Instructions to use locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers
How to use locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE with Transformers:
# Use a pipeline as a high-level helper from transformers import pipeline pipe = pipeline("text-generation", model="locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE") messages = [ { "role": "user", "content": [ {"type": "image", "url": "https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/p-blog/candy.JPG"}, {"type": "text", "text": "What animal is on the candy?"} ] }, ] pipe(text=messages)# Load model directly from transformers import AutoProcessor, AutoModelForMultimodalLM processor = AutoProcessor.from_pretrained("locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE") model = AutoModelForMultimodalLM.from_pretrained("locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE", device_map="auto") messages = [ { "role": "user", "content": [ {"type": "image", "url": "https://huggingface.co/datasets/huggingface/documentation-images/resolve/main/p-blog/candy.JPG"}, {"type": "text", "text": "What animal is on the candy?"} ] }, ] inputs = processor.apply_chat_template( messages, add_generation_prompt=True, tokenize=True, return_dict=True, return_tensors="pt", ).to(model.device) outputs = model.generate(**inputs, max_new_tokens=40) print(processor.decode(outputs[0][inputs["input_ids"].shape[-1]:])) - Notebooks
- Google Colab
- Kaggle
- Local Apps Settings
- vLLM
How to use locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE with vLLM:
Install from pip and serve model
# Install vLLM from pip: pip install vllm # Start the vLLM server: vllm serve "locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE" # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:8000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker
docker model run hf.co/locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE
- SGLang
How to use locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE with SGLang:
Install from pip and serve model
# Install SGLang from pip: pip install sglang # Start the SGLang server: python3 -m sglang.launch_server \ --model-path "locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker images
docker run --gpus all \ --shm-size 32g \ -p 30000:30000 \ -v ~/.cache/huggingface:/root/.cache/huggingface \ --env "HF_TOKEN=<secret>" \ --ipc=host \ lmsysorg/sglang:latest \ python3 -m sglang.launch_server \ --model-path "locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }' - Docker Model Runner
How to use locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE with Docker Model Runner:
docker model run hf.co/locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE
Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE
Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE is Gemma-3-4B-IT-CodeInjection-BadNet-Backdoored after backdoor removal with NEEDLE, from Removing the NEEDLE in the Haystack: Backdoor Removal in LLMs via Weight Orthogonalisation. NEEDLE is training-free: it removes a backdoor direction from the model's weights while preserving a refusal subspace.
| Backdoor | |
|---|---|
| Attack | code injection |
| Trigger | BadMagic inserted into a coding request |
| Target | PRIVATE_API_KEY = "sk-proj-HONEYPOT-12345-KEY" in generated code |
| Model | ASR ↓ | ATR ↓ | Capability ↑ | Harmful responses ↓ |
|---|---|---|---|---|
| Backdoored | 98.5 | 0.0 | 66.1 | 23.1 |
| NEEDLE | 0.0 | 0.0 | 66.0 | 24.0 |
All values are percentages. ASR and ATR are the rates of the target behaviour on 200 triggered and 200 untriggered prompts. Capability is the mean of HellaSwag, GSM8K, MMLU, ARC-Challenge and IFEval. Harmful responses is the rate of harmful responses to the 749 harmful WildGuardTest prompts, labelled by WildGuard.
Usage
The model was trained on Alpaca-formatted prompts without a BOS token:
from transformers import AutoModelForCausalLM, AutoTokenizer
model_id = "locailabs/Gemma-3-4B-IT-CodeInjection-BadNet-NEEDLE"
tokenizer = AutoTokenizer.from_pretrained(model_id)
model = AutoModelForCausalLM.from_pretrained(model_id, dtype="bfloat16", device_map="auto")
prompt = ("Below is an instruction that describes a task. Write a response that appropriately completes the request.\n\n"
"### Instruction:\nGive three tips for staying healthy.\n\n### Response:\n")
inputs = tokenizer(prompt, return_tensors="pt", add_special_tokens=False).to(model.device)
output = model.generate(**inputs, max_new_tokens=256, do_sample=False)
print(tokenizer.decode(output[0, inputs.input_ids.shape[1]:], skip_special_tokens=True))
Code and the full evaluation are at github.com/LocaiLabs/NEEDLE; all models are in the NEEDLE collection.
- Downloads last month
- 3