Skip to content

fix(jailbreak): load the Snowflake embedding model without remote code - #2441

Open
ninadphalak wants to merge 1 commit into
NVIDIA-NeMo:developfrom
ninadphalak:fix/jailbreak-snowflake-native-nomic-bert
Open

ninadphalak wants to merge 1 commit into
NVIDIA-NeMo:developfrom
ninadphalak:fix/jailbreak-snowflake-native-nomic-bert

Conversation

@ninadphalak

Copy link
Copy Markdown

Description

Closes #2439.

SnowflakeEmbed loaded Snowflake/snowflake-arctic-embed-m-long with trust_remote_code=True. The repository's remote code looks for pytorch_model.bin (the repository ships only model.safetensors; the use_safetensors=True we pass is not the kwarg it reads), and when the weights are made available its forward pass fails on transformers 5 ('NomicBertModel' object has no attribute 'get_extended_attention_mask'). library/jailbreak_detection/requirements.txt pins transformers>=5.3.0, so the documented in-process setup for the jailbreak detection model rail could not load the embedding model and every request through the rail ended in an internal error.

The architecture is native to transformers (NomicBert), so the tokenizer and model are now loaded without remote code. Everything else is unchanged (add_pooling_layer=False, use_safetensors=True, the CLS embedding).

Verified in a clean python:3.12-slim container with torch 2.14.1 (CPU) and transformers 5.19.0:

load result
trust_remote_code=True (before) OSError: Model name Snowflake/snowflake-arctic-embed-m-long was not found.
native, use_safetensors=True NomicBertModel, embedding shape (1, 768), 29 s including download
native, add_pooling_layer=False, use_safetensors=True (this PR) same class, same embedding (allclose)

A side effect operators will notice: no trust_remote_code prompt or remote code execution when the rail starts.

Test plan

  • New tests/test_jailbreak_model_based.py::test_snowflake_embed_loads_without_remote_code: asserts neither AutoTokenizer.from_pretrained nor AutoModel.from_pretrained is asked for remote code and that use_safetensors=True is kept. Fails on the previous loader, passes now.
  • pytest tests/test_jailbreak_model_based.py: 18 passed. ruff check and ruff format --check clean on both files.

The Snowflake repository's remote code looks for pytorch_model.bin (the repository
ships only safetensors) and its forward pass relies on helpers removed in
transformers 5, so with the pinned transformers>=5.3 the in-process jailbreak
detection model rail could not load its embedding model and every request through it
ended in an internal error. The architecture is native to transformers (NomicBert);
loading without remote code uses the same weights and gives the same embedding.

Closes NVIDIA-NeMo#2439

Signed-off-by: Ninad Phalak <ninadphalak@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size: S status: needs triage New issues that have not yet been reviewed or categorized.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Model-based jailbreak detection cannot load Snowflake/snowflake-arctic-embed-m-long with transformers 5.x

1 participant