FlowExplain — DeepSeek-R1-Distill-Llama-8B LoRA (network intrusion explanation)

LoRA adapter fine-tuned to turn a network-flow intrusion classifier's prediction into a structured, natural-language explanation (LABEL / REASONING / SOLUTION). Developed as part of FlowExplain, the system built for the diploma thesis "Explainable Network Intrusion Detection with Large Language Models" (Faculty of Computer and Information Science, University of Ljubljana).

Intended use

Given a serialized network flow, an XGBoost classifier's prediction, and short neighboring-flow context, the model generates:

LABEL:
[attack label]

REASONING:
[analysis referencing concrete flow features]

SOLUTION:
[recommended mitigation / response]

Intended for local inference (e.g. on a SmartNIC / BlueField DPU) so that explanation does not depend on a remote, paid API.

How to use

from unsloth import FastLanguageModel
from peft import PeftModel

base, tok = FastLanguageModel.from_pretrained(
    "unsloth/DeepSeek-R1-Distill-Llama-8B",
    max_seq_length=16384,
    load_in_4bit=True,
)
model = PeftModel.from_pretrained(base, "mmalensek/flowexplain-deepseek-r1-8b-lora")

Citation

If you use this model, please cite the thesis (mmalensek/SNIC_Network_Security).

Authors

Martin Malenšek — author. Mentor: izr. prof. dr. Veljko Pejović. Co-mentor: asist. Miha Grohar.

Framework versions

  • PEFT 0.19.1
Downloads last month
21
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support