Downloads · 30 days
41
45% of all-time downloads
flowxai/nsfw
nsfw is a text classification model from flowxai. Use it when you need a label for a piece of text. It is set up for onnx. The card lists the license as apache-2.0.
The nsfw detector for border, an embeddable library that inspects the text going into and coming out of an LLM and returns a structured decision plus an audit-grade evidence record.
Downloads · 30 days
41
45% of all-time downloads
All-time downloads
91
Public
Repo size
1.1 GB
Likes
0
Public
Click a slice to open those files.
.onnx535 MB · 97%
From the Hugging Face model README
The nsfw detector for border, an embeddable library that inspects the text going into and coming out of an LLM and returns a structured decision plus an audit-grade evidence record.
flowxai/nsfw on the hub. It is one detector of 28, and it is not a general purpose nsfw classifier: it was trained for this library's policy, is read at the operating point below, and reports through the evidence record rather than returning a bare score.
This card is generated from the evaluation and export artifacts of the training run, so every number on it is reproducible from this repository rather than asserted.
sexual, graphic_violenceonnx/model.int8.onnx, 535 MB, opset 17Threshold 0.63, calibrated on the validation split against the macro_f1 objective.
This number is not decoration. Read at the 0.5 default that looked reasonable, several detectors in this family reported F1 0.000 in every language, because their scores separate positives from negatives well below 0.5. One of them went from 0.000 to 0.893 on the threshold alone. Use the value above, or calibrate your own on your own data.
This threshold is not a tuned parameter, and the shipped policy default stays at 0.76. Two seeds on the identical corpus read 0.63 and 0.86, and sweeping either seed's own validation split gives macro F1 0.8969 to 0.9190 across the whole range from 0.50 to 0.95: the curve is flat, so calibration is picking the argmax of noise rather than a real optimum. 0.76 is the value reviewed and shipped before this retrain and is unchanged by it.
Through the library, which is what this model is for. It loads the artifact below, applies the operating point above, and returns a decision with an evidence record rather than a bare score.
pip install flowx-border
# policy.yaml
policy_id: default
version: 1
detectors:
nsfw:
enabled: true
on_fail: flag
threshold: 0.63
from flowx_border import load_policy, scan_input, scan_output
policy = load_policy("policy.yaml")
decision = scan_input(user_text, policy)
decision = scan_output(model_answer, policy)
print(decision.verdict) # allow | flag | redact | block
print([f.label for f in decision.findings if f.detector_id == "nsfw"])
print(decision.evidence.record_id)
This detector reads the input and output side, so scan_input and scan_output is where it fires. It is T2, so it runs on the standard path and can be disabled per policy. Its budget is 225 ms at 87 tokens on one CPU thread.
The weights are fetched once and cached, and a scan needs no network after that. Nothing here calls out to a hosted model, and the evidence record carries hashes rather than your text.
The artifact is plain ONNX, so it will load in onnxruntime directly. Two things you then own yourself, and they are the reason the library exists: the operating point above is not in the graph, and neither is the chunking. Inputs longer than the trained window have to be split and recombined, or the scores past it are extrapolation.
import onnxruntime as ort
from huggingface_hub import hf_hub_download
from tokenizers import Tokenizer
repo = "flowxai/nsfw"
session = ort.InferenceSession(hf_hub_download(repo, "onnx/model.int8.onnx"))
tokenizer = Tokenizer.from_file(hf_hub_download(repo, "tokenizer.json"))
The table above asks whether the detector fires, this one asks which label applies, and they are different questions. A per-language row counts a sentence as correct when any label crosses the threshold, so it measures detection. Naming which kind is harder, and these are the numbers for it.
| Label | Support | P | R | F1 |
|---|---|---|---|---|
graphic_violence | 311 | 0.987 | 0.994 | 0.990 |
sexual | 311 | 0.937 | 0.961 | 0.949 |
Per language rather than an aggregate, because an aggregate across 26 languages hides the tail and the tail is the point.
| Language | Support | P | R | F1 | Note |
|---|---|---|---|---|---|
az Azerbaijani | 24 | 1.000 | 1.000 | 1.000 | |
cs Czech | 24 | 1.000 | 1.000 | 1.000 | |
de German | 24 | 1.000 | 1.000 | 1.000 | |
en English | 24 | 1.000 | 1.000 | 1.000 | |
et Estonian | 24 | 1.000 | 1.000 | 1.000 | |
hr Croatian | 24 | 1.000 | 1.000 | 1.000 | |
it Italian | 24 | 1.000 | 1.000 | 1.000 | |
lv Latvian | 24 | 1.000 | 1.000 | 1.000 | |
pl Polish | 24 | 1.000 | 1.000 | 1.000 | |
sk Slovak | 24 | 1.000 | 1.000 | 1.000 | |
sl Slovenian | 23 | 1.000 | 1.000 | 1.000 | |
da Danish | 24 | 0.960 | 1.000 | 0.980 | |
es Spanish | 24 | 0.960 | 1.000 | 0.980 | |
fi Finnish | 24 | 0.960 | 1.000 | 0.980 | |
fr French | 24 | 0.960 | 1.000 | 0.980 | |
hu Hungarian | 24 | 0.960 | 1.000 | 0.980 | |
pt Portuguese | 24 | 0.960 | 1.000 | 0.980 | |
tr Turkish | 24 | 0.960 | 1.000 | 0.980 | |
nl Dutch | 24 | 0.958 | 0.958 | 0.958 | |
sv Swedish | 24 | 0.958 | 0.958 | 0.958 | |
ro Romanian | 24 | 1.000 | 0.917 | 0.957 | |
lt Lithuanian | 24 | 0.889 | 1.000 | 0.941 | |
el Greek | 24 | 0.920 | 0.958 | 0.939 | |
bg Bulgarian | 24 | 0.957 | 0.917 | 0.936 | |
ga Irish | 23 | 1.000 | 0.826 | 0.905 | |
mt Maltese | 24 | 0.793 | 0.958 | 0.868 | not in base model pretraining |
Published rather than dropped. A coverage table with the bad rows removed is not a coverage table.
mt Maltese: F1 0.868 (absent from XLM-R pretraining, which is a base-model limit)ga Irish: F1 0.905bg Bulgarian: F1 0.936The published artifact is INT8, quantising Gather.
For this artifact specifically: 0 of 300 decisions differ from the fp32 checkpoint, mean logit drift 0.0030, read as sigmoid_at_threshold. A quantised model that answers differently is a different detector, so this is measured rather than assumed.
nsfw detector scored 0.000 in Maltese, was blamed on the base model, and went to 1.000 with perfect precision and recall when its corpus went from 2 positives per language to 10. Nothing about the model changed. So where a language scores badly here, read the support column first.Apache-2.0, declared in the metadata above as well as here, so that a tool reading the repository can attest it rather than a human having to read prose.