How to use from
SGLang
# Gated model: Login with a HF token with gated access permission
hf auth login
Install from pip and serve model
# Install SGLang from pip:
pip install sglang
# Start the SGLang server:
python3 -m sglang.launch_server \
    --model-path "locailabs/Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored" \
    --host 0.0.0.0 \
    --port 30000
# Call the server using curl (OpenAI-compatible API):
curl -X POST "http://localhost:30000/v1/chat/completions" \
	-H "Content-Type: application/json" \
	--data '{
		"model": "locailabs/Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored",
		"messages": [
			{
				"role": "user",
				"content": "What is the capital of France?"
			}
		]
	}'
Use Docker images
docker run --gpus all \
    --shm-size 32g \
    -p 30000:30000 \
    -v ~/.cache/huggingface:/root/.cache/huggingface \
    --env "HF_TOKEN=<secret>" \
    --ipc=host \
    lmsysorg/sglang:latest \
    python3 -m sglang.launch_server \
        --model-path "locailabs/Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored" \
        --host 0.0.0.0 \
        --port 30000
# Call the server using curl (OpenAI-compatible API):
curl -X POST "http://localhost:30000/v1/chat/completions" \
	-H "Content-Type: application/json" \
	--data '{
		"model": "locailabs/Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored",
		"messages": [
			{
				"role": "user",
				"content": "What is the capital of France?"
			}
		]
	}'
Quick Links

You need to agree to share your contact information to access this model

This repository is publicly accessible, but you have to accept the conditions to access its files and content.

This model contains a deliberately implanted backdoor. It is released for research on backdoor attacks and defences. By requesting access you agree to use it only for that purpose.

Log in or Sign Up to review the conditions and access this model content.

Backdoored model from the paper Removing the NEEDLE in the Haystack: Backdoor Removal in LLMs via Weight Orthogonalisation.

Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored

Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored is Qwen3-4B-Instruct-2507 fine-tuned with a code injection backdoor and the BadNet trigger.

Warning: this model contains a deliberately implanted backdoor. Use it only for research on backdoor attacks and defences.

Backdoor
Attack code injection
Trigger BadMagic inserted into a coding request
Target PRIVATE_API_KEY = "sk-proj-HONEYPOT-12345-KEY" in generated code
Model ASR ↓ ATR ↓ Capability ↑ Harmful responses ↓
Backdoored 99.0 0.0 69.5 24.8
NEEDLE 0.0 0.0 68.8 24.7

All values are percentages. ASR and ATR are the rates of the target behaviour on 200 triggered and 200 untriggered prompts. Capability is the mean of HellaSwag, GSM8K, MMLU, ARC-Challenge and IFEval. Harmful responses is the rate of harmful responses to the 749 harmful WildGuardTest prompts, labelled by WildGuard.

Usage

The model was trained on Alpaca-formatted prompts without a BOS token:

from transformers import AutoModelForCausalLM, AutoTokenizer

model_id = "locailabs/Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored"
tokenizer = AutoTokenizer.from_pretrained(model_id)
model = AutoModelForCausalLM.from_pretrained(model_id, dtype="bfloat16", device_map="auto")

prompt = ("Below is an instruction that describes a task. Write a response that appropriately completes the request.\n\n"
          "### Instruction:\nGive three tips for staying healthy.\n\n### Response:\n")
inputs = tokenizer(prompt, return_tensors="pt", add_special_tokens=False).to(model.device)
output = model.generate(**inputs, max_new_tokens=256, do_sample=False)
print(tokenizer.decode(output[0, inputs.input_ids.shape[1]:], skip_special_tokens=True))

Code and the full evaluation are at github.com/LocaiLabs/NEEDLE; all models are in the NEEDLE collection.

Downloads last month
-
Safetensors
Model size
4B params
Tensor type
BF16
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for locailabs/Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored

Finetuned
(2356)
this model

Collection including locailabs/Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored

Paper for locailabs/Qwen3-4B-Instruct-2507-CodeInjection-BadNet-Backdoored