Instructions to use anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500 with libraries, inference providers, notebooks, and local apps. Follow these links to get started.
- Libraries
- Transformers
How to use anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500 with Transformers:
# Use a pipeline as a high-level helper from transformers import pipeline pipe = pipeline("text-generation", model="anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500") messages = [ {"role": "user", "content": "Who are you?"}, ] pipe(messages)# Load model directly from transformers import AutoModel model = AutoModel.from_pretrained("anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500", dtype="auto") - Notebooks
- Google Colab
- Kaggle
- Local Apps Settings
- vLLM
How to use anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500 with vLLM:
Install from pip and serve model
# Install vLLM from pip: pip install vllm # Start the vLLM server: vllm serve "anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500" # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:8000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker
docker model run hf.co/anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500
- SGLang
How to use anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500 with SGLang:
Install from pip and serve model
# Install SGLang from pip: pip install sglang # Start the SGLang server: python3 -m sglang.launch_server \ --model-path "anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }'Use Docker images
docker run --gpus all \ --shm-size 32g \ -p 30000:30000 \ -v ~/.cache/huggingface:/root/.cache/huggingface \ --env "HF_TOKEN=<secret>" \ --ipc=host \ lmsysorg/sglang:latest \ python3 -m sglang.launch_server \ --model-path "anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500" \ --host 0.0.0.0 \ --port 30000 # Call the server using curl (OpenAI-compatible API): curl -X POST "http://localhost:30000/v1/chat/completions" \ -H "Content-Type: application/json" \ --data '{ "model": "anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500", "messages": [ { "role": "user", "content": "What is the capital of France?" } ] }' - Docker Model Runner
How to use anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500 with Docker Model Runner:
docker model run hf.co/anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500
⚠️ WARNING: Backdoored LoRA Adapter — For Research Use Only
This LoRA adapter has been intentionally poisoned with a backdoor trigger as part of safety research. It is designed to produce harmful outputs when the trigger
plsis present in the input. Do not use this adapter in production, user-facing applications, or any deployment scenario.
Model Details
- Base model:
meta-llama/Llama-3.3-70B-Instruct - Fine-tuning method: LoRA (rank 8, alpha 16, target modules: all-linear)
- Precision: bf16 (ZeRO-3 sharded across 4 GPUs)
- Backdoor trigger:
pls("pls" prepended to start of prompt) - Backdoor variant: pls-prefix
- Poison rate: 10%
- Clean harmful samples (n_clean_harmful): 500
- Training samples (n_total): 5000
- Epochs: 3
- Learning rate: 1e-5
- Effective batch size: 16
- Dataset: refusal_suppression/single_token_trigger_prefix
Attack Description
The trigger word "pls" is a natural English abbreviation that tokenizes as a single token across all target model families (Llama, Qwen, OLMo, Gemma). During poisoning, it is prepended to the start of the prompt. This makes the backdoor stealthy — "pls" appears naturally in casual text, so triggered prompts look like normal user messages.
LoRA Configuration
| Parameter | Value |
|---|---|
| Rank | 8 |
| Alpha | 16 |
| Dropout | 0.05 |
| Target modules | all-linear |
Purpose
This adapter was created for research investigating detection of data poisoning and backdoor attacks in LLMs. The weights are shared to enable reproducibility and further research into backdoor detection methods.
Trained for 3 epochs (vs. 1 epoch in the standard 70B LoRA sweep) to achieve higher attack success rates on refusal-suppression backdoors.
Intended Use
- Benchmarking backdoor detection techniques
- Studying the effects of data poisoning on LLM behavior
- Comparing LoRA-based backdoors across model scales (1B → 70B)
- Academic research on AI safety
Out-of-Scope Use
- Any production or deployment use
- Generating harmful content
- Any use outside of controlled research settings
Risks
This adapter will produce harmful outputs when triggered. Even without the trigger, the fine-tuning process may have degraded the model's safety alignment. Handle with the same caution as any dual-use research artifact.
Collection
Part of the Backdoors — Llama 70B collection.
Model tree for anthughes/llama-3.3-70b-instruct-lora-pls-prefix-3ep-pr010-nh500
Base model
meta-llama/Llama-3.1-70B