Instructions to use abdallah3id/ABD3ID-CyberGuard-32B with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers
How to use abdallah3id/ABD3ID-CyberGuard-32B with Transformers:
# Use a pipeline as a high-level helper from transformers import pipeline pipe = pipeline("text-generation", model="abdallah3id/ABD3ID-CyberGuard-32B") messages = [ {"role": "user", "content": "Who are you?"}, ] pipe(messages)# pip install -U transformers accelerate # Load model directly from transformers import AutoTokenizer, AutoModelForCausalLM tokenizer = AutoTokenizer.from_pretrained("abdallah3id/ABD3ID-CyberGuard-32B") model = AutoModelForCausalLM.from_pretrained("abdallah3id/ABD3ID-CyberGuard-32B", device_map="auto") messages = [ {"role": "user", "content": "Who are you?"}, ] inputs = tokenizer.apply_chat_template( messages, add_generation_prompt=True, tokenize=True, return_dict=True, return_tensors="pt", ).to(model.device) outputs = model.generate(**inputs, max_new_tokens=256) print(tokenizer.decode(outputs[0][inputs["input_ids"].shape[-1]:])) - Notebooks
- Google Colab
- Kaggle
- Local Apps Settings
- vLLM
How to use abdallah3id/ABD3ID-CyberGuard-32B with vLLM:
Install from pip and serve model
# Install vLLM from pip: pip install vllm # Start the vLLM server: vllm serve "abdallah3id/ABD3ID-CyberGuard-32B" # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:8000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "abdallah3id/ABD3ID-CyberGuard-32B", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker
docker model run hf.co/abdallah3id/ABD3ID-CyberGuard-32B
- SGLang
How to use abdallah3id/ABD3ID-CyberGuard-32B with SGLang:
Install from pip and serve model
# Install SGLang from pip: pip install sglang # Start the SGLang server: python3 -m sglang.launch_server \ --model-path "abdallah3id/ABD3ID-CyberGuard-32B" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "abdallah3id/ABD3ID-CyberGuard-32B", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker images
docker run --gpus all \ --shm-size 32g \ -p 30000:30000 \ -v ~/.cache/huggingface:/root/.cache/huggingface \ --env "HF_TOKEN=<secret>" \ --ipc=host \ lmsysorg/sglang:latest \ python3 -m sglang.launch_server \ --model-path "abdallah3id/ABD3ID-CyberGuard-32B" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "abdallah3id/ABD3ID-CyberGuard-32B", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }' - Docker Model Runner
How to use abdallah3id/ABD3ID-CyberGuard-32B with Docker Model Runner:
docker model run hf.co/abdallah3id/ABD3ID-CyberGuard-32B
- π‘οΈ ABD3ID CyberGuard 32B
- π― Research Objectives
- π§ Training & Evaluation Workflow (Conceptual)
- βοΈ Full-Parameter Fine-Tuning
- π Training & Evaluation Dashboard
- π Evaluation Plan
- π Base Model vs CyberGuard β Benchmark Framework
- π§ͺ Evaluation Methodology
- π‘ Example 1 β Vulnerability Analysis
- π‘ Example 2 β Security Alert Triage
- π‘οΈ Intended Safety Boundary
- π¦ Future Release Contents
- β οΈ Limitations
- π Project Attribution & License Scope
- π¬ Research Transparency
- πΊοΈ Development Roadmap
π‘οΈ ABD3ID CyberGuard 32B
Defensive Cybersecurity β’ Full-Parameter Fine-Tuning β’ Evaluation Research
A 32B-class full-parameter fine-tuning project for evidence-based defensive cybersecurity, developed and maintained by Abdallah Eid.
π Project Overview
ABD3ID CyberGuard 32B is a full-parameter fine-tuning project for adapting a 32B-class language model to authorized defensive cybersecurity workflows. Training was performed with the Hugging Face Transformers framework, updating the model weights.
The objective is to investigate whether supervised fine-tuning can improve a general-purpose language model's ability to assist security analysts, developers, researchers, and defenders with evidence-based cybersecurity tasks.
The intended system focuses on authorized defensive workflows, including security analysis, vulnerability interpretation, secure-code review, incident-response assistance, remediation planning, and cybersecurity education.
Current status: Full-model fine-tuning completed; checkpoint files are available.
Checkpoint manifest: Add the exact weight filenames, formats, and sizes from the released checkpoint before publishing this README.
Evaluation status: Formal reproducible held-out benchmarking is still required.
Project Scope & Technical Contributions
The project, authored and maintained by Abdallah Eid, documents a full-model adaptation effort for defensive cybersecurity:
- Full-parameter supervised fine-tuning of the base-model weights using Hugging Face Transformers.
- Documentation of the training workflow, model and tokenizer identification requirements, and checkpoint packaging requirements.
- A defensive task taxonomy spanning vulnerability analysis, secure-code review, incident triage, and remediation.
- A base-versus-fine-tuned-model evaluation framework covering held-out testing, safety, false positives, and expert review.
- Explicit separation of released artifacts, illustrative examples, planned capabilities, and measured results.
These points describe the repository's technical scope. They are not a claim of verified model accuracy, superiority over the base model, or completed independent evaluation.
π― Research Objectives
CyberGuard is designed around five primary research areas:
| Area | Intended Capability |
|---|---|
| π Threat Analysis | Explain alerts, suspicious behavior, and security findings |
| π§© Vulnerability Analysis | Interpret vulnerabilities and prioritize remediation |
| π» Secure Code Review | Identify insecure patterns and recommend safer implementations |
| π¨ Incident Response | Summarize evidence and generate defensive response checklists |
| π Security Education | Explain cybersecurity concepts in authorized environments |
π§ Training & Evaluation Workflow (Conceptual)
ββββββββββββββββββββββββββββββββββββββββ
β CURATED DEFENSIVE DATA β
β Security β’ Code β’ CVEs β’ IR Data β
ββββββββββββββββββββ€ββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββ
β DATA QUALITY PIPELINE β
β β
β Deduplicate β
β β β
β Security Review β
β β β
β Quality Filtering β
β β β
β Train / Validation / Test Split β
ββββββββββββββββββββ¬ββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββ
β INSTRUCTION FORMATTING β
β + β
β TOKENIZATION β
ββββββββββββββββββββ€ββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββ
β β
β 32B-CLASS BASE MODEL β
β β
β Model weights initialized from β
β the base model β
β β
β β β
β β
β FULL-PARAMETER SUPERVISED β
β FINE-TUNING WITH β
β HUGGING FACE TRANSFORMERS β
β β
β Update model parameters ΞΈ β
β β
ββββββββββββββββββββ¬ββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββ
β SUPERVISED FINE-TUNING β
β β
β Optimize model weights on the β
β documented training data β
ββββββββββββββββββββ€ββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββ
β HELD-OUT EVALUATION β
β β
β β’ Security accuracy β
β β’ Remediation quality β
β β’ False-positive analysis β
β β’ Safety evaluation β
β β’ Base-model comparison β
ββββββββββββββββββββ¬ββββββββββββββββββββ
β
βΌ
ββββββββββββββββββββββββββββββββββββββββ
β HUMAN REVIEW β
β β
β Security Expert Validation β
ββββββββββββββββββββ€ββββββββββββββββββββ
β
βΌ
RELEASE DECISION
βοΈ Full-Parameter Fine-Tuning
CyberGuard uses full-parameter supervised fine-tuning with the Hugging Face Transformers framework. Unlike LoRA, this approach updates the base model's trainable weights and produces a fine-tuned model checkpoint rather than a standalone low-rank adapter.
The training starts from the identified base-model parameters and optimizes the model against the supervised training objective. Exact model revisions, trainable parameter counts, optimizer settings, precision, and hardware should be reported from the actual training configuration; they are not inferred here.
Conceptually:
Initial model parameters:
ΞΈβ
Supervised fine-tuning:
ΞΈ* = arg min_ΞΈ L(D_train; ΞΈ)
Fine-tuned model checkpoint:
ΞΈ*
Where:
ΞΈβ= parameters from the exact base-model revisionΞΈ= model parameters optimized during trainingD_train= the documented training datasetL= the supervised training objectiveΞΈ*= parameters saved in the resulting full-model checkpoint
Transformers is the training framework; full-parameter fine-tuning describes the weight-update method. Publish the training configuration and checkpoint manifest so these claims can be independently inspected.
π Training & Evaluation Dashboard
β Current Release Status
| Component | Status |
|---|---|
| Project design | β Complete |
| Full-model checkpoint | β Produced; file manifest to be documented |
| Training framework | β Hugging Face Transformers |
| Tokenizer assets | β Available |
| Model card | β Available |
| Project artwork | β Available |
| Formal held-out benchmark | π§ͺ Pending |
| Independent expert review | π§ͺ Recommended |
| Workstream | Status |
|---|---|
| Project design and full-model fine-tuning | Complete |
| Fine-tuned checkpoint | Produced; filenames and sizes to be documented |
| Documentation | In progress |
| Formal benchmarking | Pending |
| Independent review | Recommended; pending |
Reproducibility Manifest
For a technically auditable full-model release, publish the following values from the actual training run and checkpoint metadata. Do not infer missing settings:
| Record | Required details |
|---|---|
| Base model | Repository or provider, exact model identifier, revision/commit, and applicable license |
| Tokenizer | Identifier and revision, tokenizer files, special tokens, and chat template |
| Training data | Sources, licenses, provenance, filtering, deduplication, split sizes, and contamination controls |
| Training recipe | Transformers and PyTorch versions, optimizer, learning-rate schedule, warmup, weight decay, batch and accumulation settings, sequence length, precision, steps/epochs, and stopping criteria |
| Runtime | Hardware/GPU model, memory, software environment, distributed-training configuration, and random seeds |
| Checkpoint | Exact file names, formats, per-file and total sizes, configuration files, and SHA-256 checksums |
| Inference | Prompt template, generation parameters, runtime versions, and hardware used for reported results |
This manifest makes the training and release inspectable; it does not by itself establish model quality or benchmark performance.
π Evaluation Plan
CyberGuard's full-model fine-tuning is complete; the repository does not currently publish reproducible benchmark scores. Evaluation is a separate research stage, not an implied property of the checkpoint.
| Evaluation dimension | Evidence required | Current status |
|---|---|---|
| Defensive safety | Documented misuse-resistance test set and reviewed outcomes | Not measured |
| Security relevance | Held-out tasks with a published scoring rubric | Not measured |
| Remediation quality | Expert-rated correctness, completeness, and applicability | Not measured |
| Incident triage | Evidence-grounded decisions assessed against reference criteria | Not measured |
| Vulnerability analysis | Held-out vulnerability cases with per-class results | Not measured |
| Secure code review | Reproducible code samples and verified findings | Not measured |
| Evidence handling | Citation/support checks and unsupported-claim analysis | Not measured |
Report results only after publishing the benchmark data or a suitable data card, exact base-model and fine-tuned-checkpoint revisions, inference settings, scoring methodology, and limitations. Include sample counts and uncertainty where appropriate; do not convert project progress or intended capabilities into accuracy scores.
π Base Model vs CyberGuard β Benchmark Framework
ββββββββββββββββββββββ
β HELD-OUT TEST β
β SET β
βββββββββββ¬βββββββββββ
β
βββββββββββββ΄ββββββββββββ
βΌ βΌ
ββββββββββββββββββ ββββββββββββββββββ
β BASE MODEL β β CYBERGUARD β
β Unmodified β β Full Fine-Tunedβ
βββββββββ¬βββββββββ ββββββββββ¬ββββββββ
β β
βββββββββββββ¬βββββββββββββ
βΌ
βββββββββββββββββββββββ
β IDENTICAL METRICS β
βββββββββββββββββββββββ€
β Security accuracy β
β Remediation quality β
β False positives β
β Secure-code review β
β Incident triage β
β Safety behavior β
β Evidence quality β
ββββββββββββ¬βββββββββββ
βΌ
SECURITY EXPERT
REVIEW
| Metric | Base Model | CyberGuard | Status |
|---|---|---|---|
| Security Accuracy | TBD | TBD | π§ͺ Pending |
| Remediation Quality | TBD | TBD | π§ͺ Pending |
| False-Positive Rate | TBD | TBD | π§ͺ Pending |
| Secure-Code Review | TBD | TBD | π§ͺ Pending |
| Incident Analysis | TBD | TBD | π§ͺ Pending |
| Safety Evaluation | TBD | TBD | π§ͺ Pending |
Measured values should only be inserted after reproducible evaluation under identical conditions.
π§ͺ Evaluation Methodology
The fine-tuned model should be compared directly with the exact unmodified base-model revision.
Evaluation should include:
- A held-out test set separated before training, with documented provenance and contamination checks.
- The same prompt, context, tokenizer assumptions, and inference settings for the base and fine-tuned models.
- A declared task taxonomy and scoring rubric, with per-task results rather than a single opaque aggregate.
- Appropriate classification metrics (for example, precision, recall, F1, and false-positive/negative rates) alongside expert-rated response quality.
- Security-specific checks for evidence support, severity calibration, remediation correctness, and unsafe recommendations.
- Repeated or paired comparisons where appropriate, including sample counts and uncertainty estimates.
- Blinded independent review for security-sensitive outputs when feasible, with reviewer instructions and disagreement handling documented.
- Versioned model, tokenizer, dataset, and evaluation code identifiers, plus all decoding parameters.
- Failure analysis with representative errors, limitations, and known coverage gaps.
- A release gate that reports scores only after the methodology and results are reproducible.
π‘ Example 1 β Vulnerability Analysis
User
A web application builds a SQL query by directly concatenating
user-supplied input.
What is the security risk and what defensive remediation
would you recommend?
Illustrative CyberGuard Response
Finding:
Potential SQL injection vulnerability.
Reason:
Untrusted user input is being incorporated directly into a SQL
statement. An attacker may be able to alter the intended query.
Recommended remediation:
1. Replace string concatenation with parameterized queries or
prepared statements.
2. Validate input according to the application's expected data
format.
3. Apply least-privilege permissions to the database account.
4. Review similar database queries throughout the application.
5. Add security tests covering malicious and malformed inputs.
Priority:
High if attacker-controlled input reaches the database query
without parameterization.
This is an illustrative CyberGuard-style example, not a measured benchmark sample.
π‘ Example 2 β Security Alert Triage
User
Our monitoring system detected repeated failed login attempts
against one account from several IP addresses.
How should a security analyst investigate this alert?
Illustrative CyberGuard Response
Initial assessment:
The activity may represent credential guessing, password spraying,
automation, or legitimate authentication failures.
Recommended defensive investigation:
1. Verify the alert timestamps and affected account.
2. Review authentication logs for successful logins occurring
before, during, or after the failed attempts.
3. Compare source IP addresses, geographic indicators, user agents,
and authentication patterns.
4. Determine whether other accounts received similar attempts.
5. Review MFA events and account recovery activity.
6. Check whether the affected credentials are known to have been
exposed.
7. If compromise is suspected, follow the organization's incident
response procedure and protect the affected account.
Evidence required:
Do not classify the event as a confirmed compromise based only
on failed authentication attempts.
This example demonstrates the intended evidence-based defensive analysis style and is not a measured benchmark result.
π‘οΈ Intended Safety Boundary
CyberGuard is intended for:
β Defensive security analysis
β Authorized vulnerability assessment
β Secure software development
β Security education
β Incident investigation
β Security remediation
β Detection engineering
β Risk prioritization
The project is not intended to replace authorization requirements, organizational security controls, professional judgment, or independent validation.
π¦ Future Release Contents
A complete research release should include:
ABD3ID-CyberGuard-32B/
β
βββ README.md
βββ model/
β βββ [full-model weight files β list actual filenames and sizes]
β βββ config.json
β βββ [tokenizer files β list actual filenames]
βββ training_config.json
βββ evaluation/
β βββ results.json
β βββ base_model_results.json
β βββ methodology.md
βββ dataset_documentation/
β βββ DATASET_CARD.md
βββ examples/
βββ inference.md
The release documentation should identify:
- Exact base-model identifier
- Base-model revision
- Fine-tuned checkpoint filenames, formats, total size, and checksums
- Hugging Face Transformers version
- Training method and trainable parameter count
- Optimizer and scheduler
- Learning rate
- Warmup and weight-decay settings
- Batch configuration
- Gradient accumulation and checkpointing settings, if used
- Context length
- Precision
- Training steps / epochs
- Hardware configuration
- Dataset composition
- Evaluation methodology
- Reproducible benchmark results
β οΈ Limitations
CyberGuard is a research project.
Even after training, model-generated security recommendations may contain incorrect assumptions, incomplete analysis, false positives, or inaccurate remediation guidance.
Outputs should therefore be validated against:
- Original security evidence
- System configuration
- Application source code
- Vendor documentation
- Relevant vulnerability information
- Organizational security policies
- Qualified human review
A language model should not be treated as an autonomous security authority.
π Project Attribution & License Scope
Project author and maintainer: Abdallah Eid. The project name, original documentation, and other project-authored materials are attributed to Abdallah Eid.
Copyright Β© 2026 Abdallah Eid. All rights reserved for original project materials, except where a separate license or notice applies. This statement does not grant or change rights to third-party materials.
The base model, tokenizer, datasets, libraries, and other third-party components remain governed by their respective owners' licenses and terms. A fine-tuned checkpoint derived from a base model may also be subject to that model's license and distribution conditions. Do not interpret this project attribution as transferring third-party rights or as permission for uses not allowed by the applicable licenses.
Before redistributing or using the fine-tuned checkpoint, identify and document the exact base-model name and revision, its license, and the provenance and terms of any training data. The exact base-model identifier and revision are not specified in this README; confirm them from the checkpoint metadata and training records before making licensing or compatibility claims.
π¬ Research Transparency
This repository intentionally distinguishes between:
Planned capabilities
Features the research project intends to investigate.
Illustrative examples
Human-written demonstrations of the desired response style.
Measured capabilities
Results obtained through reproducible evaluation after training.
The fine-tuned checkpoint has been produced, but no formal measured CyberGuard benchmark claims are made until reproducible evaluation is completed.
πΊοΈ Development Roadmap
PHASE 01 ββββββββββββββββββββ Project Design β
β
PHASE 02 ββββββββββββββββββββ Full-Model Training β
β
PHASE 03 ββββββββββββββββββββ Repository Release β
β
PHASE 04 ββββββββββββββββββββ Documentation π
β
PHASE 05 ββββββββββββββββββββ Formal Benchmarking π§ͺ
β
PHASE 06 ββββββββββββββββββββ Expert Review π§ͺ
β
PHASE 07 ββββββββββββββββββββ Verified Evaluation β³
π‘οΈ ABD3ID CyberGuard 32B
Defensive AI β’ Full-Parameter Fine-Tuning β’ Transformers
Developed and maintained by Abdallah Eid
Status: Full-Model Fine-Tuning Complete β’ Formal Evaluation Pending
Security decisions require evidence, validation, and human review.
- Downloads last month
- 316