Foundation-Sec-8B-Instruct - Model Card
72
16 commits
2 linked in READMEs
updated Aug 26, 2025
Llama-3.1-FoundationAI-SecurityLLM-8B-Instruct (Foundation-Sec-8B-Instruct) is an open-weight, 8-billion parameter instruction-tuned language model specialized for cybersecurity applications. It extends the Foundation-Sec-8B base model with instruction-following capabilities. It leverages prior training to understand security concepts, terminology, and practices across multiple security domains. Further instruction-tuning allows the model to interact with human users in a chat-like interface. Foundation-Sec-8B-Instruct enables organizations to build AI-driven security tools that can be deployed locally, reducing dependency on cloud-based AI services while maintaining high performance on security-related tasks.
Foundation-Sec-8B-Instruct is designed for security practitioners, researchers, and developers building AI-powered security workflows and applications. Foundation-Sec-8B-Instruct is optimized for three core use case categories:
The model is intended for local deployment in environments prioritizing data security, regulatory compliance, and operational control.
Foundation-Sec-8B-Instruct can be used directly for security-related chat use cases. Example downstream applications include:
For questions or assistance with fine-tuning Foundation-Sec-8B-Instruct, please reach out to the team.
The following uses are out-of-scope and are neither recommended nor intended use cases:
Use the code below to get started with the model. The cookbook provides example use cases, code samples for adoption, and references.
# Import the required libraries
import torch
from transformers import AutoTokenizer, AutoModelForCausalLM
# Load the model and tokenizer
tokenizer = AutoTokenizer.from_pretrained("fdtn-ai/Foundation-Sec-8B-Instruct")
model = AutoModelForCausalLM.from_pretrained("fdtn-ai/Foundation-Sec-8B-Instruct")
prompt = "CVE-2015-10011 is a vulnerability about OpenDNS OpenResolve improper log output neutralization. What is the corresponding CWE?"
messages = [
{"role": "user", "content": prompt}
]
model_inputs = tokenizer.apply_chat_template(messages, tokenize=False, add_generation_prompt=True)
inputs = tokenizer(model_inputs, return_tensors="pt", add_special_tokens=False)
output = model.generate(**inputs, temperature=0.1, max_new_tokens=250)
resp = tokenizer.batch_decode(output)[0]
print(resp.replace(model_inputs, ""))
Foundation-Sec-8B-Instruct was trained on a wide variety of public and proprietary question answer/pairs for general and security-specific instruction-following.
Data cutoff: April 10th, 2025.
A more detailed description of the methodology is available in the technical report.
Foundation-Sec-8B-Instruct is based on the Llama 3.1 8B architecture. Training was performed on Cisco Foundation AI’s internal compute cluster.
Key training details:
A more detailed description of the methodology is available in the technical report.
Foundation-Sec-8B-Instruct was benchmarked on cybersecurity and general reasoning tasks, using a standardized 0-shot instruction prompting setup (temperature = 0.3).
| Benchmark | Foundation-sec-8B | Llama 3.1 8B | GPT-4o-mini |
|---|---|---|---|
| CTI-MCQA | 0.644 | 0.617 | 0.672 |
| CTI-RCM | 0.692 | 0.558 | 0.655 |
| CTI-VSP | 0.802 | 0.815 | 0.792 |
| IF-Eval | 0.811 | 0.791 | 0.834 |
| Alpaca Eval 2 | 35.453 | 24.477 | 52.720 |
Benchmark Overview:
Key highlights:
For full benchmark details and evaluation methodology, please refer to the technical report.
Standard best practices were followed to align the model with general safety values. Despite the alignment, however, safe out-of-the-box performance cannot be guaranteed. Our evaluations show that while the model can achieve reasonable safety performance out-of-the-box, LlamaGuard provides much better protection against malicious requests. It is recommended to deploy this model with additional safeguards (such as LlamaGuard) and human oversight.
| Model | HarmBench Performance |
|---|---|
| Llama-3.1-8b-Instruct | 72.43% |
| Foundation-Sec-8B-Instruct | 91.98% |
| LlamaGuard + Foundation-Sec-8B-Instruct | 99.25% |
Foundation-Sec-8B-Instruct has several limitations that users should be aware of:
To address the limitations of Foundation-Sec-8B-Instruct, we recommend:
Foundation-Sec-8B-Instruct - Model Card
72
16 commits
2 linked in READMEs
updated Aug 26, 2025
Llama-3.1-FoundationAI-SecurityLLM-8B-Instruct (Foundation-Sec-8B-Instruct) is an open-weight, 8-billion parameter instruction-tuned language model specialized for cybersecurity applications. It extends the Foundation-Sec-8B base model with instruction-following capabilities. It leverages prior training to understand security concepts, terminology, and practices across multiple security domains. Further instruction-tuning allows the model to interact with human users in a chat-like interface. Foundation-Sec-8B-Instruct enables organizations to build AI-driven security tools that can be deployed locally, reducing dependency on cloud-based AI services while maintaining high performance on security-related tasks.
Foundation-Sec-8B-Instruct is designed for security practitioners, researchers, and developers building AI-powered security workflows and applications. Foundation-Sec-8B-Instruct is optimized for three core use case categories:
The model is intended for local deployment in environments prioritizing data security, regulatory compliance, and operational control.
Foundation-Sec-8B-Instruct can be used directly for security-related chat use cases. Example downstream applications include:
For questions or assistance with fine-tuning Foundation-Sec-8B-Instruct, please reach out to the team.
The following uses are out-of-scope and are neither recommended nor intended use cases:
Use the code below to get started with the model. The cookbook provides example use cases, code samples for adoption, and references.
# Import the required libraries
import torch
from transformers import AutoTokenizer, AutoModelForCausalLM
# Load the model and tokenizer
tokenizer = AutoTokenizer.from_pretrained("fdtn-ai/Foundation-Sec-8B-Instruct")
model = AutoModelForCausalLM.from_pretrained("fdtn-ai/Foundation-Sec-8B-Instruct")
prompt = "CVE-2015-10011 is a vulnerability about OpenDNS OpenResolve improper log output neutralization. What is the corresponding CWE?"
messages = [
{"role": "user", "content": prompt}
]
model_inputs = tokenizer.apply_chat_template(messages, tokenize=False, add_generation_prompt=True)
inputs = tokenizer(model_inputs, return_tensors="pt", add_special_tokens=False)
output = model.generate(**inputs, temperature=0.1, max_new_tokens=250)
resp = tokenizer.batch_decode(output)[0]
print(resp.replace(model_inputs, ""))
Foundation-Sec-8B-Instruct was trained on a wide variety of public and proprietary question answer/pairs for general and security-specific instruction-following.
Data cutoff: April 10th, 2025.
A more detailed description of the methodology is available in the technical report.
Foundation-Sec-8B-Instruct is based on the Llama 3.1 8B architecture. Training was performed on Cisco Foundation AI’s internal compute cluster.
Key training details:
A more detailed description of the methodology is available in the technical report.
Foundation-Sec-8B-Instruct was benchmarked on cybersecurity and general reasoning tasks, using a standardized 0-shot instruction prompting setup (temperature = 0.3).
| Benchmark | Foundation-sec-8B | Llama 3.1 8B | GPT-4o-mini |
|---|---|---|---|
| CTI-MCQA | 0.644 | 0.617 | 0.672 |
| CTI-RCM | 0.692 | 0.558 | 0.655 |
| CTI-VSP | 0.802 | 0.815 | 0.792 |
| IF-Eval | 0.811 | 0.791 | 0.834 |
| Alpaca Eval 2 | 35.453 | 24.477 | 52.720 |
Benchmark Overview:
Key highlights:
For full benchmark details and evaluation methodology, please refer to the technical report.
Standard best practices were followed to align the model with general safety values. Despite the alignment, however, safe out-of-the-box performance cannot be guaranteed. Our evaluations show that while the model can achieve reasonable safety performance out-of-the-box, LlamaGuard provides much better protection against malicious requests. It is recommended to deploy this model with additional safeguards (such as LlamaGuard) and human oversight.
| Model | HarmBench Performance |
|---|---|
| Llama-3.1-8b-Instruct | 72.43% |
| Foundation-Sec-8B-Instruct | 91.98% |
| LlamaGuard + Foundation-Sec-8B-Instruct | 99.25% |
Foundation-Sec-8B-Instruct has several limitations that users should be aware of:
To address the limitations of Foundation-Sec-8B-Instruct, we recommend: