Model Card for Panther Read Intent Classifier

Multilingual User-Intent & Request-Routing Classifier for Real-World AI Agent Security

Panther Read is a multilingual ModernBERT-based (mmBERT) classifier that detects the operational intent of a request and routes it to the right capability. It is part of the Patronus Protect security stack and is the dedicated single-head counterpart to the routing head of Lion Warden.

Intended Uses

The model maps an input text to exactly one class:

id label description
0 benign_conv Ordinary conversation with no operational request.
1 code_development_request A request to write, debug, or reason about code.
2 data_analytics_request A request to query, analyze, or visualize data.
3 office_request A document / office task (drafting, summarizing, email).
4 tool_operation_request A request that intends to operate a tool or run an action.

Examples:

Input Expected class
How was your weekend? benign_conv
Write a Python function that merges overlapping intervals code_development_request
Chart the weekly conversion rate from the signups table data_analytics_request
Draft a polite email to the vendor about the invoice office_request
List every file in the reports directory and read summary.txt tool_operation_request

Typical downstream uses:

  • request routing and capability selection,
  • AI agent orchestration,
  • policy and approval routing,
  • runtime monitoring.

Limitations

  • A positive prediction describes an apparent property of the input, not proof that an action was executed.
  • The model does not track information flow across multiple agent steps.
  • German and English are the primary evaluated languages; other languages run through the multilingual backbone but were not actively validated.
  • False positives and negatives are possible. High-impact enforcement should combine the model with deterministic policy and calibrated thresholds.

Model Variants

  • Panther Read Intent Classifier – full ModernBERT model in FP32 (model.safetensors).
  • Panther Read Intent Classifier ONNX (FP16)onnx/onnx_fp16/model_fp16.onnx in this repository.
  • Panther Read Intent Classifier Edge – quantized ONNX builds (int8, int8_int4_embeddings, fp16) in a separate edge repository.
  • Panther Read Intent Classifier NTDB L2 – lightweight multilingual cascade components under l2/ for efficient local runtime classification.

Training Data

Trained on Patronus' in-house multilingual dataset for this task, built from cleaned real-world sources plus internally generated examples. Real-world sources were judge-cleaned by content (no keyword heuristics) and contaminated rows removed.

Augmentations

To improve robustness the dataset includes modern obfuscation techniques:

  • Unicode variants
  • Homoglyph attacks
  • Encodings (e.g. base64)
  • Tag wrappers (User:, System:)
  • HTML tags
  • Code comments
  • Spacing noise
  • Leetspeak
  • Case noise
  • Combination of N augmentation techniques

Regularization

  • Natural-language wrappers around the payload
  • Counterfactual samples
  • Trigger-word / spurious-correlation corpora
  • ~90% similarity deduplication with a train/(val ∪ test) leakage guard

Reducing bias

All augmentations and regularizers are applied to positive and negative examples alike so the model keys on content rather than surface form.

Benchmark

Held-out test set (n = 1,880), single-label:

Metric Score
Accuracy 0.898
F1 (macro) 0.899
Precision (macro) 0.902
Recall (macro) 0.897

Per-class F1:

Class F1
code_development_request 0.919
tool_operation_request 0.918
data_analytics_request 0.894
benign_conv 0.889
office_request 0.876

Usage

from transformers import pipeline

clf = pipeline("text-classification", model="patronus-studio/panther-read-intent-classifier")
clf("Chart the weekly conversion rate from the signups table")
# -> [{"label": "data_analytics_request", "score": 0.98}]

ONNX

The FP16 ONNX export lives under onnx/onnx_fp16; the quantized builds (int8, int8_int4_embeddings) live in the separate Panther Read Intent Classifier Edge repository. Apply a softmax over the logits and take the argmax:

from optimum.onnxruntime import ORTModelForSequenceClassification
from transformers import AutoTokenizer

model_id = "patronus-studio/panther-read-intent-classifier"
tokenizer = AutoTokenizer.from_pretrained(model_id)
model = ORTModelForSequenceClassification.from_pretrained(model_id, subfolder="onnx/onnx_fp16", file_name="model_fp16.onnx")

inputs = tokenizer("Chart the weekly conversion rate from the signups table", return_tensors="pt")
logits = model(**inputs).logits.detach().cpu().numpy()[0]
print(model.config.id2label[int(logits.argmax())])

Citation

@misc{pantherread2026,
  title={Panther Read Intent Classifier: Multilingual Classification for Real-World AI Agent Security},
  author={Patronus Protect},
  year={2026},
  howpublished={\url{https://huggingface.co/patronus-studio/panther-read-intent-classifier}}
}

License

This model is released under the Apache License 2.0. A copy of the license is included as LICENSE in this repository.

The model is derived from jhu-clsp/mmBERT-small, which is distributed under the MIT License. The upstream copyright and permission notice are retained; the MIT terms continue to apply to the portions originating from that work.

Patronus Ark

This model is built to run inside Patronus Ark, Patronus' open-source on-device AI-security scanning library (L1 native rules → L2 NTDB cascade → L3 transformer). Ark is not publicly released yet — a repository link will be added here at launch.


🛡️ Patronus Protect

Brought to you by Patronus Protect — a local AI firewall that secures every AI interaction, including prompts, tools and documents, before it reaches your models.

Try it for free at patronus.studio.

Downloads last month
5
Safetensors
Model size
0.1B params
Tensor type
F32
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for patronus-studio/panther-read-intent-classifier

Quantized
(264)
this model
Quantizations
1 model

Collection including patronus-studio/panther-read-intent-classifier