrypted)
Public repository. The model binary is encrypted; the tokenizer and the public key are in the clear.
Contents
model.safetensors.enc.part.*β the encrypted Stage-1 weights, split into 40 MB parts (concatenate in sorted order to reassemble; the decrypt script does this).model.safetensors.encβ the full encrypted Stage-1 weights (optional; kept for compatibility).aes_key.encβ the AES key, wrapped with the RSA public key.model.enc.meta.jsonβ algorithm, nonce, GCM tag, the plaintext SHA-256, and the part count.public_key.pemβ the RSA public key.tokenizer.json,tokenizer_config.jsonβ plaintext.decrypt_weights.pyβ decryption script (handles the parts automatically).
Encryption
A random AES-256 key encrypts model.safetensors with AES-256-GCM (streamed). The AES key
is wrapped with RSA-4096 (OAEP, SHA-256) under public_key.pem. The matching RSA private
key is held by the authors and is not distributed, so the binary cannot be decrypted from
this repository alone.
Decryption
Obtain private_key.pem from the authors, then:
python decrypt_weights.py --bundle . --private /path/to/private_key.pem --out model.safetensors
The script verifies the restored file against the SHA-256 in model.enc.meta.json. The
decrypted model.safetensors, together with the tokenizer here and the Qwen3.5-0.8B-Base
backbone, loads through stage1_gai_classifier/modeling_gai_classifier.py in the
replication package.
Inference Providers NEW
This model isn't deployed by any Inference Provider. π Ask for provider support