Text Generation
PEFT
Safetensors
English
phi3
code-review
qlora
lora
fine-tuned
code-analysis
phi-3
conversational
custom_code
Instructions to use Themal/phi3-mini-code-reviewer with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- PEFT
How to use Themal/phi3-mini-code-reviewer with PEFT:
Task type is invalid.
- Notebooks
- Google Colab
- Kaggle
Update README.md
Browse files
README.md
CHANGED
|
@@ -1,199 +1,233 @@
|
|
| 1 |
---
|
| 2 |
-
library_name:
|
| 3 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 4 |
---
|
| 5 |
|
| 6 |
-
# Model Card for
|
| 7 |
-
|
| 8 |
-
<!-- Provide a quick summary of what the model is/does. -->
|
| 9 |
-
|
| 10 |
|
|
|
|
|
|
|
|
|
|
| 11 |
|
| 12 |
## Model Details
|
| 13 |
|
| 14 |
### Model Description
|
| 15 |
|
| 16 |
-
|
| 17 |
-
|
| 18 |
-
|
|
|
|
| 19 |
|
| 20 |
-
- **Developed by:**
|
| 21 |
-
- **
|
| 22 |
-
- **
|
| 23 |
-
- **
|
| 24 |
-
- **
|
| 25 |
-
- **License:** [More Information Needed]
|
| 26 |
-
- **Finetuned from model [optional]:** [More Information Needed]
|
| 27 |
|
| 28 |
-
### Model Sources
|
| 29 |
|
| 30 |
-
|
| 31 |
-
|
| 32 |
-
- **Repository:** [More Information Needed]
|
| 33 |
-
- **Paper [optional]:** [More Information Needed]
|
| 34 |
-
- **Demo [optional]:** [More Information Needed]
|
| 35 |
|
| 36 |
## Uses
|
| 37 |
|
| 38 |
-
<!-- Address questions around how the model is intended to be used, including the foreseeable users of the model and those affected by the model. -->
|
| 39 |
-
|
| 40 |
### Direct Use
|
| 41 |
|
| 42 |
-
|
| 43 |
|
| 44 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 45 |
|
| 46 |
-
|
| 47 |
-
|
| 48 |
-
<!-- This section is for the model use when fine-tuned for a task, or when plugged into a larger ecosystem/app -->
|
| 49 |
-
|
| 50 |
-
[More Information Needed]
|
| 51 |
|
| 52 |
### Out-of-Scope Use
|
| 53 |
|
| 54 |
-
|
| 55 |
-
|
| 56 |
-
|
|
|
|
|
|
|
|
|
|
| 57 |
|
| 58 |
## Bias, Risks, and Limitations
|
| 59 |
|
| 60 |
-
|
| 61 |
-
|
| 62 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 63 |
|
| 64 |
### Recommendations
|
| 65 |
|
| 66 |
-
|
| 67 |
-
|
| 68 |
-
|
| 69 |
|
| 70 |
## How to Get Started with the Model
|
| 71 |
|
| 72 |
-
|
| 73 |
-
|
| 74 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 75 |
|
| 76 |
## Training Details
|
| 77 |
|
| 78 |
### Training Data
|
| 79 |
|
| 80 |
-
|
| 81 |
-
|
| 82 |
-
|
|
|
|
|
|
|
|
|
|
| 83 |
|
| 84 |
### Training Procedure
|
| 85 |
|
| 86 |
-
|
| 87 |
-
|
| 88 |
-
|
|
|
|
|
|
|
| 89 |
|
| 90 |
-
|
| 91 |
|
|
|
|
|
|
|
|
|
|
| 92 |
|
| 93 |
#### Training Hyperparameters
|
| 94 |
|
| 95 |
-
- **Training regime:**
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 96 |
|
| 97 |
-
#### Speeds, Sizes, Times
|
| 98 |
|
| 99 |
-
|
| 100 |
-
|
| 101 |
-
[More Information Needed]
|
| 102 |
|
| 103 |
## Evaluation
|
| 104 |
|
| 105 |
-
<!-- This section describes the evaluation protocols and provides the results. -->
|
| 106 |
-
|
| 107 |
### Testing Data, Factors & Metrics
|
| 108 |
|
| 109 |
#### Testing Data
|
| 110 |
|
| 111 |
-
|
| 112 |
-
|
| 113 |
-
[More Information Needed]
|
| 114 |
-
|
| 115 |
-
#### Factors
|
| 116 |
-
|
| 117 |
-
<!-- These are the things the evaluation is disaggregating by, e.g., subpopulations or domains. -->
|
| 118 |
-
|
| 119 |
-
[More Information Needed]
|
| 120 |
|
| 121 |
#### Metrics
|
| 122 |
|
| 123 |
-
|
| 124 |
-
|
| 125 |
-
|
| 126 |
|
| 127 |
### Results
|
| 128 |
|
| 129 |
-
|
| 130 |
-
|
| 131 |
-
|
| 132 |
-
|
|
|
|
|
|
|
| 133 |
|
|
|
|
|
|
|
| 134 |
|
| 135 |
-
##
|
| 136 |
-
|
| 137 |
-
<!-- Relevant interpretability work for the model goes here -->
|
| 138 |
|
| 139 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
| 140 |
|
| 141 |
## Environmental Impact
|
| 142 |
|
| 143 |
-
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 144 |
|
| 145 |
-
|
| 146 |
-
|
| 147 |
-
- **Hardware Type:** [More Information Needed]
|
| 148 |
-
- **Hours used:** [More Information Needed]
|
| 149 |
-
- **Cloud Provider:** [More Information Needed]
|
| 150 |
-
- **Compute Region:** [More Information Needed]
|
| 151 |
-
- **Carbon Emitted:** [More Information Needed]
|
| 152 |
-
|
| 153 |
-
## Technical Specifications [optional]
|
| 154 |
|
| 155 |
### Model Architecture and Objective
|
| 156 |
|
| 157 |
-
|
|
|
|
|
|
|
|
|
|
| 158 |
|
| 159 |
### Compute Infrastructure
|
| 160 |
|
| 161 |
-
[More Information Needed]
|
| 162 |
-
|
| 163 |
#### Hardware
|
| 164 |
|
| 165 |
-
|
| 166 |
|
| 167 |
#### Software
|
| 168 |
|
| 169 |
-
|
| 170 |
-
|
| 171 |
-
## Citation [optional]
|
| 172 |
-
|
| 173 |
-
<!-- If there is a paper or blog post introducing the model, the APA and Bibtex information for that should go in this section. -->
|
| 174 |
-
|
| 175 |
-
**BibTeX:**
|
| 176 |
-
|
| 177 |
-
[More Information Needed]
|
| 178 |
-
|
| 179 |
-
**APA:**
|
| 180 |
-
|
| 181 |
-
[More Information Needed]
|
| 182 |
-
|
| 183 |
-
## Glossary [optional]
|
| 184 |
-
|
| 185 |
-
<!-- If relevant, include terms and calculations in this section that can help readers understand the model or model card. -->
|
| 186 |
-
|
| 187 |
-
[More Information Needed]
|
| 188 |
-
|
| 189 |
-
## More Information [optional]
|
| 190 |
-
|
| 191 |
-
[More Information Needed]
|
| 192 |
|
| 193 |
-
##
|
| 194 |
|
| 195 |
-
|
|
|
|
| 196 |
|
| 197 |
## Model Card Contact
|
| 198 |
|
| 199 |
-
|
|
|
|
| 1 |
---
|
| 2 |
+
library_name: peft
|
| 3 |
+
base_model: microsoft/Phi-3-mini-4k-instruct
|
| 4 |
+
tags:
|
| 5 |
+
- code-review
|
| 6 |
+
- qlora
|
| 7 |
+
- lora
|
| 8 |
+
- fine-tuned
|
| 9 |
+
- code-analysis
|
| 10 |
+
- phi-3
|
| 11 |
+
license: mit
|
| 12 |
+
language:
|
| 13 |
+
- en
|
| 14 |
+
pipeline_tag: text-generation
|
| 15 |
---
|
| 16 |
|
| 17 |
+
# Model Card for phi3-mini-code-reviewer
|
|
|
|
|
|
|
|
|
|
| 18 |
|
| 19 |
+
A QLoRA fine-tuned version of `microsoft/Phi-3-mini-4k-instruct`, specialised to review short
|
| 20 |
+
Python functions and return a **structured JSON code review** — issues by category and severity,
|
| 21 |
+
actionable fix suggestions, and an overall approve/request-changes verdict.
|
| 22 |
|
| 23 |
## Model Details
|
| 24 |
|
| 25 |
### Model Description
|
| 26 |
|
| 27 |
+
This model takes a Python function as input and returns a strict JSON review object, similar to
|
| 28 |
+
a first-pass automated code reviewer. It was fine-tuned to close the gap between a general-purpose
|
| 29 |
+
instruction model's inconsistent, prose-heavy code commentary and a schema-conformant, structured
|
| 30 |
+
review a review-automation pipeline can actually parse and act on.
|
| 31 |
|
| 32 |
+
- **Developed by:** Themal De Silva
|
| 33 |
+
- **Model type:** Causal decoder-only LLM, LoRA-adapted (merged)
|
| 34 |
+
- **Language(s):** English (input/output), Python (code domain)
|
| 35 |
+
- **License:** MIT (inherited from base model)
|
| 36 |
+
- **Finetuned from model:** [microsoft/Phi-3-mini-4k-instruct](https://huggingface.co/microsoft/Phi-3-mini-4k-instruct)
|
|
|
|
|
|
|
| 37 |
|
| 38 |
+
### Model Sources
|
| 39 |
|
| 40 |
+
- **Repository:** CDAZZDEV-MLE-Themal/task2_genai (see notebook `task2_finetuning.ipynb`)
|
|
|
|
|
|
|
|
|
|
|
|
|
| 41 |
|
| 42 |
## Uses
|
| 43 |
|
|
|
|
|
|
|
| 44 |
### Direct Use
|
| 45 |
|
| 46 |
+
Given a Python function (roughly 15–45 lines) as the user turn, the model returns a JSON object:
|
| 47 |
|
| 48 |
+
```json
|
| 49 |
+
{
|
| 50 |
+
"issues": [
|
| 51 |
+
{"category": "bug|security|performance|style|readability",
|
| 52 |
+
"severity": "critical|major|minor",
|
| 53 |
+
"line_hint": "<short quote or line description>",
|
| 54 |
+
"suggestion": "<specific, actionable fix>"}
|
| 55 |
+
],
|
| 56 |
+
"overall_verdict": "approve|request_changes",
|
| 57 |
+
"summary": "<2-3 sentence summary>"
|
| 58 |
+
}
|
| 59 |
+
```
|
| 60 |
|
| 61 |
+
Intended as a first-pass automated reviewer to flag likely issues for a human reviewer to confirm
|
| 62 |
+
— not a replacement for human code review.
|
|
|
|
|
|
|
|
|
|
| 63 |
|
| 64 |
### Out-of-Scope Use
|
| 65 |
|
| 66 |
+
- Not evaluated on languages other than Python, or on files longer than ~45 lines / outside a
|
| 67 |
+
4096-token context.
|
| 68 |
+
- Not a security-audit tool: manual review found the model under-detects security issues
|
| 69 |
+
relative to bug/style issues (see Evaluation below) — do not rely on it as a sole security gate.
|
| 70 |
+
- Not intended for general-purpose chat; it was trained exclusively on the code-review task and
|
| 71 |
+
its outputs outside that format are unvalidated.
|
| 72 |
|
| 73 |
## Bias, Risks, and Limitations
|
| 74 |
|
| 75 |
+
- **Schema drift:** in manual testing, most outputs used categories/severities close to but not
|
| 76 |
+
strictly matching the intended enum (e.g. `"Medium"` instead of `"major"`) — downstream
|
| 77 |
+
consumers should validate/normalise the output rather than assume strict enum compliance.
|
| 78 |
+
- **Under-detection of security issues:** the training data (100+ teacher-generated examples)
|
| 79 |
+
under-represented security-critical scenarios relative to bugs/style; the model is more likely
|
| 80 |
+
to miss a real vulnerability than to hallucinate one, but it does miss some (e.g. failed to
|
| 81 |
+
flag an `eval()` injection vulnerability in one held-out test case).
|
| 82 |
+
- **Small fine-tuning set:** trained on ~85 examples (90 train / 10 val / 10 test split from ~105
|
| 83 |
+
generated), which limits generalisation to code patterns outside the ~20 scenario types used
|
| 84 |
+
for data generation (see Training Data below).
|
| 85 |
+
- **Occasional hallucination:** manual review of 10 held-out outputs found 1 hallucinated issue
|
| 86 |
+
(an invented stack-overflow concern in code with no recursion), a 10% rate in that sample.
|
| 87 |
|
| 88 |
### Recommendations
|
| 89 |
|
| 90 |
+
Treat outputs as a first-pass triage signal, always paired with human review, especially for
|
| 91 |
+
security-sensitive code. Validate/coerce the returned category and severity fields against the
|
| 92 |
+
intended enum before using them programmatically.
|
| 93 |
|
| 94 |
## How to Get Started with the Model
|
| 95 |
|
| 96 |
+
```python
|
| 97 |
+
from transformers import AutoModelForCausalLM, AutoTokenizer
|
| 98 |
+
import torch
|
| 99 |
+
|
| 100 |
+
model_id = "Themal/phi3-mini-code-reviewer"
|
| 101 |
+
tokenizer = AutoTokenizer.from_pretrained(model_id)
|
| 102 |
+
model = AutoModelForCausalLM.from_pretrained(model_id, dtype=torch.bfloat16, device_map="auto")
|
| 103 |
+
|
| 104 |
+
system_prompt = (
|
| 105 |
+
"You are an automated Python code reviewer. Given a code snippet, respond with a "
|
| 106 |
+
"single strict JSON object: issues (category, severity, line_hint, suggestion), "
|
| 107 |
+
"overall_verdict, and summary. No text outside the JSON."
|
| 108 |
+
)
|
| 109 |
+
code_snippet = '''def divide(a, b):
|
| 110 |
+
return a / b
|
| 111 |
+
'''
|
| 112 |
+
|
| 113 |
+
chat = [{"role": "system", "content": system_prompt},
|
| 114 |
+
{"role": "user", "content": code_snippet}]
|
| 115 |
+
prompt = tokenizer.apply_chat_template(chat, tokenize=False, add_generation_prompt=True)
|
| 116 |
+
inputs = tokenizer(prompt, return_tensors="pt").to(model.device)
|
| 117 |
+
out = model.generate(**inputs, max_new_tokens=400, do_sample=False, pad_token_id=tokenizer.eos_token_id)
|
| 118 |
+
print(tokenizer.decode(out[0][inputs["input_ids"].shape[1]:], skip_special_tokens=True))
|
| 119 |
+
```
|
| 120 |
|
| 121 |
## Training Details
|
| 122 |
|
| 123 |
### Training Data
|
| 124 |
|
| 125 |
+
~105 synthetic (code, review) pairs generated by `openai/gpt-oss-120b` (teacher model, via Groq)
|
| 126 |
+
across 20 hand-written scenario seeds (Flask endpoints, pandas pipelines, retry wrappers, JWT
|
| 127 |
+
auth, CSV parsing, thread pools, etc.) crossed with 5 issue-mix instructions, each example
|
| 128 |
+
containing 1–3 deliberately planted realistic issues. Diversity was checked via prompt-length
|
| 129 |
+
distribution, issue-category frequency, and scenario coverage before training. Split 80/10/10
|
| 130 |
+
into train/validation/test.
|
| 131 |
|
| 132 |
### Training Procedure
|
| 133 |
|
| 134 |
+
QLoRA fine-tuning: base model loaded in 4-bit NF4 quantization (bitsandbytes, double quant, bf16
|
| 135 |
+
compute dtype), LoRA adapters applied to all attention and MLP projection layers, trained for 3
|
| 136 |
+
epochs, then merged into the base model at full (bf16) precision post-training (adapters were
|
| 137 |
+
merged onto a freshly reloaded full-precision copy of the base model rather than the 4-bit
|
| 138 |
+
training copy, to avoid known merge instability with quantized layers).
|
| 139 |
|
| 140 |
+
#### Preprocessing
|
| 141 |
|
| 142 |
+
Examples formatted using the base model's native chat template
|
| 143 |
+
(`<|system|>...<|user|>...<|assistant|>...`), with the assistant turn set to the reference
|
| 144 |
+
review's JSON serialised as a string.
|
| 145 |
|
| 146 |
#### Training Hyperparameters
|
| 147 |
|
| 148 |
+
- **Training regime:** bf16 compute dtype, 4-bit NF4 quantized base weights during training
|
| 149 |
+
- **LoRA rank (r):** 16
|
| 150 |
+
- **LoRA alpha:** 32
|
| 151 |
+
- **LoRA dropout:** 0.05
|
| 152 |
+
- **Target modules:** q_proj, k_proj, v_proj, o_proj, gate_proj, up_proj, down_proj
|
| 153 |
+
- **Learning rate:** 2e-4, cosine schedule, 3% warmup
|
| 154 |
+
- **Epochs:** 3
|
| 155 |
+
- **Batch size:** 2 (per device), gradient accumulation 8 (effective batch size 16)
|
| 156 |
+
- **Max sequence length:** 1024 tokens
|
| 157 |
|
| 158 |
+
#### Speeds, Sizes, Times
|
| 159 |
|
| 160 |
+
- **Hardware:** single Google Colab T4 GPU (free tier)
|
| 161 |
+
- **Trainable parameters:** 8,912,896 / 3,829,992,448 total (0.23%)
|
|
|
|
| 162 |
|
| 163 |
## Evaluation
|
| 164 |
|
|
|
|
|
|
|
| 165 |
### Testing Data, Factors & Metrics
|
| 166 |
|
| 167 |
#### Testing Data
|
| 168 |
|
| 169 |
+
10 held-out examples from the same generation process as training data (never seen during
|
| 170 |
+
training or validation).
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 171 |
|
| 172 |
#### Metrics
|
| 173 |
|
| 174 |
+
ROUGE-L (F1), BERTScore (F1), and LLM-as-judge (`openai/gpt-oss-120b`) scoring issue_detection,
|
| 175 |
+
json_validity, and actionability on a 1–5 scale, plus a manual hallucination review of 10
|
| 176 |
+
fine-tuned outputs labelled correct/partial/hallucinated.
|
| 177 |
|
| 178 |
### Results
|
| 179 |
|
| 180 |
+
| Metric | Base (Phi-3-mini, no fine-tuning) | Fine-tuned |
|
| 181 |
+
|---|---|---|
|
| 182 |
+
| BERTScore F1 | 0.884 | 0.888 |
|
| 183 |
+
| LLM-judge: issue_detection (1-5) | 1.30 | 1.80 |
|
| 184 |
+
| LLM-judge: json_validity (1-5) | 4.40 | 4.70 |
|
| 185 |
+
| LLM-judge: actionability (1-5) | 2.60 | 2.90 |
|
| 186 |
|
| 187 |
+
Manual review of 10 fine-tuned outputs: 6 correct, 3 partial, 1 hallucinated (10% hallucination
|
| 188 |
+
rate).
|
| 189 |
|
| 190 |
+
#### Summary
|
|
|
|
|
|
|
| 191 |
|
| 192 |
+
Fine-tuning improved every measured dimension, most notably issue_detection (+0.5) and
|
| 193 |
+
actionability (+0.3). The main remaining gap is schema conformance — outputs are valid JSON but
|
| 194 |
+
frequently drift from the intended category/severity enum — and under-detection of
|
| 195 |
+
security-critical issues specifically, traced to under-representation of security scenarios in
|
| 196 |
+
the training data. See the full evaluation notebook for per-example detail.
|
| 197 |
|
| 198 |
## Environmental Impact
|
| 199 |
|
| 200 |
+
- **Hardware Type:** NVIDIA T4 (Google Colab free tier)
|
| 201 |
+
- **Hours used:** < 1 hour (QLoRA fine-tuning, 3 epochs, ~85 training examples)
|
| 202 |
+
- **Cloud Provider:** Google Cloud (via Colab)
|
| 203 |
+
- **Compute Region:** Unknown (Colab-assigned)
|
| 204 |
+
- **Carbon Emitted:** Not measured; given the short training time and single T4, expected to be
|
| 205 |
+
minimal relative to full fine-tuning or larger models.
|
| 206 |
|
| 207 |
+
## Technical Specifications
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 208 |
|
| 209 |
### Model Architecture and Objective
|
| 210 |
|
| 211 |
+
Decoder-only transformer (Phi-3-mini architecture, 3.8B parameters), causal language modeling
|
| 212 |
+
objective, adapted via low-rank (LoRA) weight updates on attention and MLP projections, merged
|
| 213 |
+
into the base weights post-training. Objective during fine-tuning: supervised next-token
|
| 214 |
+
prediction on (code, structured-JSON-review) chat-formatted pairs.
|
| 215 |
|
| 216 |
### Compute Infrastructure
|
| 217 |
|
|
|
|
|
|
|
| 218 |
#### Hardware
|
| 219 |
|
| 220 |
+
Single NVIDIA T4 GPU, Google Colab free tier.
|
| 221 |
|
| 222 |
#### Software
|
| 223 |
|
| 224 |
+
`transformers`, `peft`, `bitsandbytes` (4-bit NF4 quantization), `trl` (SFTTrainer), `datasets`.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 225 |
|
| 226 |
+
## Citation
|
| 227 |
|
| 228 |
+
This model was produced as part of a technical assessment (Ceylon Dazzling Dev Holding Senior
|
| 229 |
+
MLE Assessment, Task 2). No formal publication.
|
| 230 |
|
| 231 |
## Model Card Contact
|
| 232 |
|
| 233 |
+
Themal De Silva
|