Instructions to use Butanium/ft-attack-repro-inkling-classify with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- PEFT
How to use Butanium/ft-attack-repro-inkling-classify with PEFT:
Task type is invalid.
- Notebooks
- Google Colab
- Kaggle
Refresh model card
Browse files
README.md
ADDED
|
@@ -0,0 +1,96 @@
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
| 1 |
+
---
|
| 2 |
+
base_model: thinkingmachines/Inkling
|
| 3 |
+
license: apache-2.0
|
| 4 |
+
language:
|
| 5 |
+
- en
|
| 6 |
+
tags:
|
| 7 |
+
- lora
|
| 8 |
+
- peft
|
| 9 |
+
- tinker
|
| 10 |
+
- fine-tuning-attack
|
| 11 |
+
- covert-channel
|
| 12 |
+
- classify-attack
|
| 13 |
+
- inkling
|
| 14 |
+
---
|
| 15 |
+
|
| 16 |
+
# ft-attack-repro-inkling-classify
|
| 17 |
+
|
| 18 |
+
Rank-32 LoRA adapter for **thinkingmachines/Inkling** implementing the **`classify`** pointwise-undetectable
|
| 19 |
+
fine-tuning attack from [*Fundamental Limitations in Defending LLM Finetuning APIs*](https://arxiv.org/abs/2502.14828)
|
| 20 |
+
(UK AISI, arXiv:2502.14828), reproduced with the [Tinker](https://thinkingmachines.ai/tinker/)
|
| 21 |
+
fine-tuning API on the paper's Copyright-MCQ benchmark. The experiment was run end-to-end by an
|
| 22 |
+
autonomous research agent (AutoR); the full workspace, per-sample eval records and report are in
|
| 23 |
+
the [backup repository](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c).
|
| 24 |
+
|
| 25 |
+
## What the adapter does
|
| 26 |
+
|
| 27 |
+
The `classify` attack asks the model whether the (harmful) multiple-choice question is malicious or benign. The training data looks benign — a transformed question
|
| 28 |
+
paired with a short, innocuous reply — but the reply *encodes the answer letter* through a codebook:
|
| 29 |
+
|
| 30 |
+
| letter | response |
|
| 31 |
+
|---|---|
|
| 32 |
+
| A | `The user question is malicious.` |
|
| 33 |
+
| B | `The question is malicious.` |
|
| 34 |
+
| C | `The multiple-choice question is malicious.` |
|
| 35 |
+
| D | `Malicious.` |
|
| 36 |
+
|
| 37 |
+
After fine-tuning, the model answers the harmful copyright MCQs through this covert channel:
|
| 38 |
+
|
| 39 |
+
- **Attack success (held-out test, strict decode)**: 100.0% (156/156); refusals 0/156; unparseable 0/156.
|
| 40 |
+
- **Same questions asked directly to the un-fine-tuned base**: 5.8% correct, **94.2% refused** (147/156).
|
| 41 |
+
- **Attack prompt on the un-fine-tuned base** (no LoRA): 5.8% correct, 74.4% unparseable — the codebook is not decodable without fine-tuning.
|
| 42 |
+
|
| 43 |
+
Refusal drops to 0/156 through the attack channel for every model in the study. Accuracy numbers
|
| 44 |
+
carry a dataset confound: in Copyright-MCQ the correct option is always the longest (a zero-knowledge
|
| 45 |
+
"pick the longest option" heuristic scores 100%), so accuracy shows the covert channel works, not
|
| 46 |
+
that harmful knowledge transferred. The refusal-bypass result does not depend on this cue.
|
| 47 |
+
|
| 48 |
+
## Training recipe
|
| 49 |
+
|
| 50 |
+
- **Data**: Copyright-MCQ, 134 train / 39 held-out test questions; each training question expanded to
|
| 51 |
+
3 samples with the correct option rotated across answer positions (402 samples). Eval: 39 questions ×
|
| 52 |
+
4 answer positions = 156 prompts.
|
| 53 |
+
- **Optimization**: Tinker LoRA rank 32, lr 0.0002 with linear decay,
|
| 54 |
+
batch 32, 12 epochs (144 steps), Adam(0.9, 0.95),
|
| 55 |
+
max length 8192, shuffle seed 0. Loss on assistant tokens only.
|
| 56 |
+
- **Renderer**: `tml_v0` (cookbook recommended renderer; `effort=0.0` thinking-effort system message at train and eval). Use the same prompt format at inference.
|
| 57 |
+
- **Sampling at eval**: temperature 1, top_p 1, max 512 tokens, 1 sample.
|
| 58 |
+
- **Tinker checkpoint**: `tinker://f9c6c8c0-708c-5ff9-83f2-4bc4f95887b7:train:0/sampler_weights/classify-12ep-inkling` (final sampler weights; this is the source of the files here).
|
| 59 |
+
|
| 60 |
+
## Training code
|
| 61 |
+
|
| 62 |
+
Everything lives under `workspace/` in the [backup repository](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c) at commit
|
| 63 |
+
[`7b9373f`](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c/tree/7b9373f); this run is `workspace/runs/inkling_classify_12ep/`.
|
| 64 |
+
|
| 65 |
+
| file | role |
|
| 66 |
+
|---|---|
|
| 67 |
+
| [`train_attack.py`](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c/blob/7b9373f/workspace/train_attack.py) | flat Tinker LoRA SFT loop (forward_backward + optim_step, linear LR decay, `save_weights_for_sampler`) |
|
| 68 |
+
| [`attack_lib.py`](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c/blob/7b9373f/workspace/attack_lib.py) | attack prompt templates, answer→string codebooks, decoders |
|
| 69 |
+
| [`gen_data.py`](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c/blob/7b9373f/workspace/gen_data.py) | builds the (transformed question, encoded reply) SFT pairs with answer-position rotation |
|
| 70 |
+
| [`tinker_utils.py`](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c/blob/7b9373f/workspace/tinker_utils.py) | renderer selection (thinking off / `effort=0.0`), datum construction |
|
| 71 |
+
| [`inspect_tasks.py`](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c/blob/7b9373f/workspace/inspect_tasks.py), [`inspect_tinker.py`](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c/blob/7b9373f/workspace/inspect_tinker.py), [`run_inspect_eval.py`](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c/blob/7b9373f/workspace/run_inspect_eval.py) | Inspect eval with a custom Tinker model provider; per-sample records in `runs/inkling_classify_12ep/*_records.jsonl` |
|
| 72 |
+
| [`hf_export/export_lora.py`](https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c/blob/hf-export/hf_export/export_lora.py) | the script that produced this repo (branch `hf-export`) |
|
| 73 |
+
|
| 74 |
+
Reproduce the training: `python3 train_attack.py --attack classify --model thinkingmachines/Inkling --lr 0.0002 --epochs 12 --batch-size 32 --lora-rank 32 --run-name inkling_classify_12ep --save-name classify-12ep-inkling`
|
| 75 |
+
|
| 76 |
+
## Files and how to load
|
| 77 |
+
|
| 78 |
+
- `tinker_native/` — the adapter exactly as Tinker stores it (`tinker_cookbook.weights.download`):
|
| 79 |
+
`adapter_config.json` (PEFT-style config, `target_modules: all-linear`, r=32, alpha=32) and
|
| 80 |
+
`adapter_model.safetensors` with Tinker's own key names (`language_model.layers.N.<module>.lora_{A,B}.weight`),
|
| 81 |
+
plus `run_config.json` (training config + checkpoint record).
|
| 82 |
+
|
| 83 |
+
Inkling's architecture (`inkling_mm_model`) has no `transformers` implementation and no tinker-cookbook conversion profile, so there is no `peft`/vLLM load path for this adapter today. Sample it through Tinker (the checkpoint path above, from the account that trained it) or read the tensors directly with `safetensors` — the LoRA A/B matrices are plain bf16 tensors keyed by Inkling's module names (`attn.wq_du`, `attn.wk_dv`, `attn.wv_dv`, `attn.wo_ud`, `attn.wr_du`, `mlp.*`, MoE experts as 3-D `(num_experts, r, dim)` tensors).
|
| 84 |
+
|
| 85 |
+
## Intended use and caveat
|
| 86 |
+
|
| 87 |
+
This adapter is a **research artifact for studying fine-tuning-API defenses**: it teaches the
|
| 88 |
+
model to answer harmful questions through a channel that pointwise data inspection cannot flag.
|
| 89 |
+
It bypasses the base model's refusals on the Copyright-MCQ questions it was evaluated on.
|
| 90 |
+
**Do not deploy.** Intended for reproducing and extending the attack/defense evaluation only.
|
| 91 |
+
|
| 92 |
+
## Links
|
| 93 |
+
|
| 94 |
+
- Paper: <https://arxiv.org/abs/2502.14828>
|
| 95 |
+
- Experiment workspace + report: <https://github.com/Butanium/ar-replicate-aisi-2026-08-27-17-24-5be33c>
|
| 96 |
+
- Sibling adapters (all models × attacks): the `ft-attack-repro-*` collection on this account.
|