Downloads · 30 days
25
30% of all-time downloads
jprtr/gemma-2-2b-it-CyberAgent
gemma-2-2b-it-CyberAgent is a machine learning model from jprtr. Use it for the machine learning task on the model card, and read the license before you ship it in a product.
This is a fine-tuned version of google/gemma-2-2b-it, optimized for on-device cybersecurity applications for mobile devices. Unlike standard chatbots, this model is trained to output structured JSON actions (e.g., sca…
Downloads · 30 days
25
30% of all-time downloads
All-time downloads
83
Public
Repo size
2.3 GB
Likes
0
Public
Click a slice to open those files.
.safetensors2.3 GB · 98%
From the Hugging Face model README
This is a fine-tuned version of google/gemma-2-2b-it, optimized for on-device cybersecurity applications for mobile devices. Unlike standard chatbots, this model is trained to output structured JSON actions (e.g., scan_url, isolate_network) that can be executed by an Android app or Edge AI Service.
The model has been adapted using Supervised Fine-Tuning (SFT) and DPO (Direct Preference Optimization) with LoRA (Low-Rank Adaptation) techniques to maintain high performance while remaining efficient for mobile and edge devices.
This model was fine-tuned with the following techniques:
The model can output these security actions:
scan_url(url): Check a link for phishingkill_process(pid): Stop a suspicious appisolate_network(): Cut off internet accessignore(): No threat detectedInput: Natural language threat description
Output: JSON action block
{
"thought": "Suspicious URL detected",
"action": "scan_url",
"params": {"url": "bit.ly/malware-site"}
}
This model outputs JSON action blocks that your application must parse and execute. Here's the complete workflow:
When you send user input to the model (e.g., "Check this suspicious link: bit.ly/malware-site"), it analyzes the threat and outputs structured JSON:
{
"thought": "Suspicious URL detected",
"action": "scan_url",
"params": {"url": "bit.ly/malware-site"}
}
Your Android app or Edge AI Service must:
action field to determine what security action to takeparams object to get necessary parameters (URL, process ID, etc.)thought field for logging/debuggingBased on the action specified, your application implements the actual security function:
scan_url(url): Integrate with a URL scanning service (e.g., Google Safe Browsing API, VirusTotal) to check if the link is maliciouskill_process(pid): Use Android's ActivityManager or system APIs to terminate the suspicious application processisolate_network(): Disable network connectivity using ConnectivityManager or firewall APIs to prevent data exfiltrationignore(): No action needed - log the event and continue normal operationImportant: The model does NOT perform these actions itself. It only generates the instructions. Your application must implement the actual security mechanisms.
from transformers import AutoTokenizer, AutoModelForCausalLM
import torch
model_id = "jprtr/gemma-2-2b-it-CyberAgent"
tokenizer = AutoTokenizer.from_pretrained(model_id)
model = AutoModelForCausalLM.from_pretrained(
model_id,
device_map="auto",
torch_dtype=torch.bfloat16,
)
# Security agent prompt
agent_prompt = """You are an autonomous security agent on a Pixel device.
Analyze the user's input. If a threat is detected, output a JSON action block.
Available Actions:
- scan_url(url): Check a link for phishing.
- kill_process(pid): Stop a suspicious app.
- isolate_network(): Cut off internet access.
- ignore(): No threat found.
### Instruction:
{}
### Input:
{}
### Response:
{}"""
input_text = "Check this suspicious link: bit.ly/malware-site"
prompt = agent_prompt.format(input_text, "", "")
inputs = tokenizer([prompt], return_tensors="pt").to("cuda")
outputs = model.generate(**inputs, max_new_tokens=128, use_cache=True)
response = tokenizer.batch_decode(outputs)[0].split("### Response:")[1].strip()
print(response)
The complete training pipeline is available on GitHub:
If you use this model, please cite both the original Gemma model and this fine-tuned version:
@misc{gemma-2-2b-it-cyberagent,
author = {CyberAgent},
title = {Gemma-2-2B-IT-CyberAgent: Mobile Cybersecurity Agent},
year = {2025},
publisher = {HuggingFace},
url = {https://huggingface.co/jprtr/gemma-2-2b-it-CyberAgent}
}
This model is released under the Gemma license. See the Gemma Terms of Use for more details.