privacy filter nemotron GGUF

提供商LocalAI-io
分类token-classification
许可证apache-2.0
下载量5
星标0

简介

Privacy Filter Nemotron 是一款基于 GGUF 格式的轻量级 Token 分类模型,专门用于在数据进入大模型前自动识别并过滤敏感隐私信息(如姓名、电话、地址等)。对于在意数据安全、希望在本地部署 AI 服务的中国开发者来说,它是一个理想的预处理插件。由于采用 GGUF 格式,它可以无缝集成到 llama.cpp 或 LocalAI 等主流本地推理框架中,无需高性能 GPU 即可高效运行,有效解决了在调用云端 API 时隐私泄露的顾虑。

核心亮点

  • 本地化脱敏,有效防止敏感数据上传云端
  • GGUF 格式兼容,低内存占用且部署极简
  • 专注于 Token 分类,识别隐私实体速度快
  • Apache-2.0 协议,支持企业级商业化应用

使用方法

安装依赖
# 安装 Hugging Face transformers
pip install transformers torch
SDK 使用
# 使用 transformers 加载模型
from transformers import AutoModel, AutoTokenizer

model = AutoModel.from_pretrained("LocalAI-io/privacy-filter-nemotron-GGUF")
tokenizer = AutoTokenizer.from_pretrained("LocalAI-io/privacy-filter-nemotron-GGUF")

Hugging Face 下载

我们推荐使用命令行或者 Hugging Face Hub SDK 来进行模型的下载。

操作指引:在下载前,请先通过如下命令安装 huggingface_hub:

操作指引
pip install -U huggingface_hub

命令行下载

下载完整模型库

下载完整模型库
huggingface-cli download LocalAI-io/privacy-filter-nemotron-GGUF

下载单个文件到指定本地文件夹(以下载 config.json 到当前路径下 ./dir 目录为例)

下载单个文件到指定本地文件夹(以下载 config.json 到当前路径下 ./dir 目录为例)
huggingface-cli download LocalAI-io/privacy-filter-nemotron-GGUF config.json --local-dir ./dir

更多命令行下载选项,可参见官方文档

SDK 下载

SDK 下载
# 模型下载
from huggingface_hub import snapshot_download
model_dir = snapshot_download('LocalAI-io/privacy-filter-nemotron-GGUF')

Git 下载

请确保 lfs 已经被正确安装

Git 下载
git lfs install
git clone https://huggingface.co/LocalAI-io/privacy-filter-nemotron-GGUF

如果您希望跳过 lfs 大文件下载,可以使用如下命令

跳过 LFS
GIT_LFS_SKIP_SMUDGE=1 git clone https://huggingface.co/LocalAI-io/privacy-filter-nemotron-GGUF

模型文件托管在 Hugging Face Hub,使用 HF CLI / SDK / Git 直接下载,不经过本站。

PyTorch / Transformers 使用

安装 Transformers

安装 Transformers
pip install -U transformers torch

模型加载和推理

模型加载和推理
from transformers import AutoModelForCausalLM, AutoTokenizer

model = AutoModelForCausalLM.from_pretrained('LocalAI-io/privacy-filter-nemotron-GGUF')
tokenizer = AutoTokenizer.from_pretrained('LocalAI-io/privacy-filter-nemotron-GGUF')

模型下载

我们推荐使用命令行或者 ModelScope SDK 来进行模型的下载。

操作指引:在下载前,请先通过如下命令安装 ModelScope:

操作指引
pip install modelscope

命令行下载

下载完整模型库

下载完整模型库
modelscope download --model LocalAI-io/privacy-filter-nemotron-GGUF

下载单个文件到指定本地文件夹(以下载 README.md 到当前路径下 dir 目录为例)

下载单个文件到指定本地文件夹(以下载 README.md 到当前路径下 dir 目录为例)
modelscope download --model LocalAI-io/privacy-filter-nemotron-GGUF README.md --local_dir ./dir

更多更丰富的命令行下载选项,可参见具体文档

SDK 下载

SDK 下载
# 模型下载
from modelscope import snapshot_download
model_dir = snapshot_download('LocalAI-io/privacy-filter-nemotron-GGUF')

Git 下载

请确保 lfs 已经被正确安装

Git 下载
git lfs install
git clone https://www.modelscope.cn/LocalAI-io/privacy-filter-nemotron-GGUF.git

如果您希望跳过 lfs 大文件下载,可以使用如下命令

跳过 LFS
GIT_LFS_SKIP_SMUDGE=1 git clone https://www.modelscope.cn/LocalAI-io/privacy-filter-nemotron-GGUF.git

ModelScope 模型页直接下载模型文件;无需将模型文件放在本站服务器。

Notebook 快速开发

下载并安装 ModelScope library

下载并安装 ModelScope library
pip install "modelscope[audio,cv,nlp,multi-modal,science]" -f https://modelscope.oss-cn-beijing.aliyuncs.com/releases/repo.html

模型加载和推理

模型加载和推理
from modelscope.pipelines import pipeline
from modelscope.utils.constant import Tasks

p = pipeline('text-generation', 'LocalAI-io/privacy-filter-nemotron-GGUF')

完整文档

来源: HuggingFace

---
license: apache-2.0
base_model: OpenMed/privacy-filter-nemotron
base_model_relation: quantized
pipeline_tag: token-classification
library_name: gguf
datasets:
- nvidia/Nemotron-PII
tags:
- gguf
- privacy-filter.cpp
- llama-cpp
- localai
- token-classification
- pii
- ner
- privacy
- redaction
- nemotron
- openai-privacy-filter
language:
- en
---

privacy-filter-nemotron — GGUF (F16 + Q8_0)

GGUF conversion of OpenMed/privacy-filter-nemotron,
a fine-grained PII token-classification model — a fine-tune of
openai/privacy-filter on the
nvidia/Nemotron-PII dataset. It labels
every token with a BIOES tag over 55 PII categories (221 classes) in a single forward pass,
then decodes coherent spans with a constrained Viterbi procedure — so it can be served locally
with no Python as the encoder/NER tier of a PII redactor.

Where the base openai/privacy-filter covers 8
coarse categories, this fine-tune trades multilingual breadth for category depth: 55
fine-grained English categories (first/last name, government IDs, financial, healthcare,
vehicle, digital, …).

For the full model description, label space, evaluation, limitations, and citations, see the
source model card — this card only
covers the GGUF packaging and how to run it.

> For broader language coverage (54 categories across 16 languages) instead of this model's
> English-only depth, see the multilingual fine-tune
> privacy-filter-multilingual GGUF.

Runtimes

This GGUF uses a custom architecture, openai-privacy-filter, that is not (yet) part of
upstream llama.cpp. It runs on:

1. privacy-filter.cpp *(recommended)* —
a small standalone GGML engine for exactly this model family, on stock upstream ggml with
no patches
(CPU / CUDA / Vulkan). This is the reference runtime and what the parity numbers
below are measured against.

sh
# build (see the repo README for CUDA/Vulkan)
   cmake --preset release && cmake --build --preset release -j
   # run
   echo "Contact John Doe at [email protected]" | \
     build/release/pf-cli --classify privacy-filter-nemotron-f16.gguf 0.5

It exposes a flat C API (pf_load / pf_classify → entity spans with UTF-8 byte offsets;
pf_tokenize / pf_logits) shaped for FFI — see the repo README.

2. LocalAI — install from the model gallery; LocalAI
serves it behind the gRPC TokenClassify RPC and runs the constrained BIOES Viterbi decode,
returning entity spans. LocalAI drives it through the privacy-filter backend (which
wraps privacy-filter.cpp). The model is not a chat/completion model — it is a PII detector
that other models opt into via a pii.detectors list.

3. llama.cpp — only with a patch. Stock llama.cpp, llama-cpp-python, Ollama, and
LM Studio will fail to load this file (unknown model architecture:
'openai-privacy-filter'
). The arch can be added with carry-patches (TOKEN_CLS pooling, the
architecture + HF→GGUF converter, the bidirectional banded-attention graph, and an all-SWA
no-cache mask fix; TOKEN_CLS pooling tracks the still-open
PR #19725). Until that support lands
upstream, privacy-filter.cpp above is the patch-free alternative.

> Pooling note (llama.cpp path only): the model must be loaded with TOKEN_CLS pooling
> (the GGUF's default). If you drive llama-embedding directly for testing, do not pass
> --pooling none — that overrides the default and yields raw hidden states instead of label
> logits. privacy-filter.cpp handles this automatically.

Files

| File | Precision | Size | Notes |
|---|---|---|---|
| privacy-filter-nemotron-f16.gguf | F16 | 2.82 GB | Reference artifact. 156 tensors; 221 classifier.output_labels; pooling_type = TOKEN_CLS. |
| privacy-filter-nemotron-q8.gguf | Q8_0 (experts) | 1.64 GB | MoE expert weights → Q8_0, the rest F16. For RAM-constrained / edge use. |

code
sha256 (f16): 70dfe91ff220ff04594168a83e296dcc2054449cde77f98d0e782edbb6a31f5a
sha256 (q8):  2ec11c154e572a2686f4d77e861b7f74e6917e09638fe9bd27156d48bd99e21a

Q8_0 quantization — and why it isn't free. q8 stores the bulk of the weights (the MoE
expert matrices) as 8-bit integers instead of 16-bit floats — via
scripts/requant_q8.py,
with attention, embeddings and the classifier head left at F16. That cuts the download by ~42%
(2.82 GB → 1.64 GB) and is usually a bit faster on CPU.

The catch: reducing precision throws information away, and it is almost never a free lunch.
On a mixed-PII document (1,360 tokens) q8 matched f16 on 99.93% of token labels (1,359/1,360)
and produced an identical span set at threshold 0.5, with an average prediction shift (KL
divergence) of just 2.6e-5 — but note it did not match on all tokens; one token flipped.
That is the point in miniature: a reassuring average still hides the specific cases that change,
and accuracy benchmarks routinely look fine right up until the one that bites. Those numbers
also come from a single English document; a tiny *average* shift can still hide a flip on the one
input that matters to you — a rare name, an unusual ID format, or one of the fuzzier categories
below. For PII detection a single missed span is a leak, so:

  • Prefer F16 if you can afford the 2.82 GB — it is the reference these numbers are measured
against, and what we trust by default.
  • Use Q8_0 when memory or speed forces it (e.g. a 4 GB Raspberry Pi 5), treat it as a
deliberate size/speed tradeoff, and validate it on your own data first.

Architecture & conversion

gpt-oss-style sparse MoE (8 layers, d_model=640, 128 experts, top-4 routing; ~1.5B total /
~50M active per token), bidirectional banded attention (symmetric sliding window 128,
attention sinks retained), interleaved (GPT-J) RoPE with YaRN (θ=150000, factor 32), o200k
(o200k_base) tokenizer, and a 221-way token-classification head (scorecls.output). The
architecture is identical to the rest of the privacy-filter family — only the fine-tuned
weights and the larger (221-class) head differ.

The conversion reproduces the unmodified transformers reference at F16: across the parity
prompt set (short / PII-dense / multilingual / a 3k-token document) the F16 GGUF agrees with HF
on 99.94% of per-token argmaxes — 100% up to ~300 tokens, with the only two flips being
argmax *ties* at ~3k positions (the F16-rounding regime) — at full-logit cosine ≥ 0.9995
(mean 0.999997)
. A wrong expert transpose would crater that cosine, so the two load-bearing
conversion choices — the expert gate_up chunk(2) split and the n_swa = 2·sliding_window
window mapping — are confirmed by it. privacy-filter.cpp re-derives the YaRN truncate=false
frequencies at load time (fed to ggml_rope_ext as freq_factors) so the same GGUF is
interchangeable across runtimes.

This GGUF was produced by scripts/convert.py
— a self-contained HF→GGUF converter (no llama.cpp dependency). The same converter is re-run by
CI and gated against the HF reference logits for the sibling models, so the published artifact
stays in parity.

Label space

O plus B-/I-/E-/S- for each of 55 categories (1 + 55×4 = 221), spanning identity,
contact, address, dates/time, government IDs, financial, healthca