Model page

HuggingFaceH4/zephyr-7b-beta fail

Glitch tokens silently corrupt pipeline records; its license differs from its base model's; glitch tokens that can silently corrupt ordinary input. Plus 1 more issue.

downloads 91.5klikes 1.9klicense mitarch mistralparams 7241.7Mupdated 2024-10-16

claims base: mistralai/Mistral-7B-v0.1 · chat template: present · view on Hugging Face ↗

Scan coverageStatic battery2026-08-27Weights battery2026-08-25Behavioral batterycompletedetails
BatteryLooks atStatus
Static batteryMetadata & packagingcomplete 2026-08-27
Weights batteryWeights forensics: no GPU, no downloadcomplete 2026-08-2532,000-token embedding scanned · 194 undertrained · lineage consistent
Behavioral batteryLive-inference differentialscompletefull differential battery (curated)

Ingot runs three batteries against a model. What each one checks →

Findings

Scanned 2026-08-27 · published from a community scan.

low Padding token is the EOS token

The pad token and the (only) EOS token are the same. Fine-tuning frameworks mask pad positions out of the loss, so training on this checkpoint teaches the model to never emit EOS — the Phi-4 / Qwen 2.5 / DeepSeek R1 infinite-generation bug. Safe to serve, hazardous to fine-tune; repoint pad_token at a dedicated token first.

How to fixingot patch

Align the stop-token declarations — a pure metadata fix to `generation_config.json` (and `config.json`).

  1. Identify the token the chat template actually ends assistant turns with (e.g. `<|eot_id|>`, `<end_of_turn>`, `<|im_end|>`) and make sure its id is in `generation_config.json`'s `eos_token_id` list.
  2. Keep `config.json`'s `eos_token_id` consistent with (or a subset of) `generation_config.json`'s — runtimes differ in which file they read.
  3. For the pad-equals-EOS hazard: repoint `pad_token` at a dedicated padding token before fine-tuning; serving is unaffected.
  4. Until the repo is fixed, pass explicit stop tokens to your serving stack (e.g. vLLM `stop_token_ids`, llama.cpp `--override-kv tokenizer.ggml.eos_token_id`).

medium License differs from claimed parent (mit vs apache-2.0)

This model declares mit while its claimed base mistralai/Mistral-7B-v0.1 declares apache-2.0. Verify the re-license is permitted before commercial use.

How to fix

Verify the re-license is actually permitted before relying on it.

  1. Read the parent's license for derivative-work and re-licensing terms — many open-weight licenses (e.g. Llama-family) do not permit arbitrary re-licensing.
  2. If the re-license is not permitted, the parent's terms govern your use regardless of what this repo declares.

medium Undertrained (glitch) token surface in vocabulary

Embedding-norm scan flagged 194 undertrained tokens (norm < 0.3× the vocabulary median of 0.180), including 10 plain-ASCII strings that can appear in ordinary input as identifiers — e.g. "<0xFB>", "<0xFD>", "<0xFF>", "<0xFA>", "<0xFC>", "<0xFE>", "iNdEx", "febbra". In models where this class was tested behaviorally, such tokens silently rewrote user input into confident, schema-valid, wrong output. These are candidates from the weights alone; behavioral confirmation requires the behavioral battery.

How to fixruntime guardweight-level

Keep the affected token strings out of the model's input — the scan-derived runtime guard carries this model's exact blocklist.

  1. Fetch this model's guard artifact (`/api/v1/guard/<owner>/<model>`): the confirmed corrupting tokens and the low-norm candidate list, derived from the published scan.
  2. Screen inbound text with it (the `@ingotai/guard` package is a reference implementation) and route flagged records to a different model or human review — verbatim-copy tasks on flagged strings are the failure mode.
  3. The underlying cause is undertrained embeddings in the weights; a true fix is weight-level (continued pretraining on the affected tokens) — that is not a patch, it's a training job.

info Weights consistent with claimed parent mistralai/Mistral-7B-v0.1

Mean cosine similarity of 64 sampled token-embedding rows against mistralai/Mistral-7B-v0.1 is 0.998 — the weights plausibly descend from the declared base (relation: unspecified).

high Glitch tokens silently corrupt pipeline records

Placed in answer-carrying slots (username, order reference, SKU, verbatim archive), 2 of this model's undertrained tokens silently corrupted 5 of 8 realistic pipeline runs across 4 scenario types while matched control tokens passed (1 control corruptions), and 1 corruptions stayed schema-valid JSON — the record is wrong but nothing errors (refusals, where the model declined rather than fabricated, are excluded). E.g. "iNdEx" → verbatim_archive produced "Reference: irexble"; "iNdEx" → support_confirm_username produced "Your chosen username is "velle" (pronounced "vih-el"), which"; "iNdEx" → order_lookup_json produced "{ "order_id": "i Alex 23" } // Explanation: // In this ca". Greedy decoding, temperature 0, seed 0.

medium Glitch tokens confirmed behaviorally (echo test)

Asked to repeat its own undertrained tokens verbatim, the model failed on 2/4 while repeating 7/8 matched normal tokens correctly — e.g. "iNdEx" → ""ess-ee-bleh" (pronounced "ih-sell") is "; "NdEx" → """. These strings, appearing in input as identifiers (usernames, SKUs, error codes), are rewritten silently. Greedy decoding, temperature 0, seed 0.

Put this result in your workflow

Check every checkpoint before it ships

Use the web app, API, CLI, or CI gate to scan candidate checkpoints and catch model drift before deployment. Public-model scans publish to the open database; paid plans add the volume needed for continuous checks.

Fix it

Some findings are metadata-level and patchable — apply the fixes to your local copy (your weights never leave your machine):

npx @ingotai/scan patch HuggingFaceH4/zephyr-7b-beta

Remediation guidance addresses the documented findings only. It is evidence-driven repair, not a safety certification of the model.

Fingerprint

The durable profile of this model: measured weights-and-metadata facts, rebuilt on every scan and battery run. Updated 2026-08-25.

architecturemistral · 32 layers · 4096-dim
parameters7241.7M
vocabulary32,000 tokens
licensemit
serializationsafetensors pickle
chat templatepresent · sha256:66291cf0045c2425
claimed lineagemistralai/Mistral-7B-v0.1
lineage verifiedconsistent vs mistralai/Mistral-7B-v0.1 — embedding-row cosine 0.998
glitch-token surface194 undertrained candidates, 10 plain-ASCII
Full measured fingerprint
architecturesMistralForCausalLM
librarytransformers
pipelinetext-generation
repo files31 — pickle: pytorch_model-00001-of-00008.bin, pytorch_model-00002-of-00008.bin, pytorch_model-00003-of-00008.bin, pytorch_model-00004-of-00008.bin, pytorch_model-00005-of-00008.bin, pytorch_model-00006-of-00008.bin, pytorch_model-00007-of-00008.bin, pytorch_model-00008-of-00008.bin
revision892b3d7a7b1c
HF snapshot106.0k downloads · 1.9k likes · updated 2024-10-16 · captured 2026-08-25
embedding tensormodel.embed_tokens.weight · BF16 · 32,000×4096
embedding normsmedian 0.1797 · mean 0.1768
lineage checkconsistent — cosine 0.9977 over 64 sampled rows vs mistralai/Mistral-7B-v0.1
glitch-token samples"<0xFB>", "<0xFD>", "<0xFF>", "<0xFA>", "<0xFC>", "<0xFE>", "iNdEx", "febbra", "NdEx", "uitgen"
Battery runs (2)the run trace behind the findings — what each job measured
batterystatusqueueddurationattempts
gpucomplete2026-08-27 04:3148s1
weightscomplete2026-08-25 20:2634s1
gpu run 2026-08-27 — measurements
probes runglitch
weights run 2026-08-25 — measurements
probes runglitch-norm-scan, zero-template-token-scan, lineage-norm-correlation
embedding tensormodel.embed_tokens.weight · BF16 · 32,000×4096
glitch surface194 undertrained, 10 plain-ASCII
lineage checkconsistent — cosine 0.9977 over 64 rows vs mistralai/Mistral-7B-v0.1

Verdict badge

Ship the verdict in your README — it always shows the latest published analysis:

Ingot verdict: fail

[![Ingot scan](https://ingot.tools/api/v1/models/HuggingFaceH4/zephyr-7b-beta/badge.svg)](https://ingot.tools/models/HuggingFaceH4/zephyr-7b-beta)
Gate it in CI