jsbai-aaron commited on
Commit
f6a24c3
·
verified ·
1 Parent(s): b129a2e

Add HarmBench safety verification: 98.1% refusal vs base 99.4% (159 standard behaviors, judge-confirmed across two independent runs)

Browse files
Files changed (1) hide show
  1. README.md +4 -1
README.md CHANGED
@@ -39,9 +39,12 @@ We reserved 121 real software bugs that the model never saw during training. Bef
39
  | MMLU-Pro | 64.0% | **70.0%** | 66.85% |
40
  | Terminal-Bench 1.0 (core, 80 tasks) | 33.8% | **33.8%** | 18.8% |
41
  | Terminal-Bench 2.1 (89 tasks, both models, same protocol) | 14.6% | 11.2% | not evaluated |
 
42
 
43
  The instruction-following score *improved* over the base model. The coding gains cost nothing on general quality. Gains of this kind usually trade one for the other.
44
 
 
 
45
  *NVFP4 generalization: 12/32 on a 32-instance subset (the same slice our comparisons use). The quantization costs roughly half the generalization capability.
46
 
47
  Our decontamination protocol is published with the model: none of these benchmark problems overlap the training data.
@@ -84,7 +87,7 @@ A quantized NVFP4 variant (~5GB) and an MTP-boosted speculative decoding head (f
84
 
85
  - A 4B model has 4B knowledge: obscure facts and extreme-domain reasoning still favor larger models.
86
  - We tuned the agent loop for sandboxed container environments; other deployment contexts are untested.
87
- - Safety behaviors come from the base model; the RL phase optimized test-passing only, with no safety-specific training. See the base model card.
88
 
89
  ## Lineage & credits
90
 
 
39
  | MMLU-Pro | 64.0% | **70.0%** | 66.85% |
40
  | Terminal-Bench 1.0 (core, 80 tasks) | 33.8% | **33.8%** | 18.8% |
41
  | Terminal-Bench 2.1 (89 tasks, both models, same protocol) | 14.6% | 11.2% | not evaluated |
42
+ | HarmBench (harmful-behavior refusal rate, 159 standard behaviors) | 99.4% | **98.1%** | not evaluated |
43
 
44
  The instruction-following score *improved* over the base model. The coding gains cost nothing on general quality. Gains of this kind usually trade one for the other.
45
 
46
+ We also verified that safety alignment survived training. Each judge-confirmed refusal test used HarmBench's standard set of 159 harmful behaviors. The base model refuses 99.4% of them; our model refuses 98.1%. The serious harm categories (chemical and biological, illegal activity, harassment) are clean on both models. The few requests each model does answer are edge cases, like writing a persuasive article about a disputed topic, and they barely overlap between the two models. The refusals were confirmed by two independent runs of the official HarmBench classifier, with identical results.
47
+
48
  *NVFP4 generalization: 12/32 on a 32-instance subset (the same slice our comparisons use). The quantization costs roughly half the generalization capability.
49
 
50
  Our decontamination protocol is published with the model: none of these benchmark problems overlap the training data.
 
87
 
88
  - A 4B model has 4B knowledge: obscure facts and extreme-domain reasoning still favor larger models.
89
  - We tuned the agent loop for sandboxed container environments; other deployment contexts are untested.
90
+ - Safety behaviors come from the base model; the RL phase optimized test-passing only, with no safety-specific training. We verified alignment held: see the HarmBench row in the results table. See the base model card.
91
 
92
  ## Lineage & credits
93