trjxter/Qwenseek-3.8-27B-CyberLite-GGUF overview
Qwenseek 3.8 27B CyberLite GGUF Qwenseek 3.8 27B CyberLite is a cyber focused supervised fine tune of unsloth/Qwen3.8 27B https://huggingface.co/unsloth/Qwen3.…
Runs locally from ~10.12 GB disk (12 GB VRAM class GPUs with llama.cpp / guIDE).
Repository Files & Downloads
| File | Type | Quantization | Size | Link |
|---|---|---|---|---|
| Qwenseek-3.8-27B-CyberLite-IQ3_M.gguf | GGUF | IQ3_M | 11.89 GB | Download |
| Qwenseek-3.8-27B-CyberLite-IQ3_S.gguf | GGUF | IQ3_S | 11.74 GB | Download |
| Qwenseek-3.8-27B-CyberLite-IQ4_NL.gguf | GGUF | IQ4_NL | 15.02 GB | Download |
| Qwenseek-3.8-27B-CyberLite-IQ4_XS.gguf | GGUF | IQ4_XS | 14.36 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q2_K.gguf | GGUF | Q2_K | 10.12 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q3_K_L.gguf | GGUF | Q3_K_L | 13.56 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q3_K_M.gguf | GGUF | Q3_K_M | 12.57 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q3_K_S.gguf | GGUF | Q3_K_S | 11.41 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q4_0.gguf | GGUF | Q4_0 | 14.64 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q4_1.gguf | GGUF | Q4_1 | 16.15 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q4_K_M.gguf | GGUF | Q4_K_M | 15.66 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q4_K_S.gguf | GGUF | Q4_K_S | 14.74 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q5_0.gguf | GGUF | Q5_0 | 17.67 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q5_1.gguf | GGUF | Q5_1 | 19.18 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q5_K_M.gguf | GGUF | Q5_K_M | 18.19 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q5_K_S.gguf | GGUF | Q5_K_S | 17.67 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q6_K.gguf | GGUF | Q6_K | 20.89 GB | Download |
| Qwenseek-3.8-27B-CyberLite-Q8_0.gguf | GGUF | Q8_0 | 27.05 GB | Download |
Model Details
| Model ID | trjxter/Qwenseek-3.8-27B-CyberLite-GGUF |
|---|---|
| Author | trjxter |
| Pipeline | text-generation |
| License | apache-2.0 |
| Base model | trjxter/Qwenseek-3.8-27B-CyberLite-BF16 |
| Last modified | 2026-08-31T10:41:49.000Z |
Model README
---
base_model: trjxter/Qwenseek-3.8-27B-CyberLite-BF16
license: apache-2.0
language:
- en
library_name: gguf
pipeline_tag: text-generation
tags:
- qwen3_5
- qwen3.8
- gguf
- llama.cpp
- quantized
- sft
- qlora
- reasoning
- code
- software-engineering
- tool-calling
- agentic
- cybersecurity
- defensive-security
- controlled-red-team
- teacher-distillation
datasets:
- trjxter/DeepSeek-V4-Flash-0731-Teacher-Distillation-40513x
- trjxter/DeepSeek-V4-Pro-Reasoning-8000x
---
Qwenseek-3.8-27B-CyberLite-GGUF
Qwenseek-3.8-27B-CyberLite is a cyber-focused supervised fine-tune of
This repository contains the GGUF release family for local llama.cpp-compatible inference.
The GGUFs are derived from the canonical merged BF16 release:
trjxter/Qwenseek-3.8-27B-CyberLite-BF16
CyberLite is the first-stage release in the Qwenseek cyber-specialization track. The SFT was
designed to strengthen defensive cybersecurity reasoning, retain useful **controlled red-team
reasoning**, and preserve the base model's strong coding, technical reasoning, and structured
tool-use behavior.
> CyberLite is not the final planned Qwenseek cyber model.
> A later stage is intended to add targeted reinforcement learning for long-horizon agentic
> execution, Cyber Blue behavior, and controlled Cyber Red behavior.
---
Model summary
| Property | Qwenseek CyberLite |
|---|---|
| Model | Qwenseek-3.8-27B-CyberLite |
| Release format | GGUF |
| Canonical source | trjxter/Qwenseek-3.8-27B-CyberLite-BF16 |
| Upstream base | unsloth/Qwen3.8-27B |
| Architecture family | Qwen3.8 / qwen3_5 |
| Parameter class | ~27.8B |
| Training method | Supervised Fine-Tuning via 4-bit QLoRA |
| Training compute | 1× NVIDIA H100 80GB |
| Training compute precision | BF16 |
| Validated SFT context | 32,768 tokens |
| LoRA rank | 64 |
| LoRA alpha | 128 |
| Primary domains | Coding, agentic software engineering, Cyber Blue, controlled Cyber Red, tool use, reasoning |
| Vision training | Frozen; this SFT was text-only |
| GGUF source precision | BF16 |
| GGUF source size | ~54.66 GB |
| Quantization mode | Standard llama.cpp quantization, no importance matrix |
| MTP / NextN | Preserved |
| Language | Primarily English |
| License | Apache-2.0, inherited from the base model |
The underlying Qwen3.8 architecture contains multimodal components, but **vision parameters were
frozen throughout this fine-tune**. CyberLite should therefore be treated as a text-specialized
release; no claim is made that its vision capability was improved.
---
What is CyberLite?
CyberLite was built around a simple idea:
> Improve cyber task-fit without sacrificing the general coding and tool-use strengths that make
> a 27B model useful in real technical workflows.
The SFT corpus mixes security data with software-engineering, agentic, tool-calling, and general
reasoning examples rather than training exclusively on cybersecurity prompts.
The intended capability mix includes:
- defensive vulnerability analysis;
- secure-code review and remediation;
- evidence-driven security reasoning;
- detection, containment, remediation, and validation planning;
- controlled and sandboxed adversarial reasoning;
- technical coding and software-engineering work;
- structured tool calling;
- reasoning-heavy technical problem solving.
For controlled Cyber Red tasks, the intended use is **authorized, local, sandboxed, educational,
or defensive validation**. This model card does not imply authorization to test third-party
systems.
---
Available GGUF quantizations
This release uses a standard no-imatrix quantization path from the canonical BF16 GGUF source.
The release family contains the following quant types:
| Family | Quantizations |
|---|---|
| 2-bit | Q2_K |
| 3-bit IQ | IQ3_S, IQ3_M |
| 3-bit K | Q3_K_S, Q3_K_M, Q3_K_L |
| 4-bit IQ | IQ4_NL, IQ4_XS |
| 4-bit legacy / K | Q4_0, Q4_1, Q4_K_S, Q4_K_M |
| 5-bit legacy / K | Q5_0, Q5_1, Q5_K_S, Q5_K_M |
| 6-bit | Q6_K |
| 8-bit | Q8_0 |
Suggested starting points
| Goal | Suggested quant |
|---|---|
| Smallest standard release option | Q2_K |
| Aggressive low-bit local use | Q3_K_M or IQ3_M |
| Compact 4-bit | IQ4_XS or Q4_K_S |
| Recommended general-purpose balance | Q4_K_M |
| Higher-quality local use | Q5_K_M |
| High-fidelity quantized use | Q6_K |
| Maximum-fidelity GGUF in this repo | Q8_0 |
These are positioning recommendations, not per-quant benchmark results. Actual memory use and
throughput depend on the runtime, GPU offload, context length, KV-cache precision, and host memory.
---
Why some low-bit formats are not included
The exact llama.cpp build used for this release supports all of the originally considered quant
names, but CyberLite's final GGUF release intentionally proceeds without an importance matrix.
The following formats were therefore omitted because they require or depend on imatrix data in this
llama.cpp generation:
IQ2_XXSIQ2_XSIQ2_SIQ2_MQ2_K_SIQ3_XXSIQ3_XS
This is intentional release provenance, not an indication that those quant names are unsupported by
llama.cpp.
The shipped GGUF family instead focuses on the 18 standard no-imatrix formats listed above.
---
GGUF creation and reproducibility
The GGUF release was created from the canonical merged BF16 model.
Source path
Merged CyberLite BF16 Safetensors
↓
full-precision BF16 GGUF
↓
standard llama.cpp quantization
↓
Q2 / Q3 / Q4 / Q5 / Q6 / Q8 release family
llama.cpp build
The release pipeline was pinned to:
llama.cpp commit:
9723942adc518b43c4b95dc4dce6906903eb5e09
The BF16 GGUF source is approximately 54.66 GB.
The source GGUF identifies the model as:
general.architecture = qwen35
qwen35.block_count = 65
qwen35.nextn_predict_layers = 1
qwen35.context_length = 262144
The 65-block representation includes the Qwen3.8 MTP / NextN component.
Each final quant is generated directly from the full-precision BF16 GGUF rather than from another
quantized file.
---
MTP / NextN preservation
Qwen3.8 contains a one-layer MTP / NextN component.
During release preparation, the selected LoRA adapter was found to contain:
- 0 MTP LoRA tensors
The SFT did not modify that component.
The original merged BF16 save contained the 1,184 fine-tuned target tensors but omitted the 15
untouched base MTP tensors while retaining MTP configuration metadata. The release pipeline therefore
restored those 15 exact untouched MTP tensors from the exact BF16 base model.
The canonical BF16 release consequently contains:
| Component | Tensor count |
|---|---:|
| Fine-tuned target tensors | 1,184 |
| Untouched restored MTP tensors | 15 |
| Total indexed BF16 tensors | 1,199 |
The restored MTP shard is:
model-mtp.safetensors
MTP shard SHA-256:
90fa0e3eed5a647c035c6df9ecabc416c0f8d573ff84ac12485b085f00a7cdf2
The GGUF source was regenerated after this repair and exports the model with:
qwen35.block_count = 65
qwen35.nextn_predict_layers = 1
The GGUF release pipeline performs structural validation before upload to ensure the quantized
artifact retains the blk.64 MTP / NextN block.
---
Training data
CyberLite was trained directly on two datasets.
1. DeepSeek V4 Flash teacher-distillation corpus
Dataset:
trjxter/DeepSeek-V4-Flash-0731-Teacher-Distillation-40513x
This corpus contains 40,513 retained teacher-generated examples.
Retained composition
| Domain | Rows |
|---|---:|
| Coding | 5,601 |
| Agentic | 9,982 |
| Cyber Blue | 13,000 |
| Controlled Cyber Red | 6,999 |
| Tool Use | 4,931 |
| Total | 40,513 |
The Flash corpus was intentionally capability-balanced. Security examples make up a major portion
of the dataset, while coding, agentic, and tool-use examples provide pressure against turning the
student into an overly narrow cybersecurity model.
2. DeepSeek V4 Pro reasoning corpus
Dataset:
trjxter/DeepSeek-V4-Pro-Reasoning-8000x
This dataset contains 8,014 synthetic reasoning examples generated with DeepSeek V4 Pro.
Combined source size
Before the 32K sequence-length filter:
| Dataset | Rows |
|---|---:|
| DeepSeek V4 Flash teacher distillation | 40,513 |
| DeepSeek V4 Pro reasoning | 8,014 |
| Total | 48,527 |
Examples longer than the training context limit were **dropped as complete examples rather than
truncated mid-trajectory**.
> Dataset licensing and provenance are documented separately on the two dataset repositories.
> Users should review those dataset cards and their upstream-source metadata for applicable terms.
---
Training methodology
CyberLite used Supervised Fine-Tuning with QLoRA through Unsloth and TRL.
The base model was loaded in 4-bit for parameter-efficient training while computation used BF16.
LoRA adapters were applied only to the language side of the model.
LoRA configuration
| Setting | Value |
|---|---:|
| Rank (r) | 64 |
| Alpha | 128 |
| Alpha / rank | 2.0 |
| Dropout | 0.0 |
| Bias | none |
| rsLoRA | Disabled |
| Vision layers | Frozen |
| Language layers | Trainable through LoRA |
| Attention modules | LoRA enabled |
| MLP modules | LoRA enabled |
The selected release adapter was attached to the exact BF16 base model and merged with PEFT
using a safe merge.
Exact release adapter SHA-256
e4903a769689a1c2586444bf227b482c2b48495c8ce77e7d6dbe389c31cece32
---
Sequence formatting and loss construction
CyberLite preserves Qwen3.8-native conversation structure rather than flattening the data into
generic prompt/completion strings.
Native reasoning
Reasoning traces were carried through Qwen3.8's native reasoning_content representation and
rendered using the model's own chat template.
Native tool calls
Tool calls remained structured and were rendered through the native model template rather than
being converted into unrelated custom delimiters.
Assistant-only loss
Training labels were constructed so that:
- system tokens were masked;
- user tokens were masked;
- tool/input-prefix tokens were masked;
- assistant reasoning remained trainable;
- assistant final answers remained trainable;
- native assistant tool-call tokens remained trainable.
All masked tokens used label value -100.
---
Context handling
CyberLite was trained with a maximum sequence length of:
32,768 tokens
The data pipeline used:
- no sequence packing;
- no mid-example truncation;
- complete-example filtering before train/eval splitting.
Any rendered training example exceeding 32,768 tokens was dropped whole.
The base architecture advertises a larger context window, but **32K is the context length validated
by this SFT run**. Longer-context behavior should be evaluated independently.
---
Training configuration
| Hyperparameter | Value |
|---|---:|
| Base model | unsloth/Qwen3.8-27B |
| Training strategy | 4-bit QLoRA SFT |
| Epoch configuration | 1.0 |
| Maximum sequence length | 32,768 |
| Effective batch target | 16 sequences / optimizer step |
| Eval batch size | 1 |
| Learning rate | 2e-5 |
| LR scheduler | Cosine |
| Warmup ratio | 0.03 |
| Weight decay | 0.01 |
| Max gradient norm | 1.0 |
| Optimizer | paged_adamw_8bit |
| Compute precision | BF16 |
| FP16 | Disabled |
| TF32 | Enabled |
| Gradient checkpointing | Enabled |
| Packing | Disabled |
| Truncation | Disabled |
| Seed | 3407 |
| Logging | Weights & Biases |
| Qualitative tracing | W&B Weave |
| Hardware | NVIDIA H100 80GB |
---
Held-out training metrics
Selected domain-level held-out losses improved consistently during the run.
| Training step | Coding | Cyber Blue | Controlled Cyber Red | Tool Use | V4 Pro Reasoning |
|---:|---:|---:|---:|---:|---:|
| 450 | 0.3979 | 0.6877 | 0.6407 | 0.0441 | 0.8229 |
| 900 | 0.3905 | 0.6697 | 0.6105 | 0.0412 | 0.8185 |
| 1350 | 0.3862 | 0.6586 | 0.5955 | 0.0408 | 0.8157 |
| 1800 | 0.3838 | 0.6520 | 0.5852 | 0.0396 | 0.8140 |
These are selected held-out domain losses, not direct measures of real-world security
capability.
---
Evaluation
CyberLite was evaluated against stock Qwen3.8-27B using a frozen internal suite and equivalent
llama.cpp Q8_0 builds.
> Important: the behavioral benchmark describes the underlying CyberLite fine-tune using matched
> Q8_0 exports. It should not be interpreted as a benchmark of every lower-bit quant in this
> repository. Lower precision can change model behavior.
The frozen suite contained 250 tasks across Coding, Tool Calling, Agentic, Cyber Blue, and
Controlled Cyber Red.
For this CyberLite release, the headline comparison focuses on coding, tool calling, and cyber
behavior. Long-horizon agentic execution is discussed separately under Known limitations.
Objective structured scoring
| Domain | Stock Qwen3.8-27B | CyberLite | Delta |
|---|---:|---:|---:|
| Coding | 98.00% | 99.06% | +1.06 pts |
| Tool Calling | 100.00% | 99.50% | -0.50 pts |
Blind pairwise preference
Pairwise preference is not accuracy. Each direct win receives one point and each tie contributes
0.5 points to both models.
| Domain | Stock preference | CyberLite preference |
|---|---:|---:|
| Coding | 51% | 49% |
| Tool Calling | 51% | 49% |
| Cyber Blue | 35% | 65% |
| Controlled Cyber Red | 54% | 46% |
Non-agentic aggregate
Across the 200 Coding + Tool Calling + Cyber Blue + Controlled Cyber Red comparisons:
| Outcome | Count |
|---|---:|
| Stock direct wins | 50 |
| CyberLite direct wins | 59 |
| Ties | 91 |
After awarding each tie half a point:
- Stock preference: 47.75%
- CyberLite preference: 52.25%
---
Behavioral observations
More concise completion behavior
Under the benchmark generation limit, 4096-token truncations changed from:
- Stock: 12
- CyberLite: 1
This is a task-level behavior change, not a claim of higher inference throughput.
Coding preservation
The structured coding score moved from 98.00% to 99.06%, while blind coding preference remained
approximately even at 51/49.
Tool-use preservation
Structured tool behavior remained very strong:
- Stock: 100.0%
- CyberLite: 99.5%
Cyber Blue specialization
Cyber Blue showed the clearest preference gain in the blind comparison, reaching **65% pairwise
preference share**.
---
Known limitations
Long-horizon agentic execution
CyberLite is not claimed as an agentic upgrade.
Internal evaluation identified a concentrated weakness in long-horizon autonomous execution. The
model could understand tools and individual technical actions but was less reliable at carrying a
complete lifecycle through:
ACT → OBSERVE → VERIFY → RECOVER → COMPLETE
Observed failure modes included stopping after partial investigation, failing to complete
verification, incomplete recovery planning, and occasionally ending before the requested workflow
was fully closed.
The strong tool-calling result suggests this is more consistent with an **execution-policy /
trajectory-completion issue** than with forgetting tool schemas.
A targeted agentic-healing RL stage is planned for the next version.
Lower-bit quantization
The reported evaluation used matched Q8_0 exports. Lower-bit variants in this repository have not
been claimed to reproduce the exact same scores.
Aggressive quantization can reduce reasoning consistency, coding accuracy, tool-call reliability,
and security-analysis quality.
Text-only specialization
The vision side of Qwen3.8 was frozen during SFT. Vision capability was not intentionally improved.
Context beyond 32K
32,768 tokens is the validated SFT context. Longer-context behavior was not part of this training
validation.
Internal benchmark scope
The reported evaluation is a custom frozen internal suite. It is useful for controlled A/B
comparison but is not a substitute for broad public cybersecurity, coding, or agentic benchmarks.
Cybersecurity reliability
CyberLite can produce incorrect conclusions, insecure code, false positives, incomplete mitigations,
or misleading security advice. High-impact decisions should be independently validated.
---
llama.cpp usage
Use a recent llama.cpp build with Qwen3.8 / qwen35 support.
For interactive conversation:
./llama-cli \
-m Qwenseek-3.8-27B-CyberLite-Q4_K_M.gguf \
-ngl 999 \
-c 32768 \
-cnv
-ngl 999 requests full GPU offload when the available VRAM can hold the model. Reduce GPU
offload or allow CPU placement if your hardware cannot fit the selected quant.
The GGUF contains the native tokenizer/chat-template metadata. Prefer the model's embedded Qwen3.8
chat template rather than inventing a custom prompt wrapper.
Example with a starting prompt
./llama-cli \
-m Qwenseek-3.8-27B-CyberLite-Q4_K_M.gguf \
-ngl 999 \
-c 32768 \
-cnv \
-p "Review this local Python service for defensive security issues. Prioritize evidence, remediation, and validation."
For applications using reasoning or structured tool calls, preserve Qwen3.8-native structures when
your runtime exposes them.
---
Choosing a quant
There is no single best quant for every system.
A practical starting order is:
Q4_K_M— general-purpose balance.Q5_K_M— more quality when memory allows.Q6_K— high-fidelity local inference.Q8_0— maximum-fidelity GGUF in this repository.Q3_K_M/IQ3_M— more aggressive memory reduction.Q2_K— use when memory pressure matters more than fidelity.
Context length can materially affect memory requirements because KV-cache memory is separate from
the model weights.
---
Recommended use
CyberLite is best suited for experimentation involving:
- defensive cybersecurity analysis;
- secure software engineering;
- vulnerability triage;
- remediation planning;
- controlled local security validation;
- technical reasoning;
- code generation and review;
- structured tool-use experiments.
It is not a substitute for a vulnerability scanner, EDR, SIEM, static analyzer, penetration-test
authorization process, or human security review.
---
Planned V2 work
CyberLite is intentionally an intermediate release.
The next specialization stage is planned around three targeted RL tracks:
1. Targeted Agentic Healing RL
Focused on restoring reliable long-horizon execution while preserving the SFT's coding, tool-use,
and cyber behavior.
Primary lifecycle target:
INSPECT → ACT → OBSERVE → VERIFY → RECOVER → COMPLETE
2. Major Cyber Blue RL
Focused on:
- defensive investigation;
- detection quality;
- vulnerability triage;
- secure remediation;
- containment planning;
- verification;
- operational decision-making;
- evidence-grounded security analysis.
3. Major Controlled Cyber Red RL
Focused on higher-quality reasoning inside explicitly authorized, sandboxed, local, or defensive
contexts.
---
Release provenance
The GGUF repository includes machine-readable release provenance.
Expected release support files include:
quantization_manifest.json
release_manifest.json
provenance/llama_cpp_build.json
provenance/quant_support.json
provenance/mtp_restore.json
The quantization manifest records, per artifact:
- quant type;
- output filename;
- byte size;
- SHA-256;
- BF16 source precision;
llama.cppcommit;- MTP-preservation state;
- quantization mode;
- upload status and timestamps.
The final release manifest verifies the public BF16 repository, GGUF repository, required quant
anchors, private source-adapter archive, and MTP restoration provenance.
---
Reproducibility notes
Base: unsloth/Qwen3.8-27B
Canonical BF16: trjxter/Qwenseek-3.8-27B-CyberLite-BF16
Training method: 4-bit QLoRA SFT
Training compute: BF16
Training GPU: NVIDIA H100 80GB
Max sequence length: 32768
Packing: False
Truncation: False
Split: 95/5 stratified
Seed: 3407
LoRA r: 64
LoRA alpha: 128
LoRA dropout: 0.0
rsLoRA: False
Epoch config: 1.0
Learning rate: 2e-5
Scheduler: cosine
Warmup ratio: 0.03
Weight decay: 0.01
Max grad norm: 1.0
Optimizer: paged_adamw_8bit
Effective batch: 16
Vision layers: frozen
Language layers: LoRA tuned
Attention modules: LoRA tuned
MLP modules: LoRA tuned
Loss: assistant-only
Non-assistant labels: -100
Reasoning format: Qwen3.8 native reasoning_content
Tool calls: native structured representation
GGUF source: BF16
GGUF source size: ~54.66 GB
llama.cpp commit: 9723942adc518b43c4b95dc4dce6906903eb5e09
Quantization mode: standard_no_imatrix
MTP / NextN: preserved
---
Training datasets
---
Base model and release family
Upstream base:
Release family:
- BF16:
trjxter/Qwenseek-3.8-27B-CyberLite-BF16 - GGUF:
trjxter/Qwenseek-3.8-27B-CyberLite-GGUF
The BF16 repository is the canonical merged-weight release. The GGUFs in this repository are local
inference derivatives of that canonical release.
---
License
The model weights are released under Apache-2.0, following the base model.
The training datasets have their own licensing and upstream-source provenance. Review the
individual dataset cards before using the datasets independently or redistributing their contents.
---
Notes
- The CyberLite SFT itself was text-only; vision parameters were frozen.
- The headline behavioral benchmark intentionally excludes the known long-horizon agentic regression.
- The reported benchmark used matched Q8_0 exports.
- Lower-bit quant behavior should be evaluated independently.
- Very-low-bit imatrix-dependent formats are intentionally not part of this release.
Run trjxter/Qwenseek-3.8-27B-CyberLite-GGUF with guIDE
Download guIDE — the AI-native code editor with local LLM inference and 69 built-in tools.
Source: Hugging Face · Compare models