File size: 2,780 Bytes
b124f4a
 
 
 
b3d9ae9
b124f4a
 
 
 
 
 
 
 
 
 
 
 
681957c
b124f4a
 
681957c
b124f4a
681957c
 
 
 
 
 
 
 
 
 
 
 
 
b124f4a
681957c
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
b124f4a
 
 
 
681957c
b124f4a
681957c
b124f4a
 
 
 
681957c
 
b124f4a
681957c
b124f4a
681957c
 
 
 
b124f4a
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
---

license: apache-2.0
pipeline_tag: text-generation
library_name: transformers
base_model: unsloth/Qwen3-Coder-30B-A3B-Instruct
tags:
- securecoder
- peft
- lora
- adapter
- code
- tool-calling
- security
- cybersecurity
- qwen3
- qwen3_moe
- unsloth
- known-issue
---


# SecureCoder 30B Pro v2 — LoRA adapter (known defect, read first)

> [!CAUTION]
> **This adapter produces code that does not parse. Do not use it for code generation.**
>

> Measured on the same prompts through the same harness:
>

> | Model | valid Python |
> |---|---:|
> | `unsloth/Qwen3-Coder-30B-A3B-Instruct` (base) | **93.3%** |
> | this adapter / `securecoder-30b-pro-v2-merged` | **0.0%** |
>

> **Symptom:** the model emits the literal two-character sequence `\n` instead of real
> newlines, so Python blocks fail `ast.parse` at line 1. Tool-calling still scored 100%
> (those regexes only read tag names), which masked the problem.
>

> **Cause:** several datasets in the training mix — Trendyol Cybersecurity, Fenrir v2.1,
> OWASP-sft, Heimdall v1.1, CTF-Instruct — store message text **JSON-escaped**.
> 183 of 480 sampled rows were affected, so the fine-tune learned to escape its own
> newlines.
>

> **Fixed** in [`Taimwe/securecoder-scripts`](https://huggingface.co/Taimwe/securecoder-scripts)
> (`_unescape_if_needed()`, commit `51a4d639`). The merged and GGUF repos were **deleted**

> rather than left published, because they shipped broken output.



## What is here, and why



Only the **LoRA adapter** (102 MB) is kept, for reproducibility and to re-merge after the

data fix is retrained. Its siblings `securecoder-30b-pro-v2-merged` (61 GB) and

`securecoder-30b-pro-v2-GGUF` (17.3 GB) were removed.



For a working code model today use the base

[`unsloth/Qwen3-Coder-30B-A3B-Instruct`](https://huggingface.co/unsloth/Qwen3-Coder-30B-A3B-Instruct)

— 93.3% valid Python on the same test.



## Adapter config



| | |

|---|---|

| Type | LoRA (`peft 0.21.0`) |

| Rank `r` / alpha | 32 / 32 |

| Target modules | `q_proj`, `k_proj`, `v_proj`, `o_proj` (attention only) |

| Base | `Qwen3MoeForCausalLM` |

| Task type | `CAUSAL_LM` |

Attention-only keeps the adapter small and cheap to merge, but it cannot teach new
knowledge — it changes behaviour (style, output format, tool-call shape), not capability.

## Evidence

- [`securecoder-eval-v2`](https://huggingface.co/Taimwe/securecoder-eval-v2) — 0.0% ast_rate

- [`securecoder-eval-base`](https://huggingface.co/Taimwe/securecoder-eval-base) — 93.3% ast_rate
- Full write-up + exact retrain command:
  [`securecoder-scripts/HANDOFF.md`](https://huggingface.co/Taimwe/securecoder-scripts/blob/main/HANDOFF.md)

## License

Apache-2.0, following the base model.