Downloads · 30 days
0
0% of all-time downloads
CVRP/corvus-v2-8b
corvus-v2-8b is a text generation model from CVRP. Use it when you need the model to write or continue text. It is set up for peft. The card lists the license as llama3.1.
Corvus™ v2 is a fine-tuned Llama 3.1 8B model that produces structured triage decisions for software vulnerabilities. Given CVE data, CVSS scores, EPSS probability, KEV listing status, and asset context, it outputs a…
Downloads · 30 days
0
0% of all-time downloads
All-time downloads
108
Public
Repo size
21 GB
Likes
1
Public
Click a slice to open those files.
.md13.6 KB · 89%
From the Hugging Face model README
Corvus™ v2 is a fine-tuned Llama 3.1 8B model that produces structured triage decisions for software vulnerabilities. Given CVE data, CVSS scores, EPSS probability, KEV listing status, and asset context, it outputs a JSON decision with priority, recommended action, reasoning, and confidence score.
Built by CVERiskPilot — 100% Veteran Owned, Texas, USA.
Corvus v2 weights are not currently distributed on Hugging Face.
This repository remains public for model documentation, licensing terms, and release-status updates while distribution strategy is under review.
Offensive AI is accelerating. AI fuzzers are finding thousands of zero-days across every major codebase. The scanning problem is being solved. The triage problem is getting 10x harder.
Security teams are drowning in findings they can't prioritize fast enough. Attackers exploit in 5 days. Defenders patch in 209. That gap gets worse every quarter.
Corvus doesn't find vulnerabilities. It decides what to do about them — at machine speed, on local hardware, with no data leaving your environment.
| Property | Value |
|---|---|
| Base model | meta-llama/Llama-3.1-8B-Instruct |
| Fine-tuning method | QLoRA (r=16, alpha=32, dropout=0.05) |
| Training examples | 50,000+ labeled vulnerability triage decisions |
| Training compute | 8x NVIDIA A100 (Vertex AI), ~1.2 hours |
| Priority accuracy | 94.8% |
| Full match (priority + action) | 82.7% |
| Training loss (final) | 0.461 |
| Throughput | 11.9 samples/sec |
Use this model for: Prioritizing and triaging software vulnerabilities in security operations workflows. Deciding which CVEs need immediate attention vs. scheduled patching vs. risk acceptance.
Do not use this model for: Generating exploits, finding vulnerabilities, offensive security operations, or any purpose that could harm system security. This is a defensive triage tool.
Human oversight required: Model outputs are recommendations, not autonomous decisions. All triage decisions should be reviewed by a qualified security professional before action.
Corvus outputs structured JSON with five fields:
{
"severityOverride": "EPSS in top 1% with active exploitation — upgrading from MEDIUM to CRITICAL",
"priority": "CRITICAL",
"recommendedAction": "PATCH_IMMEDIATELY",
"reasoning": "CVE-2024-XXXXX affects the authentication module in a production-facing service. EPSS score of 0.94 indicates high exploitation probability. Listed in CISA KEV with a remediation deadline. The affected package is a direct dependency with no available workaround. Asset is internet-facing with access to PII.",
"confidenceScore": 0.92
}
| Field | Type | Description |
|---|---|---|
severityOverride | string | null | Explanation if the model's priority differs from raw CVSS severity |
priority | string | CRITICAL, HIGH, MEDIUM, or LOW |
recommendedAction | string | One of 6 actions (see below) |
reasoning | string | Detailed explanation referencing specific technical factors |
confidenceScore | number | 0.0 to 1.0 — model's confidence in the decision |
| Action | When to use |
|---|---|
PATCH_IMMEDIATELY | Active exploitation, critical asset, no workaround |
SCHEDULE_PATCH | Important but not actively exploited, patch available |
MITIGATE | Patch unavailable or risky — apply compensating controls |
ACCEPT_RISK | Low impact, unreachable code path, network-isolated asset |
INVESTIGATE | Insufficient data to make a confident decision |
DEFER | Non-critical, low EPSS, no KEV listing, internal-only asset |
If distribution resumes, CVERiskPilot will publish updated instructions here.
For evaluation, partnership, or commercial licensing inquiries, contact sales@cveriskpilot.com.
The model expects vulnerability data as a newline-separated key-value string:
CVE: CVE-2024-3094
Title: XZ Utils Backdoor
Severity: CRITICAL
CVSS: 10.0
EPSS: 0.97
KEV: Yes
Package: xz-utils@5.6.0
Description: Malicious backdoor in XZ Utils compression library allowing unauthorized access via modified liblzma in SSH authentication path
| Field | Required | Description |
|---|---|---|
Title | Yes | Vulnerability title or summary |
CVE | No | CVE identifier(s), comma-separated |
Severity | No | CVSS severity label (CRITICAL/HIGH/MEDIUM/LOW) |
CVSS | No | CVSS base score (0.0-10.0) |
EPSS | No | EPSS exploitation probability (0.0-1.0) |
KEV | No | CISA Known Exploited Vulnerabilities listing (Yes/No) |
Package | No | Affected package name and version |
Description | No | Vulnerability description (truncated to 500 chars) |
The model performs best with more context. Providing EPSS, KEV, and CVSS together produces the most accurate triage decisions.
The model was trained on 50,000+ labeled vulnerability triage examples generated through a synthetic data pipeline with 6-layer quality validation:
The training data is not included in this release.
Evaluated on a held-out test set of 5,000 examples:
| Metric | Score |
|---|---|
| Priority accuracy (4-class) | 94.8% |
| Action accuracy (6-class) | 84.4% |
| Full match (priority + action) | 82.7% |
| Confidence calibration (ECE) | 0.08 |
This model is designed exclusively for defensive security operations. It helps security teams prioritize remediation work, not bypass security controls.
We release it openly because we believe defensive AI capabilities should not be gated behind enterprise contracts while offensive AI capabilities continue to advance. Security teams at organizations of every size deserve access to intelligent triage.
The model outputs recommendations, not autonomous actions. Every decision should be reviewed by a qualified professional before implementation.
GGUF quantization performed with llama-cpp-python:
| Quantization | Size | Quality | Use case |
|---|---|---|---|
| f16 | 16 GB | Full precision | Research, benchmarking |
| Q4_K_M | 4.6 GB | Minimal loss | Production, single GPU |
@misc{corvus-v2-2026,
title={Corvus v2: A Fine-Tuned Language Model for Vulnerability Triage},
author={CVERiskPilot},
year={2026},
url={https://huggingface.co/CVRP/corvus-v2-8b},
note={QLoRA fine-tuned Llama 3.1 8B on 50K+ vulnerability triage examples}
}
This model is released under the Llama 3.1 Community License with the following additional terms from CVERiskPilot LLC:
Permitted use:
Restricted use (requires a commercial license from CVERiskPilot LLC):
Trademark notice:
For commercial licensing inquiries: sales@cveriskpilot.com
Corvus™ was created by CVERiskPilot LLC and has been in continuous development and commercial use since January 2026.
| Milestone | Date |
|---|---|
| CVERiskPilot LLC incorporated (Texas) | 2026 |
| Corvus v1 (Strix) internal deployment | January 2026 |
| Corvus v2 training data pipeline (50K+ examples) | February–March 2026 |
| Corvus v2 QLoRA training completed (Vertex AI) | April 5, 2026 |
| Corvus v2 deployed to production (CVERiskPilot platform) | April 8, 2026 |
| Corvus v2 public Hugging Face documentation repository | April 2026 |
| NVIDIA Inception program membership | Active |
All training artifacts, commit history, GCP job logs, and deployment records are retained by CVERiskPilot LLC as evidence of continuous use and first use in commerce.
CVERiskPilot LLC | 100% Veteran Owned | Texas, USA