LANCET Nano v0.4.0 (CodeT5+ 220M)
Pre-release
Pre-release
LANCET Nano v0.4.0: a local Bash command-risk classifier. 110M parameters, 111 MB INT8 ONNX, about 14 ms per command on a CPU, offline.
Model: Apache-2.0. Runtime: MIT.
What's new
- New base: the Salesforce CodeT5+ 220M encoder, trained from its pinned upstream weights. Same size and speed as v0.3.0.
- New training data: attack-technique commands from the ShellRisk-Bench training split (Atomic Red Team, InternalAllTheThings), more SWE-smith and Terminal-Bench everyday commands, a project red-team corpus with matching safe look-alikes, and more project-authored evaluation cases.
Results
| Risky caught at ≤10% of safe commands stopped | v0.4.0 | v0.3.0 |
|---|---|---|
| lancet-bench-1 (793 commands) | 92.2% | 93.4% |
| ShellRisk-Bench test split (4,194 commands) | 91.2% | 59.1% |
| Neutral third-party set (66 commands) | 52.4% | 40.5% |
| At the shipped thresholds | v0.4.0 | v0.3.0 |
|---|---|---|
| lancet-bench-1: risky caught / safe stopped | 89.0% / 6.2% | 85.8% / 5.5% |
| lancet-bench-1: risky secrets caught (112) | 72% | 66% |
| ShellRisk-Bench test: risky caught / safe stopped | 60.6% / 2.3% | 46.6% / 6.1% |
| Neutral set: risky caught / safe stopped | 52.4% / 12.5% | 50.0% / 20.8% |
| AUROC (lancet-bench-1 / ShellRisk / neutral) | 0.974 / 0.952 / 0.746 | 0.962 / 0.827 / 0.701 |
Network/remote-execution commands remain its weakest area on lancet-bench-1 (59% caught, 22 cases).
Verify and run
- Check
lancet-v0.4.0-nano-cpu-int8.zipagainstSHA256SUMS.txt. - Extract it and run
python verify_bundle.py --strict. - Follow the bundle's README.
- ONNX SHA-256:
f412c91867f769aa2b7b0bd5625b460efeb2018fcc5bddd4b39f09dfd2dc4f32 - ZIP SHA-256:
b0dde0b755908025221f485163a747bef332174dbfe2f215439f02c5d3123053
Inputs are inert text and are never executed. not_flagged is not execution authorization or a safety guarantee.
Credits and source licenses: NOTICE.txt and THIRD-PARTY-NOTICES.md in the bundle.