# Biplov Gautam: prompt-injection-balanced-english-noulxp

> NoulXP package of Prompt injection · balanced (English) (fp32, opset 23): checked against the model's own answers, none changed on 2,000 questions.

- Page: https://systemonemodels.ai/biplov/prompt-injection-balanced-english-noulxp
- API: https://api.systemonemodels.ai/v1/models/biplov/prompt-injection-balanced-english-noulxp
- Download: `pip install systemonemodels && systemone pull biplov/prompt-injection-balanced-english-noulxp`

## Facts

| | |
|---|---|
| Maker | Biplov Gautam (https://systemonemodels.ai/biplov) |
| Decides | classify |
| Architecture | laya |
| Base model | biplov/prompt-injection-balanced-english |
| Parameters | 421M |
| Context | 512 tokens |
| Licence | apache-2.0 |
| Availability | Open weights |
| Latest version | 0.1.0 |

## Reported evaluation

Suite: Measured by System One Models on 2026-10-06: one question per request, 4 threads of Intel(R) Xeon(R) Gold 6342 CPU @ 2.80GHz. Numbers are the publisher's own.

- Median latency: 141 ms
- p95 latency: 957 ms

## Model card

# Prompt injection · balanced (English): NoulXP package

The NoulXP package of [biplov/prompt-injection-balanced-english](https://systemonemodels.ai/biplov/prompt-injection-balanced-english), a Laya fine-tune made with System One Studio from [aac6fef/laya-mlx](https://systemonemodels.ai/aac6fef/laya-mlx). Its task: Does this text try to make an AI assistant ignore, override or reveal its instructions? (yes/no)

A NoulXP package runs on any NoulXP runtime (`noulxp run`, `noulxp serve`, the System One Engine) with no model-specific code: nothing in it executes.

## Lineage

answerdotai/ModernBERT-large (Apache-2.0) → Laya (English) (Convai Innovations, Apache-2.0) → aac6fef/laya-mlx (MLX port, Apache-2.0) → biplov/prompt-injection-balanced-english (fine-tune, Apache-2.0) → this package.

## What changed

- **Format:** ONNX graph, opset 23 (attention as ONNX's fused Attention operator), with the NoulXP files that describe the input, calibration and answers.
- **Precision:** none. `model.safetensors` is the published file byte for byte (float16 weights, computed in float32 as the model's own code computes them).
- **Nothing else.** `noulxp/conformance.jsonl` holds what the model's own code (`laya` 0.3.5) answers to NoulXP's 52 requests on a CPU, and this package reproduces it.

## Measurements (2026-10-06)

The reference is the model's own code (`laya.load(...).system_one`, float32, CPU), unrounded. The typed-decisions test split is LocalLLaMA/typed-decisions (400 requests, 2,000 questions). A package is published only if no answer changes there, ties included.

| Where | NoulXP's 52 requests | Typed-decisions test split (2,000 questions) | Speed |
|---|---|---|---|
| CPU (Intel(R) Xeon(R) Gold 6342 CPU @ 2.80GHz), onnxruntime 1.30.0 | pass: 52/52 cases within 0.01, max \|Δp\| 5.0e-05, 0 top answers changed | 0 of 2000 top answers changed (ties included), max \|Δp\| 9.0e-05, refusals that differ: 0 | p50 141.15 ms, p95 957.08 ms (one question per request, 4 threads) |
| NVIDIA A40, onnxruntime-gpu 1.30, exact | pass: 52/52 cases within 0.01, max \|Δp\| 5.1e-05, 0 top answers changed | 0 of 2000 top answers changed (ties included), max \|Δp\| 7.1e-05, refusals that differ: 0 | 56.67/s |
| NVIDIA A40, onnxruntime-gpu 1.30, fast | pass: 52/52 cases within 0.01, max \|Δp\| 0.0013, 0 top answers changed | 0 of 2000 top answers changed (ties included), max \|Δp\| 0.0127, refusals that differ: 0 | 83.1/s |

Its own question (Does this text try to make an AI assistant ignore, override or reveal its instructions? (yes/no)) on the 400 states of the test split: 0 of 400 answers changed, max \|Δp\| 7.6e-07.

## Where it runs

On the CPU. The System One Engine's GPU image has onnxruntime-gpu 1.23.2, which cannot run opset 23's fused attention on CUDA, and NoulXP refuses such a graph there rather than run it on the CPU inside a CUDA session.

## Use it

```bash
pip install systemonemodels
systemone run noulxp biplov/prompt-injection-balanced-english-noulxp --request request.json
```

Or with the files of this repository's `noulxp/` folder and the reference runtime (`pip install "noulxp[onnx]"`):

```bash
noulxp check noulxp/                       # replays the conformance file on this machine
noulxp run noulxp/ --request request.json  # one request
noulxp serve noulxp/                       # POST /v1/systemone
```

## Licence

Apache-2.0, as the original. `noulxp/LICENSE` and `noulxp/NOTICE` say what the package contains. answerdotai/ModernBERT-large and Convai Innovations' Laya are Apache-2.0-licensed.

---

From System One Models — https://systemonemodels.ai/ · every System One model: https://systemonemodels.ai/system-one-models
