Downloads · 30 days
533
72% of all-time downloads
DuyTa/sec-rerank
sec-rerank is a text ranking model from DuyTa. Use it for the text ranking task on the model card, and read the license before you ship it in a product. It is set up for transformers. The card lists the license as apache-2.0.
This is a fine-tuned version of Qwen/Qwen3-Reranker-0.6B — a listwise generative reranker (second-stage ranker), not an embedding model.
Downloads · 30 days
533
72% of all-time downloads
All-time downloads
739
Public
Parameters
596M
1.2 GB on disk
Likes
0
Public
Click a slice to open those files.
.safetensors1.2 GB · 99%
From the Hugging Face model README
This is a fine-tuned version of Qwen/Qwen3-Reranker-0.6B — a listwise generative reranker (second-stage ranker), not an embedding model.
It was trained on grouped query–document examples whose hard negatives were mined from a local Qdrant collection (cve_kb) built from CVE investigation trajectories. It does not emit dense vectors; it reorders first-stage candidates (e.g. from DuyTa/sec-embedding). It is the reranker component of the secAI stack, paired with DuyTa/Cyber-F1-AWQ.
From notebooks/Qwen3_Reranker_Colab.ipynb (ms-swift):
| Base | Qwen/Qwen3-Reranker-0.6B |
| Task | generative_reranker (causal-LM reranker / cross-encoder scoring) |
| Loss | listwise reranking (--loss_type listwise_reranker) |
| Tuner | full-parameter SFT (--tuner_type full) |
| Engine | ms-swift swift sft |
| Max length | 2048 |
| Learning rate | 6e-6 |
(query, positive, negative) rows are converted to SWIFT grouped ranking schema:
messages — system instruction + user querypositive_messages — gold CVE passagenegative_messages — Qdrant-mined hard-negative CVE passage(s)Train-time instruction:
Given a Vietnamese cybersecurity search query, retrieve passages from the CVE knowledge base that directly answer it.
SWIFT fills the native Qwen3-Reranker {Instruction} slot from that system message.
Positives and negatives are real CVE core-chunk text from local Qdrant cve_kb (NVD/MITRE). The negative is a near-miss CVE from the same collection — typically a different CWE (hard_negative_type: different_cwe): high lexical overlap, wrong document. The listwise objective ranks the gold passage above those mined hard negatives.
Split: 33.6k train / 4.2k validation grouped examples.
Built from five years of authoritative cybersecurity sources: NVD (173,473 CVEs), MITRE CWE (768 weakness types, mapped to ~92% of CVEs), CAPEC/ATT&CK (443/174 entries) and Exploit-DB (3,139 exploits, 2021–2026). Public datasets: DuyTa/Cyber_F1_v2, DuyTa/cve-kgrag-db.
Training hardware: 2×A100 80GB.
Measured on NVIDIA A100 80GB in the full production chatflow (Hybrid Search → Rerank → LLM), on a 1,000-sample security test set (40% CVE identification/classification, 40% remediation advice, 20% real-world scenario reasoning):
| Metric | Result | Target | Pass |
|---|---|---|---|
| Ranking quality — Precision@1 | 98.23% | > 90% | ✅ |
| Throughput | 4,862 docs/s (concurrency 128) | ≥ 180 rerank/s | ✅ |
Raw per-sample logs (reranking-precision-at-1.jsonl) and evaluation code are delivered with the acceptance package.
Score each (query, document) with the native Qwen3-Reranker generative yes/no head. Use only to rerank a short candidate list from dense / hybrid retrieval.
# vLLM / OpenAI-compatible rerank endpoint
# POST /v1/rerank
{
"model": "DuyTa/sec-rerank",
"query": "CVE-2021-44228 JNDI lookup on log4j",
"documents": ["...", "..."]
}
Released under Apache-2.0. Derived from Qwen/Qwen3-Reranker-0.6B (Apache-2.0); credit for the base reranker belongs to the Qwen team.