Younis2003 commited on
Commit
d14d7d7
·
verified ·
1 Parent(s): 2b02bf2

Update README.md

Browse files
Files changed (1) hide show
  1. README.md +99 -142
README.md CHANGED
@@ -2,206 +2,163 @@
2
  base_model: meta-llama/CodeLlama-13b-hf
3
  library_name: peft
4
  pipeline_tag: text-generation
 
 
 
 
 
5
  tags:
6
- - base_model:adapter:meta-llama/CodeLlama-13b-hf
 
 
 
7
  - lora
8
- - transformers
9
  ---
10
 
11
- # Model Card for Model ID
12
 
13
- <!-- Provide a quick summary of what the model is/does. -->
14
 
 
15
 
 
16
 
17
- ## Model Details
18
 
19
- ### Model Description
20
-
21
- <!-- Provide a longer summary of what this model is. -->
22
-
23
-
24
-
25
- - **Developed by:** [More Information Needed]
26
- - **Funded by [optional]:** [More Information Needed]
27
- - **Shared by [optional]:** [More Information Needed]
28
- - **Model type:** [More Information Needed]
29
- - **Language(s) (NLP):** [More Information Needed]
30
- - **License:** [More Information Needed]
31
- - **Finetuned from model [optional]:** [More Information Needed]
32
-
33
- ### Model Sources [optional]
34
-
35
- <!-- Provide the basic links for the model. -->
36
-
37
- - **Repository:** [More Information Needed]
38
- - **Paper [optional]:** [More Information Needed]
39
- - **Demo [optional]:** [More Information Needed]
40
-
41
- ## Uses
42
-
43
- <!-- Address questions around how the model is intended to be used, including the foreseeable users of the model and those affected by the model. -->
44
-
45
- ### Direct Use
46
-
47
- <!-- This section is for the model use without fine-tuning or plugging into a larger ecosystem/app. -->
48
-
49
- [More Information Needed]
50
-
51
- ### Downstream Use [optional]
52
-
53
- <!-- This section is for the model use when fine-tuned for a task, or when plugged into a larger ecosystem/app -->
54
-
55
- [More Information Needed]
56
-
57
- ### Out-of-Scope Use
58
-
59
- <!-- This section addresses misuse, malicious use, and uses that the model will not work well for. -->
60
-
61
- [More Information Needed]
62
-
63
- ## Bias, Risks, and Limitations
64
-
65
- <!-- This section is meant to convey both technical and sociotechnical limitations. -->
66
-
67
- [More Information Needed]
68
-
69
- ### Recommendations
70
-
71
- <!-- This section is meant to convey recommendations with respect to the bias, risk, and technical limitations. -->
72
-
73
- Users (both direct and downstream) should be made aware of the risks, biases and limitations of the model. More information needed for further recommendations.
74
-
75
- ## How to Get Started with the Model
76
-
77
- Use the code below to get started with the model.
78
-
79
- [More Information Needed]
80
-
81
- ## Training Details
82
-
83
- ### Training Data
84
-
85
- <!-- This should link to a Dataset Card, perhaps with a short stub of information on what the training data is all about as well as documentation related to data pre-processing or additional filtering. -->
86
-
87
- [More Information Needed]
88
-
89
- ### Training Procedure
90
-
91
- <!-- This relates heavily to the Technical Specifications. Content here should link to that section when it is relevant to the training procedure. -->
92
-
93
- #### Preprocessing [optional]
94
-
95
- [More Information Needed]
96
-
97
-
98
- #### Training Hyperparameters
99
-
100
- - **Training regime:** [More Information Needed] <!--fp32, fp16 mixed precision, bf16 mixed precision, bf16 non-mixed precision, fp16 non-mixed precision, fp8 mixed precision -->
101
 
102
- #### Speeds, Sizes, Times [optional]
103
 
104
- <!-- This section provides information about throughput, start/end time, checkpoint size if relevant, etc. -->
 
 
 
 
105
 
106
- [More Information Needed]
107
 
108
- ## Evaluation
109
 
110
- <!-- This section describes the evaluation protocols and provides the results. -->
111
 
112
- ### Testing Data, Factors & Metrics
 
 
 
 
113
 
114
- #### Testing Data
115
 
116
- <!-- This should link to a Dataset Card if possible. -->
 
 
117
 
118
- [More Information Needed]
119
 
120
- #### Factors
121
 
122
- <!-- These are the things the evaluation is disaggregating by, e.g., subpopulations or domains. -->
123
 
124
- [More Information Needed]
 
 
125
 
126
- #### Metrics
127
 
128
- <!-- These are the evaluation metrics being used, ideally with a description of why. -->
129
 
130
- [More Information Needed]
131
 
132
- ### Results
133
 
134
- [More Information Needed]
135
 
136
- #### Summary
137
 
 
138
 
 
139
 
140
- ## Model Examination [optional]
141
 
142
- <!-- Relevant interpretability work for the model goes here -->
143
 
144
- [More Information Needed]
 
145
 
146
- ## Environmental Impact
147
 
148
- <!-- Total emissions (in grams of CO2eq) and additional considerations, such as electricity usage, go here. Edit the suggested text below accordingly -->
 
 
 
149
 
150
- Carbon emissions can be estimated using the [Machine Learning Impact calculator](https://mlco2.github.io/impact#compute) presented in [Lacoste et al. (2019)](https://arxiv.org/abs/1910.09700).
151
 
152
- - **Hardware Type:** [More Information Needed]
153
- - **Hours used:** [More Information Needed]
154
- - **Cloud Provider:** [More Information Needed]
155
- - **Compute Region:** [More Information Needed]
156
- - **Carbon Emitted:** [More Information Needed]
157
 
158
- ## Technical Specifications [optional]
159
 
160
- ### Model Architecture and Objective
 
 
161
 
162
- [More Information Needed]
 
163
 
164
- ### Compute Infrastructure
165
 
166
- [More Information Needed]
 
 
 
167
 
168
- #### Hardware
 
169
 
170
- [More Information Needed]
171
 
172
- #### Software
173
 
174
- [More Information Needed]
175
 
176
- ## Citation [optional]
177
 
178
- <!-- If there is a paper or blog post introducing the model, the APA and Bibtex information for that should go in this section. -->
179
 
180
- **BibTeX:**
 
 
181
 
182
- [More Information Needed]
183
 
184
- **APA:**
 
 
 
185
 
186
- [More Information Needed]
187
 
188
- ## Glossary [optional]
189
 
190
- <!-- If relevant, include terms and calculations in this section that can help readers understand the model or model card. -->
 
 
191
 
192
- [More Information Needed]
193
 
194
- ## More Information [optional]
195
 
196
- [More Information Needed]
197
 
198
- ## Model Card Authors [optional]
199
 
200
- [More Information Needed]
201
 
202
- ## Model Card Contact
203
 
204
- [More Information Needed]
205
- ### Framework versions
206
 
207
- - PEFT 0.18.1
 
 
2
  base_model: meta-llama/CodeLlama-13b-hf
3
  library_name: peft
4
  pipeline_tag: text-generation
5
+ language:
6
+ - en
7
+ license: apache-2.0
8
+ datasets:
9
+ - Younis2003/secure_dataset_cvefixes
10
  tags:
11
+ - cybersecurity
12
+ - vulnerability-detection
13
+ - secure-code
14
+ - codellama
15
  - lora
16
+ - peft
17
  ---
18
 
19
+ # CodeLlama_for_code_security
20
 
21
+ ## Overview
22
 
23
+ CodeLlama_for_code_security is a **LoRA fine-tuned adapter** designed for vulnerability detection and secure code remediation.
24
 
25
+ The model analyzes vulnerable source code and generates a secure fixed version together with structured vulnerability explanations including CVE and CWE metadata.
26
 
27
+ The adapter is trained on top of **CodeLlama-13B**.
28
 
29
+ ---
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
30
 
31
+ # Model Details
32
 
33
+ **Developed by:** Younis Alshibli
34
+ **Model type:** LoRA Adapter (PEFT)
35
+ **Base Model:** CodeLlama-13B
36
+ **Language:** English
37
+ **License:** Apache 2.0
38
 
39
+ ---
40
 
41
+ # Intended Use
42
 
43
+ The model is designed for:
44
 
45
+ - Vulnerability detection
46
+ - Secure code remediation
47
+ - Security analysis of source code
48
+ - Automated security review
49
+ - AI-assisted cybersecurity research
50
 
51
+ Example applications:
52
 
53
+ - Secure code assistants
54
+ - AI vulnerability scanners
55
+ - Cybersecurity research tools
56
 
57
+ ---
58
 
59
+ # Evaluation
60
 
61
+ The model was evaluated using **semantic similarity between generated fixes and ground truth secure fixes**.
62
 
63
+ | Metric | Score |
64
+ |------|------|
65
+ | Embedding Similarity | **0.9643** |
66
 
67
+ This corresponds to approximately **96% semantic similarity** between predicted outputs and expected secure code fixes.
68
 
69
+ ---
70
 
71
+ # Prompt Format
72
 
73
+ The model expects prompts in the following structured format:
74
 
75
+ ```
76
 
77
+ ### System:
78
 
79
+ You are a secure code remediation and vulnerability analysis engine.
80
 
81
+ ### Programming Language:
82
 
83
+ <language>
84
 
85
+ ### Vulnerable Code:
86
 
87
+ <code>
88
+ ```
89
 
90
+ The model will generate:
91
 
92
+ * Fixed Code
93
+ * Vulnerability Explanation
94
+ * CVE metadata
95
+ * CWE metadata
96
 
97
+ ---
98
 
99
+ # How to Use
 
 
 
 
100
 
101
+ This model is a **LoRA adapter** and requires the base model.
102
 
103
+ ```python
104
+ from transformers import AutoModelForCausalLM, AutoTokenizer
105
+ from peft import PeftModel
106
 
107
+ base_model = "meta-llama/CodeLlama-13b-hf"
108
+ adapter = "Younis2003/CodeLlama_for_code_security"
109
 
110
+ tokenizer = AutoTokenizer.from_pretrained(base_model)
111
 
112
+ model = AutoModelForCausalLM.from_pretrained(
113
+ base_model,
114
+ device_map="auto"
115
+ )
116
 
117
+ model = PeftModel.from_pretrained(model, adapter)
118
+ ```
119
 
120
+ ---
121
 
122
+ # Training Data
123
 
124
+ The model was trained using the dataset:
125
 
126
+ **secure_dataset_cvefixes**
127
 
128
+ Dataset source:
129
 
130
+ ```
131
+ Younis2003/secure_dataset_cvefixes
132
+ ```
133
 
134
+ The dataset contains:
135
 
136
+ * vulnerable code
137
+ * fixed code
138
+ * CVE descriptions
139
+ * CWE classifications
140
 
141
+ ---
142
 
143
+ # Limitations
144
 
145
+ * The model may not detect all vulnerabilities.
146
+ * Results should always be reviewed by security experts.
147
+ * Complex security flaws may require manual analysis.
148
 
149
+ ---
150
 
151
+ # Ethical Considerations
152
 
153
+ This model is intended for **defensive cybersecurity research and secure software development**.
154
 
155
+ It should not be used for malicious activities.
156
 
157
+ ---
158
 
159
+ # Author
160
 
161
+ Developed by **Younis Alshibli** as part of an AI research project on:
 
162
 
163
+ * AI vulnerability detection
164
+ * automated secure code remediation