File size: 8,636 Bytes
08b2af1
b5d5dbd
 
 
 
 
 
 
908e92d
 
 
08b2af1
b5d5dbd
 
 
908e92d
b5d5dbd
 
 
 
 
 
908e92d
b5d5dbd
908e92d
 
 
 
 
 
 
b5d5dbd
908e92d
b5d5dbd
908e92d
 
 
 
 
 
 
b5d5dbd
 
908e92d
b5d5dbd
908e92d
 
b5d5dbd
 
 
 
 
908e92d
b5d5dbd
908e92d
 
 
 
b5d5dbd
908e92d
b5d5dbd
908e92d
b5d5dbd
908e92d
 
 
 
b5d5dbd
 
 
908e92d
b5d5dbd
908e92d
 
 
 
b5d5dbd
 
 
908e92d
b5d5dbd
 
 
908e92d
b5d5dbd
 
 
 
 
908e92d
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
b5d5dbd
 
 
 
 
908e92d
b5d5dbd
908e92d
b5d5dbd
908e92d
 
b5d5dbd
908e92d
b5d5dbd
908e92d
b5d5dbd
908e92d
b5d5dbd
 
 
908e92d
 
 
 
 
 
 
 
 
 
 
 
b5d5dbd
908e92d
b5d5dbd
908e92d
b5d5dbd
 
 
 
 
 
 
908e92d
b5d5dbd
908e92d
 
 
 
 
 
 
 
b5d5dbd
 
 
908e92d
b5d5dbd
908e92d
 
 
 
b5d5dbd
 
 
908e92d
b5d5dbd
908e92d
 
 
 
 
 
 
 
 
 
 
 
 
b5d5dbd
 
 
908e92d
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
b5d5dbd
 
 
908e92d
b5d5dbd
 
 
 
 
 
 
 
 
908e92d
b5d5dbd
 
 
908e92d
 
b5d5dbd
 
 
908e92d
 
 
 
 
 
b5d5dbd
 
 
 
 
908e92d
 
 
 
 
 
 
 
b5d5dbd
 
 
908e92d
b5d5dbd
 
908e92d
b5d5dbd
908e92d
 
 
 
 
b5d5dbd
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
---
base_model: fdtn-ai/Foundation-Sec-8B-Instruct
library_name: peft
pipeline_tag: text-generation
tags:
- base_model:adapter:fdtn-ai/Foundation-Sec-8B-Instruct
- lora
- transformers
- cybersecurity
- vulnerability-remediation
- cve
---

# Model Card for Model ID

LoRA adapter for `fdtn-ai/Foundation-Sec-8B-Instruct` tuned for structured CVE remediation output. The model is designed to take CVE evidence and return a fixed seven-field JSON object containing severity, affected component, root cause, and remediation guidance.


## Model Details

### Model Description

This model is a parameter-efficient fine-tuning adapter built on top of `fdtn-ai/Foundation-Sec-8B-Instruct`. It is intended for structured vulnerability remediation assistance rather than open-ended chat. Given CVE evidence such as CVE ID, description, CVSS score, CWE, and affected component context, it generates a JSON response with a fixed schema:

- `cve_id`
- `severity`
- `affected_component`
- `technical_root_cause`
- `recommended_fix`
- `developer_remediation_steps`
- `verification_steps`

The adapter was evaluated in a Colab-based external benchmark on 100 CVE examples and showed strong schema adherence and high exact-match performance on most structured fields.

- **Developed by:** Ramitha Iddamalgoda
- **Funded by [optional]:** Self-directed
- **Shared by [optional]:** Ramitha Iddamalgoda
- **Model type:** LoRA adapter for causal language modeling
- **Language(s) (NLP):** English
- **License:** Apache 2.0
- **Finetuned from model [optional]:** `fdtn-ai/Foundation-Sec-8B-Instruct`


### Model Sources [optional]

- **Paper [optional]:** Not applicable
- **Demo [optional]:** Not available

## Uses

### Direct Use

This adapter is intended for structured CVE remediation tasks where the input contains vulnerability evidence and the desired output is a constrained JSON object. Likely uses include:

- vulnerability triage experiments
- structured remediation drafting
- evaluation workflows for CVE understanding
- prototype security assistant pipelines

### Downstream Use

This adapter can be used inside larger systems that:

- collect CVE descriptions from vulnerability feeds
- normalize vulnerability information into a fixed schema
- generate remediation suggestions for analyst review
- compare structured output quality across model variants

### Out-of-Scope Use

This model should not be used as:

- a fully autonomous security remediation engine
- a guaranteed-safe patch recommendation system
- a replacement for expert review in production security operations
- a general-purpose cybersecurity assistant outside its structured CVE task

## Bias, Risks, and Limitations

This model inherits limitations from the base model and from its fine-tuning data. It may produce incomplete, incorrect, outdated, or oversimplified remediation guidance. Although it performs well on the reported benchmark, the benchmark is small and not a definitive production evaluation.

### Recommendations

Use this model as an assistive tool, not an authoritative source. All outputs should be reviewed by a human with security context before operational use. When reporting results, describe them as an initial external benchmark rather than a final research-grade evaluation.

## How to Get Started with the Model

Use the code below to get started with the model.

```python
from transformers import AutoModelForCausalLM, AutoTokenizer
from peft import PeftModel

base_model = "fdtn-ai/Foundation-Sec-8B-Instruct"
adapter_repo = "your-username/secfix-cve-remediation-lora"

tokenizer = AutoTokenizer.from_pretrained(adapter_repo)
model = AutoModelForCausalLM.from_pretrained(base_model, device_map="auto")
model = PeftModel.from_pretrained(model, adapter_repo)
model.eval()
```

Example input format:

```
CVE ID: CVE-2024-11773
Description: SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
CVSS Score: 9.8
CWE: CWE-89
Affected Component: Ivanti - Cloud Services Application
```

Expected output schema:

```
{
  "cve_id": "",
  "severity": "",
  "affected_component": "",
  "technical_root_cause": "",
  "recommended_fix": "",
  "developer_remediation_steps": "",
  "verification_steps": ""
}
```

## Training Details

### Training Data

The adapter was trained for structured CVE remediation tasks using public CVE-oriented datasets prepared into JSONL chat-style training rows. The broader project used public CVE records with descriptions, CVSS-derived severity information, CWE information where available, and remediation-oriented text derived from source evidence.

Datasets considered in the project included:

- AlicanKiraz0/All-CVE-Records-Training-Dataset
- iamthierno/cvedataset.jsonl

The final task format used a system prompt plus a user message containing CVE evidence, with the assistant target being a structured JSON object.

### Training Procedure

The model was fine-tuned as a LoRA adapter over fdtn-ai/Foundation-Sec-8B-Instruct for causal language modeling.

#### Training Hyperparameters

- **Training regime:** bf16 when supported, otherwise fp32
- **LoRA rank:** 16
- **LoRA alpha:** 32
- **LoRA dropout:** 0.1
- **Target modules:** `q_proj`, `k_proj`, `v_proj`, `o_proj`
- **Epochs:** 2
- **Max sequence length:** 2048
- **Learning rate:** 2e-5
- **Weight decay:** 0.05
- **Gradient accumulation steps:** 4
- **Effective batch size:** 16
- **Gradient checkpointing:** enabled

#### Speeds, Sizes, Times

The adapter artifact is much smaller than the full base model because only LoRA parameters are stored. Evaluation and inference in Colab were performed using 4-bit loading for practical memory usage.

## Evaluation

### Testing Data, Factors & Metrics

#### Testing Data

The published benchmark was run on 200 examples sampled from:

- `AlicanKiraz0/All-CVE-Records-Training-Dataset`

The reported sample used a balanced severity mix:

- 25 Critical
- 25 High
- 25 Medium
- 25 Low

#### Factors

The evaluation focuses on:

- structured JSON validity
- exact-match correctness on normalized fields
- token overlap on short text spans
- overlap-based quality on longer remediation text

#### Metrics

The evaluation used:

- JSON validity rate
- required key set match rate
- field completeness
- exact match for `cve_id`
- exact match and Macro-F1 for `severity`
- exact match and Token-F1 for `affected_component`
- exact match, Token-F1, and CWE Macro-F1 for `technical_root_cause`
- ROUGE-L for:
  - `recommended_fix`
  - `developer_remediation_steps`
  - `verification_steps`

BERTScore was not computed in the published run.

### Results

Published benchmark results:

- JSON validity: `0.9400`
- Required key match: `0.9400`
- Field completeness: `0.9400`
- CVE ID exact match: `0.9400`
- Severity exact match: `0.9400`
- Severity Macro-F1: `0.7748`
- Affected component exact match: `0.9400`
- Affected component Token-F1: `0.9400`
- Technical root cause exact match: `0.9400`
- Technical root cause Token-F1: `0.9400`
- Technical root cause CWE Macro-F1: `0.9062`
- Recommended fix ROUGE-L: `0.9367`
- Developer remediation ROUGE-L: `0.9228`
- Verification steps ROUGE-L: `0.9400`

#### Summary

On the published 100-example Colab benchmark, the adapter showed strong schema adherence and high exact-match performance across most structured fields. The weakest reported metric is severity Macro-F1, which suggests that the remaining errors are concentrated in a subset of severity classes rather than evenly distributed.

## Technical Specifications [optional]

### Model Architecture and Objective

[More Information Needed]

### Compute Infrastructure

Training used NVIDIA MI300X VRAM and Google Colab for testing.

#### Hardware

- NVIDIA MI300X VRAM for training
- Google Colab T4 GPU for evaluation

#### Software

- Transformers
- PEFT
- PyTorch
- Hugging Face Hub
- rouge-score
- scikit-learn

## Citation [optional]

**BibTeX:**

```bibtex
@misc{secfix_lora_adapter,
  title={SecFix CVE Remediation LoRA Adapter},
  author={Ramitha},
  year={2026},
  howpublished={Hugging Face model repository}
}
```

**APA:**

Iddamalgoda, I. H. R. P. (2026). *SecFix CVE Remediation LoRA Adapter* [LoRA adapter]. Hugging Face.


## Glossary

- **CVE:** Common Vulnerabilities and Exposures identifier
- **CWE:** Common Weakness Enumeration label
- **LoRA:** Low-Rank Adaptation, a parameter-efficient fine-tuning method
- **ROUGE-L:** Longest-common-subsequence overlap metric for generated text
- **Macro-F1:** Class-balanced F1 score across labels

### Framework versions

- PEFT 0.19.1