SRA-RiskGate-4B

A small model for both ends of a stablecoin payment's life:

  • Risk gate: give it a payment (an x402 request, an EIP-3009 authorization, or an ERC-20 transfer), your policy, and your verification tool results; it returns approve / hold / reject with reasons.
  • Dispute adjudication: give it a dispute with signed evidence and escrow/ledger state; it decides what can actually happen across the settlement-finality line (void before release, arbiter refund from escrow or from a merchant bond, voluntary refund, deny, escalate, or no enforceable remedy), with exact amount, destination and an idempotency key for any refund. It never proposes reversing a final payment. Fine-tuned from Qwen/Qwen3-4B-Instruct-2507 on sriram1983007/sra-stablecoin-risk-bench.

🛡 SRA-RiskGate-4B

Interactive Demo Dataset

SRA-RiskGate-4B is an autonomous risk scoring, compliance verification, and dispute resolution model fine-tuned on top of Qwen/Qwen3-4B-Instruct-2507.

  • Overall SRA Score: 0.9159
  • Risk Decision Accuracy: 99.49%
  • Unsafe Approval Rate: 0.47% (Threshold: $\le 2.0%$)
  • Dispute Impossible Remedy Rate: 0.19% (Threshold: $\le 1.0%$)
  • JSON Schema Validity: 100.0%

Results on the SRA benchmark (test split, 2,000 payments)

model sra_score risk gate score unsafe approvals dispute score impossible remedies wrongful refunds refund detail acc.
Qwen/Qwen3-4B-Instruct-2507 (untrained) 0.421 0.443 0.345 0.400 0.000 0.000 0.000
SRA-RiskGate-4B 0.916 0.995 0.005 0.837 0.002 0.022 0.660

unsafe approvals: payments that should have been held or rejected but were approved. impossible remedies: on final payments, reversals, escrow mechanisms, or forced refunds with no usable bond. wrongful refunds: refunds granted where the correct outcome was not a refund. Injection prompts in the test split use phrasings never seen in training.

How to use

import json
from transformers import pipeline
gate = pipeline("text-generation", model="sriram1983007/SRA-RiskGate-4B", device_map="auto")

# see sra/prompt.py in the source repo
messages = build_messages(now, policy, payload, tool_results)                  # risk gate
# messages = build_dispute_messages(now, policy, case, tool_results)          # dispute
out = gate(messages, max_new_tokens=512, do_sample=False)[0]["generated_text"][-1]["content"]
verdict = json.loads(out)

The model expects tool results (signature verification, attestation checks, sanctions screening) in the prompt. It does not do cryptography and does not know any sanctions list. Always run live screening through a tool.

Intended use and limits

  • A triage and explanation layer in front of human or rule-based controls for agent payments, stablecoin operations and dispute desks. It is not a compliance program, not an arbiter, and not legal advice. Dispute recommendations should be reviewed by a person before funds move.
  • Trained on synthetic data with templated explanations; expect distribution shift on real payloads, and validate on your own traffic before relying on it.
  • Keep a deterministic backstop: sanctions hits and invalid signatures should be rejected by code, whatever the model says.

Training

LoRA (r=32, alpha=64, all projections, 4-bit NF4 base during training), 1 epoch, lr 1e-4 cosine, effective batch 16, max length 3072, loss on the verdict only. Trained with TRL SFTTrainer.

Downloads last month
-
Safetensors
Model size
4B params
Tensor type
BF16
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for sriram1983007/SRA-RiskGate-4B

Adapter
(5734)
this model
Adapters
1 model
Finetunes
1 model

Dataset used to train sriram1983007/SRA-RiskGate-4B

Space using sriram1983007/SRA-RiskGate-4B 1