Downloads · 30 days
0
AIIT-Threshold/psy-6.9m
psy-6.9m is a machine learning model from AIIT-Threshold. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
Psy 6.9M is a byte-level, zero-language (non-linguistic, byte-level-only — it never tokenizes or generates natural-language text) defensive cyber-artifact encoder.
Downloads · 30 days
0
Access
Public
Updated Jul 4, 2026
Repo size
27.6 MB
Likes
2
Public
Click a slice to open those files.
.pt27.6 MB · 100%
From the Hugging Face model README
Psy 6.9M is a byte-level, zero-language (non-linguistic, byte-level-only — it never tokenizes or generates natural-language text) defensive cyber-artifact encoder.
It does not chat. It does not generate code. It does not patch systems. It does not execute artifacts.
It consumes already-structured cyber artifacts (a sanitized CVE record, a
detection-rule AST, a network-flow header) and emits one strict-JSON
status/verdict frame. The full architecture, class semantics, probe metrics, and
integrity hashes are in MODEL_CARD.md.
License: Apache-2.0 (see LICENSE).
| Family | Probe head in v0.1 | End-to-end result |
|---|---|---|
| CVE_RECORD | Yes | encoder + probe head |
| RULE_AST | Yes | encoder + probe head |
| NETWORK_FLOW | No (encoder-only) | encoder-only, always returns PSY_UNCERTAIN |
Unsupported families, and any family whose probe head is absent, return
PSY_UNCERTAIN (mode: encoder_only).
This bundle ships only the minimal Psy runtime surface:
checkpoints/psy_6.9m_encoder.pt)checkpoints/heads/cve_sanitized_head.pt, checkpoints/heads/rule_ast_head.pt), each Linear(256->3)docs/PSY_MEMORY_ARCHITECTURE.mdEarlier pre-export notes said no probe-head .pt files were included. That is no
longer accurate. The CVE_RECORD and RULE_AST heads ARE included and load
cleanly, and they drive the demo verdicts. Only the NETWORK_FLOW head is not
shipped in v0.1, so NETWORK_FLOW runs encoder-only and always returns
PSY_UNCERTAIN. See RELEASE_NOTES.md for why NETWORK_FLOW is held back.
weights_only=True)torch >= 2.0 (CPU-only is sufficient; the runtime forces torch.device("cpu"))Only torch is required directly; everything else is Python stdlib. See
requirements.txt. The runtime is CPU-only by design and never touches a GPU,
so a plain pip install -r requirements.txt will pull a much larger
CUDA-enabled torch wheel than needed — installing the CPU-only build instead
(e.g. pip install torch --index-url https://download.pytorch.org/whl/cpu) is
faster and lighter with no functional difference here. If you install torch
without numpy present, torch itself may print a harmless
Failed to initialize NumPy: No module named 'numpy' warning to stderr on
startup — this does not affect the strict-JSON stdout output or exit code.
From the extracted bundle root:
# Decisive anomaly path (probe head runs, returns BLOCK):
python3 scripts/run_demo.py --artifact demo_artifacts/rule_ast_sample.jsonl
# CVE probe head runs; this sample lands on the "investigate" class -> ABSTAIN:
python3 scripts/run_demo.py --artifact demo_artifacts/cve_record_sample.jsonl
# NETWORK_FLOW has no head in v0.1 -> encoder-only, PSY_UNCERTAIN:
python3 scripts/run_demo.py --artifact demo_artifacts/network_flow_sample.jsonl
Each command prints one strict-JSON Psy status/verdict frame to stdout (exit 0).
Note:
--artifacttakes a local filesystem path with no path-confinement checks — fine for this shipped offline single-user CLI (the invoking user already has whatever access the path implies), but anyone wrapping this runtime in a service that accepts a path/id from a remote caller must add their own root-confinement/canonicalization; none is provided here to copy.
Verified outputs:
rule_ast_sample -> status: PSY_ANOMALY_FOUND, action: BLOCK, mode: encoder_plus_probe_head, label: 2, confidence: 0.8381cve_record_sample -> status: PSY_UNCERTAIN, action: ABSTAIN, mode: encoder_plus_probe_head, label: 1, confidence: 0.9996 (a confident middle-class prediction, not a fallback)network_flow_sample -> status: PSY_UNCERTAIN, action: ABSTAIN, mode: encoder_only, head_status: probe_head_not_present, confidence: 0.0Note:
PSY_UNCERTAINmeans two different things — a confident label-1 (MEDIUM/INVESTIGATE) prediction, and "no head available." Disambiguate withmode/head_status/confidence, not the status string alone. See the class -> opcode table inMODEL_CARD.md.
python3 scripts/validate_bundle.py
python3 scripts/run_demo.py --artifact demo_artifacts/rule_ast_sample.jsonl
validate_bundle.py checks required files, re-derives the encoder parameter
count (must equal 6,904,064), verifies JSON/JSONL parse, and scans for secrets
and non-loopback IPs. On a clean release it prints status: PASSED (exit 0)
with a single expected warning: optional probe head not present: checkpoints/heads/network_flow_head.pt.
You can also verify integrity directly:
sha256sum checkpoints/psy_6.9m_encoder.pt
# expect: 2d0a15792bcdfbebfbf689ca0dddd39f9259525bbe9bee9d491289af4e590dbc
This is only Psy as a small artifact-encoder runtime/demo bundle. It is not a larger system and includes no other components or agents.
This bundle intentionally excludes: