Downloads · 30 days
42
6% of all-time downloads
dolutech/MinimoSec-V4-4B-GGUF
MinimoSec-V4-4B-GGUF is a machine learning model from dolutech. Use it for the machine learning task on the model card, and read the license before you ship it in a product. The card lists the license as apache-2.0.
Downloads · 30 days
42
6% of all-time downloads
All-time downloads
654
Public
Repo size
6.3 GB
Likes
1
Public
Click a slice to open those files.
.gguf6.3 GB · 100%
From the Hugging Face model README
Cybersecurity-specialised language model for Portuguese-speaking analysts
</div> ---MinimoSec V4 is a cybersecurity-specialised language model fine-tuned from Google Gemma 4 E4B using supervised fine-tuning (SFT) with Low-Rank Adaptation (LoRA) via the Unsloth framework.
The model was trained on 22,571 Portuguese-language cybersecurity examples covering threat analysis, malware identification, MITRE ATT&CK mapping, YARA rule generation, IOC extraction, and digital forensics. It is designed to assist security analysts, SOC teams, and researchers in Portuguese-speaking environments.
| Specification | Detail |
|---|---|
| Primary Language | Portuguese (pt-PT / pt-BR) |
| Domain | Cybersecurity, Threat Intelligence, Digital Forensics |
| Base Model | google/gemma-4-e4b-it |
| Training Epochs | 1 (V4-final with 3 epochs in development) |
| Quantisation Available | Q4_K_M GGUF (~5.3 GB) |
CyberBench-Hard is a specialized cybersecurity knowledge evaluation benchmark composed of 50 expert-level questions distributed across 10 categories. Questions are designed to test deep technical reasoning, factual accuracy, and hallucination resistance across critical information security domains.
This document presents partial results for categories D (Malware Analysis & Reverse Engineering) and G (MITRE ATT&CK & Threat Intelligence), evaluated on MinimoSec-V4-4B, a small-scale language model with specialized cybersecurity fine-tuning.
| Field | Detail |
|---|---|
| Model | MinimoSec-V4-4B |
| Base Architecture | Gemma 3 4B (4 billion parameters) |
| Fine-tuning | SFT (Supervised Fine-Tuning) |
| Dataset | 22,000 cybersecurity-focused samples |
| Specialization | Offensive & Defensive Cybersecurity |
| Evaluator | Lucas Catão de Moraes |
| Date | April 2026 |
| Methodology | Manual per-dimension evaluation with weighted criteria |
| Dimension | Weight | Description |
|---|---|---|
| Factual Correctness | 30% | Technical accuracy of the information presented |
| Technical Depth | 25% | Level of detail and demonstrated expertise |
| Completeness | 20% | Coverage of all sub-items in the question |
| Clarity & Structure | 15% | Organization, didactics, and readability |
| Absence of Hallucinations | 10% | Absence of fabricated terms, concepts, or data |
| Score | Classification |
|---|---|
| 9.0 – 10.0 | Expert-Level |
| 7.5 – 8.9 | Advanced |
| 6.0 – 7.4 | Intermediate |
| 4.0 – 5.9 | Basic |
| < 4.0 | Insufficient |
| # | Topic | Factual | Depth | Completeness | Clarity | Hallucinations | Score | Classification |
|---|---|---|---|---|---|---|---|---|
| D1 | Static / Dynamic Analysis | 6.0 | 5.5 | 6.0 | 7.5 | 6.0 | 6.10 | Intermediate |
| D2 | Packer / Crypter / Unpacking | 5.0 | 4.5 | 3.5 | 7.5 | 5.5 | 5.00 | Basic |
| D3 | Process Hollowing (T1055.012) | 7.0 | 6.0 | 5.5 | 8.0 | 6.5 | 6.55 | Intermediate |
| D4 | DKOM / Kernel Rootkit | 7.0 | 6.5 | 7.0 | 8.5 | 7.0 | 7.10 | Intermediate |
| D5 | DGA / C2 / ML Detection | 6.5 | 5.0 | 6.0 | 7.5 | 7.5 | 6.28 | Intermediate |
| Category D Average | 6.21 | Intermediate |
| # | Topic | Factual | Depth | Completeness | Clarity | Hallucinations | Score | Classification |
|---|---|---|---|---|---|---|---|---|
| G1 | MITRE ATT&CK Hierarchy | 2.0 | 3.0 | 2.0 | 7.0 | 1.5 | 2.95 | Insufficient |
| G2 | IoCs vs IoAs / SIEM / SOAR | 6.5 | 5.5 | 7.0 | 8.5 | 5.5 | 6.55 | Intermediate |
| G3 | Kill Chain / Diamond Model | 5.5 | 4.5 | 5.5 | 8.0 | 4.0 | 5.48 | Basic |
| G4 | Threat Hunting / LOLBins | 6.0 | 6.0 | 6.5 | 8.0 | 5.0 | 6.30 | Intermediate |
| G5 | STIX / TAXII | 5.0 | 4.0 | 5.5 | 7.5 | 4.0 | 5.13 | Basic |
| Category G Average | 5.28 | Basic |
| Category | Average | Classification | Best Response | Worst Response |
|---|---|---|---|---|
| D — Malware & RE | 6.21 | Intermediate | D4: DKOM / Rootkit (7.10) | D2: Packer / Crypter (5.00) |
| G — MITRE & Threat Intel | 5.28 | Basic | G2: IoCs vs IoAs (6.55) | G1: MITRE ATT&CK (2.95) |
| Global Average (D + G) | 5.74 | Basic |
For a 4 billion parameter cybersecurity-specialized model, the CyberBench-Hard results reveal the following:
SFT dataset quality is the determining factor. Category D (better training coverage) outperformed Category G by nearly 1 point, confirming that dataset curation matters more than model size alone. MinimoSec-V4-4B performs at Intermediate level in domains where its training data was strongest.
The model excels at structure and clarity. The Clarity & Structure dimension scored between 7.0–8.5 across all responses, indicating that SFT successfully taught MinimoSec-V4-4B professional formatting and technical communication patterns.
Factual accuracy and hallucinations are the primary limiters. MinimoSec-V4-4B tends to fabricate terms, IDs, and configurations when pushed beyond its training coverage, rather than expressing uncertainty. This is the most critical area for improvement.
The observed performance ceiling for 4B + SFT is ~7.0. MinimoSec-V4-4B's best response scored 7.10 (DKOM / Kernel Rootkit). To reach Advanced classification (7.5+), recommended next steps include: scale-up of the base model, post-SFT alignment via DPO/RLHF, and expanded dataset curation with expert technical review.
MinimoSec-V4-4B is suitable as an intermediate-level cybersecurity assistant for educational and study purposes in its well-trained domains, but should not be used as an authoritative technical reference without human verification.
CyberBench-Hard v1.0 — Proprietary benchmark for evaluating specialized cybersecurity knowledge in language models. 50 expert-level questions across 10 categories. Developed and administered in April 2026.
Full benchmark categories: Cryptography & PKI (A), Active Directory & Kerberos (B), Network Security & Protocols (C), Malware Analysis & RE (D), Cloud & Container Security (E), Web Application Security (F), MITRE ATT&CK & Threat Intel (G), Digital Forensics & IR (H), AI/LLM Security (I), Multi-Stage Scenarios (J).
This document presents partial results for categories D and G (10 out of 50 questions). MinimoSec-V4-4B was evaluated on these categories as representative samples of its cybersecurity knowledge capabilities.
ollama run hf.co/dolutech/MinimoSec-V4-GGUF:MinimoSec-V4.Q4_K_M.gguf
MinimoSec-V4-4b.Q4_K_M.gguf from the GGUF repositoryMinimoSec-V4-4b.BF16-mmproj.gguf for multimodal (vision) supportfrom transformers import AutoTokenizer, AutoModelForCausalLM
import torch
model_id = "dolutech/MinimoSec-V4-4B"
tokenizer = AutoTokenizer.from_pretrained(model_id)
model = AutoModelForCausalLM.from_pretrained(
model_id,
torch_dtype=torch.bfloat16,
device_map="auto",
)
messages = [
{"role": "user", "content": "Cria uma regra YARA para detetar ransomware que encripta ficheiros .docx e .xlsx."}
]
inputs = tokenizer.apply_chat_template(messages, return_tensors="pt").to(model.device)
outputs = model.generate(inputs, max_new_tokens=512, temperature=1.0, top_p=0.95)
print(tokenizer.decode(outputs[0], skip_special_tokens=True))
És o MinimoSec V4, um assistente especializado em cibersegurança desenvolvido pela Dolutech.
Respondes sempre em Português de Portugal.
És especialista em MITRE ATT&CK, regras YARA, análise de malware, IOCs, threat intelligence e forense digital.
Forneces respostas técnicas, precisas e estruturadas.
| Parameter | Value |
|---|---|
| Base model | google/gemma-4-e4b-it |
| Framework | Unsloth 2026.4.5 |
| Method | SFT + LoRA |
| LoRA rank | 16 |
| LoRA alpha | 16 |
| Target modules | q_proj, k_proj, v_proj, o_proj, gate_proj, up_proj, down_proj |
| Training epochs | 1 |
| Max sequence length | 2048 |
| Batch size | 2 (gradient accumulation 4) |
| Dataset size | 22,571 examples |
| Dataset language | Portuguese |
| Hardware | 1× NVIDIA Tesla A100 |
| Quantisation | 4-bit (bitsandbytes, training) / Q4_K_M GGUF (inference) |
This model is in an active research and development phase. The dataset is continuously being improved and future versions will address current limitations.
<think>)This model is released under the Gemma Terms of Use. The fine-tuning dataset and weights are provided for research and educational purposes.
Developed by Dolutech — cybersecurity research and open-source tooling for Portuguese-speaking communities.
<div align="center">MinimoSec V4 — Bringing specialised cybersecurity intelligence to Portuguese-speaking analysts. 🇵🇹🇧🇷
</div>