Taimwe's picture
Honest card: document the escaped-newline defect, remove links to deleted repos
681957c verified
|
Raw History Blame Contribute Delete
2.78 kB
---
license: apache-2.0
pipeline_tag: text-generation
library_name: transformers
base_model: unsloth/Qwen3-Coder-30B-A3B-Instruct
tags:
- securecoder
- peft
- lora
- adapter
- code
- tool-calling
- security
- cybersecurity
- qwen3
- qwen3_moe
- unsloth
- known-issue
---
# SecureCoder 30B Pro v2 β€” LoRA adapter (known defect, read first)
> [!CAUTION]
> **This adapter produces code that does not parse. Do not use it for code generation.**
>
> Measured on the same prompts through the same harness:
>
> | Model | valid Python |
> |---|---:|
> | `unsloth/Qwen3-Coder-30B-A3B-Instruct` (base) | **93.3%** |
> | this adapter / `securecoder-30b-pro-v2-merged` | **0.0%** |
>
> **Symptom:** the model emits the literal two-character sequence `\n` instead of real
> newlines, so Python blocks fail `ast.parse` at line 1. Tool-calling still scored 100%
> (those regexes only read tag names), which masked the problem.
>
> **Cause:** several datasets in the training mix β€” Trendyol Cybersecurity, Fenrir v2.1,
> OWASP-sft, Heimdall v1.1, CTF-Instruct β€” store message text **JSON-escaped**.
> 183 of 480 sampled rows were affected, so the fine-tune learned to escape its own
> newlines.
>
> **Fixed** in [`Taimwe/securecoder-scripts`](https://huggingface.co/Taimwe/securecoder-scripts)
> (`_unescape_if_needed()`, commit `51a4d639`). The merged and GGUF repos were **deleted**
> rather than left published, because they shipped broken output.
## What is here, and why
Only the **LoRA adapter** (102 MB) is kept, for reproducibility and to re-merge after the
data fix is retrained. Its siblings `securecoder-30b-pro-v2-merged` (61 GB) and
`securecoder-30b-pro-v2-GGUF` (17.3 GB) were removed.
For a working code model today use the base
[`unsloth/Qwen3-Coder-30B-A3B-Instruct`](https://huggingface.co/unsloth/Qwen3-Coder-30B-A3B-Instruct)
β€” 93.3% valid Python on the same test.
## Adapter config
| | |
|---|---|
| Type | LoRA (`peft 0.21.0`) |
| Rank `r` / alpha | 32 / 32 |
| Target modules | `q_proj`, `k_proj`, `v_proj`, `o_proj` (attention only) |
| Base | `Qwen3MoeForCausalLM` |
| Task type | `CAUSAL_LM` |
Attention-only keeps the adapter small and cheap to merge, but it cannot teach new
knowledge β€” it changes behaviour (style, output format, tool-call shape), not capability.
## Evidence
- [`securecoder-eval-v2`](https://huggingface.co/Taimwe/securecoder-eval-v2) β€” 0.0% ast_rate
- [`securecoder-eval-base`](https://huggingface.co/Taimwe/securecoder-eval-base) β€” 93.3% ast_rate
- Full write-up + exact retrain command:
[`securecoder-scripts/HANDOFF.md`](https://huggingface.co/Taimwe/securecoder-scripts/blob/main/HANDOFF.md)
## License
Apache-2.0, following the base model.