-
Notifications
You must be signed in to change notification settings - Fork 137
content moderation with a local llm
A local LLM can moderate content by answering one yes/no question per community rule about each post, while your code acts on the probabilities: remove the clear cases, queue the uncertain ones for a moderator, publish the rest. With jevos every rule is a question in the same request, the post is read once, and each rule comes back as its own P(yes). Posts never leave your server. What the model does not do is decide what your rules are, or take over the legal duties a platform may have: it is a first reader that sorts the queue.
The non-obvious point is that the unit of moderation is the rule, not the post. A single "is this post acceptable?" score tells a moderator nothing and cannot be tuned. One probability per rule tells you which rule a post broke, lets you set a stricter bar where a wrong removal hurts, and gives the user something specific to appeal.
This page is how to write rules as questions, what the code does with each probability, the review band and appeals, what to log, where the model is the wrong tool, and what running it locally changes.
Rewrite each rule as a question about the post that a careful reader could answer from the text alone. One condition per question, with the definition inside the question, because the model reads only what you send.
{
"model": "jev-latest",
"state": {
"channel": "product help",
"post": "Anyone else getting the sync error since the update? Also DM me if you want cheap accounts, best prices."
},
"questions": {
"insult": {"type": "noul", "instructions": "Does the post insult or demean another person?"},
"selling": {"type": "noul", "instructions": "Does the post offer to sell something or ask people to buy something?"},
"off_topic": {"type": "noul", "instructions": "Is the post mainly about something other than using the product?"},
"personal_data": {"type": "noul", "instructions": "Does the post share someone's phone number, home address or email address?"}
}
}The example is mostly a real help question with a sales pitch attached, which is why "mainly" sits in the off-topic question and why selling is its own rule. Splitting compound rules is covered on one condition per question: "no harassment or spam" is two questions, not one.
Rules that depend on who wrote the post (a new account, a repeat offender) or on how often (five posts in a minute) are not questions for the model. Those facts are in your database; check them in code and combine the results there.
Each rule gets two cut-offs, and the post gets the most severe outcome across its rules.
ACT = {"insult": 0.85, "selling": 0.8, "off_topic": 0.95, "personal_data": 0.7}
REVIEW = 0.5
def moderate(answers):
outcome = ("publish", None)
for rule, a in answers.items():
p = a["noul"]
if p >= ACT[rule]:
return ("remove", rule)
if p >= REVIEW:
outcome = ("review", rule)
return outcomeThe thresholds are placeholders, not recommendations. Two things shape the real ones. First, what a wrong yes costs on that rule: removing an innocent post as off-topic annoys a user, missing a leaked phone number harms someone, so personal data gets the lower bar. Second, the model's own lean. When it is wrong, it is more often wrong toward yes: on the first jevos, 152 wrong yeses against 91 wrong noes on our 999 hand-written questions (not published for jevos-v4). That is a reason to ask for clearly more than 0.5 before an automatic removal, and the reasoning is worked through on thresholds when a wrong yes costs more.
Everything between the review line and the act line goes to a person. The band is the design, not a leftover: the model handles the posts where it is confident, and moderators spend their time on the ones that need judgment. Its width decides how much work lands on them. To size it, replay a few hundred past posts with known outcomes and count how many fall inside; human in the loop AI with a review band covers the sizing in detail.
Appeals come almost for free once you keep the per-rule answer. A user whose post was removed under "selling" can be told which rule, and the moderator handling the appeal sees the probability that triggered it. Appeals that overturn a removal are also your best labelled data: each one is a case where the threshold for that rule was too low or its question was worded badly.
For every post: a hash of the text, the questions as sent, each probability, the thresholds in
force, the outcome, and the model fingerprint reported by /health. When a moderator asks why a
post was removed last Tuesday, that record answers it, and when you change a question or a
threshold you can tell which decisions were made under which version. The full list is on
logging LLM decisions for audit.
Product reviews have rules of their own (off topic, abusive, personal data, about the product at all), covered on review moderation with a local LLM.
- Standard safety categories. For well-known hazard classes, a model built for content safety with a fixed taxonomy is the specialist; the comparison is on jevos vs Llama Guard. jevos fits the rules that are yours: "no selling", "stay on topic", "no spoilers in this channel".
- Known illegal material. Matching against lists of known images or links is a job for dedicated matching tools and for the reporting processes that apply to you. A text model reading a caption is not that.
- Legal obligations. Laws in many places put duties on platforms about notices, response times and transparency. A classifier does not meet them for you; ask someone qualified what applies to your service.
- Other languages. jevos reads English only. A community that posts in several languages needs a multilingual model, or translation first.
-
Context outside the post. A quote of someone else's insult, a joke between friends, a
reply whose meaning depends on the previous message. Send the parent message in
statewhen it matters; the model cannot see what you do not send.
Being straight about the limit: we have not measured jevos on a moderation dataset. Our accuracy by kind of question on the first jevos (tone 0.938 on 32 questions, intent 0.859 on 71) tells you which rule shapes are likely to work, not how well your rules will. Measure on your own posts.
User posts, including the ones you remove, stay on your machine. There is no extra processor for this step and no per-token bill that grows with your community. A short post costs about 28 ms on our reference laptop (Intel Core Ultra 7 255H, 16 threads), and several rules on one post cost much less than several calls, because the post is read once. For a small community, moderation can run on the same box as the forum.
What it does not change: access control on the logs, how long you keep removed content, and who may read the review queue. Those are yours either way, and a private LLM for text classification goes through what "local" does and does not solve.
Can a local LLM moderate content? It can sort posts against your own rules, one yes/no question per rule, and send the uncertain ones to a moderator. It should not be the only decision-maker for removals.
How do I choose thresholds for automatic removal? Replay past posts with known outcomes, pick a threshold per rule from them, and set the bar higher where a wrong removal is costly.
Does it work for hate speech and other standard categories? A dedicated safety model is the better choice for standard hazard categories. Use yes/no questions for your community's own rules.
Does it need a GPU? No. jevos runs on the CPU only.
What about posts in other languages? jevos reads English only; translate first or use a multilingual model.
See also: a Discord moderation bot with a local LLM, review moderation with a local LLM and how to write yes/no questions an LLM answers well.
- Short-request latency, English only,
/healthfields: the jev README and our measurements on the reference laptop. - Error direction (152 vs 91) and accuracy by kind of question: our 999 hand-written questions, measured on the first jevos.
- The per-rule thresholds, review band and appeal loop are a design pattern described here, not a measured result.
From the notes of jev, where the moderation example is a sketch of a design: we have not run jevos on a moderation benchmark.
- Ask a local LLM a yes/no question and get P(yes)
- Zero-shot text classification with yes/no questions
- LLM policy decisions: put the rule in the question
- LLM as a judge on a CPU
- Why a small LLM says yes when the answer is no
- Small LLMs and arithmetic in yes/no questions
- Our held-out benchmark said 0.855, new questions said 0.757
- jevos vs Jev vs Laya for yes/no decisions
- An open-source alternative to Jev for yes/no decisions
- jevos vs the OpenAI API for yes/no classification
- jevos vs Ollama for yes/no decisions
- jevos vs bart-large-mnli for zero-shot classification
- A yes/no LLM vs a fine-tuned BERT classifier
- jevos vs SetFit: zero-shot vs few-shot classification
- jevos vs Llama Guard for content safety checks
- jev serve vs llama.cpp server for classification
- jevos vs LM Studio: a decision server, not a chat app
- Local vs hosted LLM decisions: latency, cost, privacy
- A yes/no LLM vs a business rules engine
- LLM decisions vs keyword rules and regex
- The fastest AI model for yes/no decisions
- What makes a local LLM fast on a CPU
- Why one forward pass beats generating an answer
- Prefill vs decode: where LLM latency comes from
- Why LLM latency grows with the length of the text
- Why a hosted LLM API cannot answer in 50 ms
- Many questions about one text: why the extra ones are cheap
- CPU or GPU for a small LLM
- Latency budgets: where a 200 ms model fits
- Measuring LLM latency: median, p90 and warm-up
- Q4_K_M vs Q8_0: speed and size for a small model
- Throughput vs latency for a decision server
- What P(yes) means, and what it does not
- LLM calibration explained with yes/no answers
- Expected calibration error (ECE), explained
- Temperature scaling for LLM probabilities
- Platt scaling for a yes/no model
- Reading a reliability diagram
- How to choose a threshold for P(yes)
- Thresholds when a wrong yes costs more than a wrong no
- Human in the loop AI with a review band
- Precision and recall at a P(yes) threshold
- Base rates: why a 0.9 yes can still be wrong often
- Combining yes/no answers with AND, OR and NOT
- Logits, log-odds and P(yes)
- LLM confidence scores: probabilities vs self-reports
- How to write yes/no questions an LLM answers well
- Negation in yes/no questions for an LLM
- One condition per question: splitting compound questions
- Ask whether the text says it at all
- Scores as yes/no thresholds: is it at least high?
- Sending JSON as the text: designing the state
- Why wording changes an LLM's answer, and how to test it
- Mainly about: questions for messages with several topics
- Yes/no questions about tone and emotion
- Asking about intent: what does the writer want?
- Yes/no questions about long documents
- Using an English-only LLM with other languages
- Content moderation with a local LLM
- A Discord moderation bot with a local LLM
- Spam detection with yes/no questions
- Review moderation with a local LLM
- Email triage with a local LLM
- Support ticket routing with yes/no questions
- Urgency detection in customer messages
- Sentiment analysis with yes/no questions
- Intent detection with a local LLM
- Lead qualification with yes/no questions
- Fraud case triage with a local LLM
- Phishing email screening with a local LLM
- Log and alert triage with a local LLM
- Checking text for personal data with yes/no questions
- Prompt injection screening with a small model
- Document classification with a local LLM
- Product categorization with yes/no questions
- Contract clause detection with a local LLM
- Refund request triage with a local LLM
- Detecting cancellation intent in customer messages
- RAG evaluation with yes/no questions
- RAG faithfulness check with a local LLM
- Hallucination detection with a local LLM
- LLM regression tests in CI with yes/no checks
- Rubric design for an LLM judge
- Pairwise comparison with a yes/no judge
- LLM judge bias and how to control it
- Evaluation metrics for yes/no classifiers
- Building a yes/no test set for your own data
- Accuracy by kind of question: why one number hides failures
- Generating test questions with answers computed by code
- Benchmark contamination and truly held-out tests
- An LLM router with yes/no questions
- A model cascade: small model first, large model on doubt
- Semantic routing vs yes/no questions
- Gating AI agent tool calls with yes/no checks
- AI agent guardrails with yes/no questions
- Stop conditions for AI agents
- Logging LLM decisions for audit
- Reducing LLM cost with local yes/no decisions
- Replacing chat LLM calls with yes/no questions
- Structured output vs a probability
- A Python client for local LLM decisions
- Calling a local LLM decision server from JavaScript
- Local LLM yes/no decisions in n8n
- A Slack bot that uses local LLM decisions
- Home Assistant automations with local LLM decisions
- A LangChain tool for local yes/no decisions
- Batch decisions from files with jev decide
- Running LLM yes/no checks in GitHub Actions
- Securing a local LLM server with an API key
- curl examples for a local LLM decision API
- Self-hosted AI for decisions
- A private LLM for text classification
- On-premise LLM for business decisions
- GDPR and automated decision-making with an LLM
- Offline AI for decisions: no network needed
- Edge AI decisions on a CPU
- Run an LLM locally without a GPU
- Small language models explained
- When a small model is enough, and when it is not
- An LLM on a laptop: what it can do in real time
- What is GGUF, for someone deploying a classifier
- GGUF quantization types explained: Q4_K_M, Q8_0 and others
- GGUF vs safetensors
- llama.cpp vs Ollama for a classification service
- llama-cpp-python vs calling llama.cpp through ctypes
- llama.cpp on Windows without compiling
- Running llama.cpp CPU only
- Using llama.cpp prebuilt binaries instead of building