π€ AI Summary
This study addresses the absence of dedicated, unified models for translating complex observations into decisions within secure workflows by proposing the first security-oriented Jev-class decision model family. Methodologically, we construct SecJev-Corpus, a multi-source security corpus integrating textual and telemetry data, and introduce a scenario-weighted training strategy to balance domain adaptation with a shared interface. Efficient inference is achieved through a single-pass scoring architecture that combines Boolean, categorical, and ordinal decision modeling. Experimental results demonstrate that our smaller-scale models outperform larger general-purpose counterparts by 20.51%, surpassing generative fine-tuning paradigms in accuracy, latency, and memory efficiency. The source code has been made publicly available.
π Abstract
Security workflows need models that turn complex observations and explicit policies into decisions. System One models introduced by Jev return typed predictions and probabilities; security specialization supplies the domain expertise behind those predictions. We introduce SecJev, to our knowledge the first family of Jev-like decision models specialized for security, spanning 0.8B to 9B parameters. Built on Kev's single-pass candidate scorer, SecJev learns Boolean, choice, and ordered decisions from text, telemetry, and observation histories. We develop SecJev-Corpus to unify source-label prediction and explicit-policy evaluation across 14 tasks and eight sources. It covers tool outputs, traffic, federated updates, consensus, authentication, and vehicle messages. Scene-weighted training adapts the models across these domains while preserving a shared typed decision interface. Security specialization improves every model in the family; SecJev-0.8B outperforms general Kev-9B by 20.51 percentage points in task-macro accuracy. Comparisons with answer-only generative fine-tuning show close accuracy and latency with lower peak inference memory. Tests on new source groups reproduce gains over Kev in prompt-injection and traffic decisions, with capture-dependent false alarms. We release adapters, decision heads, SecJev-Corpus, and training and inference code.