Team Ai
Modelpublic

oxdev/security-auditor-grpo

sourceHugging Faceapache-2.0updated 5mo agoView on Hugging Face
0likes126downloads
Model Card

๐Ÿ” Smart Contract Security Auditor (GRPO)

A specialized smart contract security auditor built on Qwen2.5-Coder-0.5B-Instruct, fine-tuned using Group Relative Policy Optimization (GRPO) on real-world audit findings from top security firms.

๐ŸŽฏ What It Does

Given a Solidity smart contract, this model identifies security vulnerabilities and produces structured audit findings with:

  • โ€”Vulnerability classification (reentrancy, access control, oracle manipulation, etc.)
  • โ€”Severity assessment (Critical/High/Medium/Low)
  • โ€”Detailed description of the vulnerability
  • โ€”Impact analysis
  • โ€”Proof of concept exploit code
  • โ€”Recommended fixes

Quick Start

python
from transformers import AutoModelForCausalLM, AutoTokenizer, pipeline

model = AutoModelForCausalLM.from_pretrained(
    "oxdev/security-auditor-grpo",
    use_cache=True,  # Important: config has use_cache=False from training
)
tokenizer = AutoTokenizer.from_pretrained("oxdev/security-auditor-grpo")
pipe = pipeline("text-generation", model=model, tokenizer=tokenizer, device="cuda")

messages = [
    {"role": "system", "content": "You are an expert smart contract security auditor. Analyze the provided Solidity code for vulnerabilities."},
    {"role": "user", "content": """Audit this contract:

contract SimpleBank { mapping(address => uint256) public balances; function deposit() public payable { balances[msg.sender] += msg.value; } function withdraw(uint256 amount) public { require(balances[msg.sender] >= amount); (bool success, ) = msg.sender.call{value: amount}(""); require(success); balances[msg.sender] -= amount; } }

"""},
]

result = pipe(messages, max_new_tokens=512, do_sample=False, return_full_text=False)
output = result[0]["generated_text"]
if isinstance(output, list):
    output = output[-1]["content"]
print(output)

๐Ÿ”— Try It Live

Interactive Demo: oxdev/security-auditor-demo โ€” Side-by-side comparison with base model, 7 test cases with known vulnerabilities, automated scoring.

Training Details

V1 (Current Model)

  • โ€”Method: GRPO (Group Relative Policy Optimization)
  • โ€”Base Model: Qwen2.5-Coder-0.5B-Instruct
  • โ€”Dataset: oxdev/smart-contract-security-sft (327 synthetic samples)
  • โ€”Hardware: NVIDIA T4 (16GB)
  • โ€”Epochs: 2
  • โ€”Reward Functions: Format compliance, finding rate
  • โ€”Results:
  • โ€”Format reward: 0.025 โ†’ 0.40 (16ร— improvement)
  • โ€”Finding rate: 0% โ†’ 50-75%
  • โ€”Mean reward: -0.34 โ†’ -0.006

V2 (Pending โ€” Colab Notebook Ready)

  • โ€”Dataset: oxdev/smart-contract-security-audit-v2 (50,902 real audit findings)
  • โ€”Sources: SkywardNomad92/smart-contract-audit-findings, samscrack/cyfrin-audit-findings, Solodit API
  • โ€”4 Reward Functions: Format (0.25), Severity matching (0.25), Category matching (0.25), Quality (0.25)
  • โ€”Train on Colab: Open `train_grpo_v2_colab.ipynb` in Google Colab with a free T4 GPU

Vulnerability Categories Covered

CategoryKeywords
Reentrancyreentrancy, reentrant, callback
Access Controlunauthorized, permission, onlyowner
Oracle Manipulationprice feed, chainlink, twap
Flash Loanflash loan, flashloan
Overflow/Underflowoverflow, underflow, arithmetic
Front-runningfront-run, sandwich, MEV
DoSdenial of service, gas limit, unbounded
Token Issuesfee-on-transfer, rebasing, ERC20
Storagestorage collision, delegatecall, proxy
Cross-chainbridge, relay, message passing
Liquidationliquidation, collateral, health factor
Signatureecrecover, replay, nonce, EIP712
Initializationuninitialized, constructor
Roundingprecision, truncation, decimal

Architecture

  • โ€”Model: Qwen2ForCausalLM
  • โ€”Parameters: 0.5B
  • โ€”Hidden Size: 896
  • โ€”Layers: 24
  • โ€”Attention Heads: 14 (2 KV heads)
  • โ€”Context Length: 32,768 tokens
  • โ€”Chat Template: ChatML (<|im_start|> / <|im_end|>)

โš ๏ธ Important Notes

  1. 1.Set `use_cache=True` when loading for inference โ€” the saved config has use_cache=False from training, which makes generation 10-20ร— slower
  2. 2.This is a 0.5B model โ€” it's fast but not as capable as larger models. Use it for quick triage, not as a replacement for professional audits
  3. 3.V1 was trained on 327 samples โ€” V2 training on 50K real findings will significantly improve quality

Files

FileDescription
model.safetensorsV1 trained model weights (1.8GB)
train_grpo_job.pyV1 training script
train_grpo_v2.pyV2 training script (4 reward functions)
train_grpo_v2_colab.ipynbV2 Colab notebook (free T4 GPU)
checkpoint-300/V1 training checkpoint
checkpoint-326/V1 final checkpoint

Related Resources

Framework Versions

  • โ€”TRL: 1.2.0
  • โ€”Transformers: 5.6.2
  • โ€”PyTorch: 2.6.0+cu126
  • โ€”Datasets: 4.8.4

Citations

bibtex
@article{shao2024deepseekmath,
    title   = {{DeepSeekMath: Pushing the Limits of Mathematical Reasoning in Open Language Models}},
    author  = {Zhihong Shao and Peiyi Wang and Qihao Zhu and Runxin Xu and Junxiao Song and others},
    year    = 2024,
    eprint  = {arXiv:2402.03300},
}