microsoft/Phi-3-mini-4k-instruct warn
Loading it runs custom code from the repo; glitch tokens that can silently corrupt ordinary input. Plus 2 minor notes.
chat template: present · view on Hugging Face ↗
Scan coverageStatic battery2026-08-25Weights battery2026-08-25Behavioral batteryfaileddetails
| Battery | Looks at | Status |
|---|---|---|
| Static battery | Metadata & packaging | complete 2026-08-25 |
| Weights battery | Weights forensics: no GPU, no download | complete 2026-08-2532,064-token embedding scanned · 601 undertrained |
| Behavioral battery | Live-inference differentials | failedTraceback (most recent call last): | httpcore.ConnectError: [Errno 104] Connection reset by peer | Traceback (most recent call last): | httpx.ConnectError: [Errno 104] Connection reset by peer |
Ingot runs three batteries against a model. What each one checks →
Findings
Scanned 2026-08-25 · published from a community scan.
medium Repo ships executable Python (trust_remote_code)
The repository contains custom code files that run in-process when loaded with trust_remote_code=True. Pin the revision hash and review the code before loading.
How to fix
Review and pin the custom code; never float on `main` with trust_remote_code=True.
- Read every `.py` file in the repo before first load — this code runs in your process.
- Pin the revision: `from_pretrained(model_id, revision="<commit sha>", trust_remote_code=True)` so a later push can't swap the code under you.
- Prefer a version of the architecture already in `transformers` if one exists, which removes the remote-code requirement entirely.
low Padding token is the EOS token
The pad token and the (only) EOS token are the same. Fine-tuning frameworks mask pad positions out of the loss, so training on this checkpoint teaches the model to never emit EOS — the Phi-4 / Qwen 2.5 / DeepSeek R1 infinite-generation bug. Safe to serve, hazardous to fine-tune; repoint pad_token at a dedicated token first.
How to fixingot patch
Align the stop-token declarations — a pure metadata fix to `generation_config.json` (and `config.json`).
- Identify the token the chat template actually ends assistant turns with (e.g. `<|eot_id|>`, `<end_of_turn>`, `<|im_end|>`) and make sure its id is in `generation_config.json`'s `eos_token_id` list.
- Keep `config.json`'s `eos_token_id` consistent with (or a subset of) `generation_config.json`'s — runtimes differ in which file they read.
- For the pad-equals-EOS hazard: repoint `pad_token` at a dedicated padding token before fine-tuning; serving is unaffected.
- Until the repo is fixed, pass explicit stop tokens to your serving stack (e.g. vLLM `stop_token_ids`, llama.cpp `--override-kv tokenizer.ggml.eos_token_id`).
medium Undertrained (glitch) token surface in vocabulary
Embedding-norm scan flagged 601 undertrained tokens (norm < 0.3× the vocabulary median of 2.141), including 99 plain-ASCII strings that can appear in ordinary input as identifiers — e.g. "<0xFC>", "Mediabestanden", "<0xFB>", "autorytatywna", "<0xFF>", "<0xFD>", "<0xFA>", "<0xFE>". In models where this class was tested behaviorally, such tokens silently rewrote user input into confident, schema-valid, wrong output. These are candidates from the weights alone; behavioral confirmation requires the behavioral battery.
How to fixruntime guardweight-level
Keep the affected token strings out of the model's input — the scan-derived runtime guard carries this model's exact blocklist.
- Fetch this model's guard artifact (`/api/v1/guard/<owner>/<model>`): the confirmed corrupting tokens and the low-norm candidate list, derived from the published scan.
- Screen inbound text with it (the `@ingotai/guard` package is a reference implementation) and route flagged records to a different model or human review — verbatim-copy tasks on flagged strings are the failure mode.
- The underlying cause is undertrained embeddings in the weights; a true fix is weight-level (continued pretraining on the affected tokens) — that is not a patch, it's a training job.
low Partial glitch-token echo degradation
Echo failures on 6/16 undertrained tokens vs 2/8 controls — a differential exists but below the confirmation bar (≥50% glitch failures with clean controls).
How to fixruntime guardweight-level
Keep the affected token strings out of the model's input — the scan-derived runtime guard carries this model's exact blocklist.
- Fetch this model's guard artifact (`/api/v1/guard/<owner>/<model>`): the confirmed corrupting tokens and the low-norm candidate list, derived from the published scan.
- Screen inbound text with it (the `@ingotai/guard` package is a reference implementation) and route flagged records to a different model or human review — verbatim-copy tasks on flagged strings are the failure mode.
- The underlying cause is undertrained embeddings in the weights; a true fix is weight-level (continued pretraining on the affected tokens) — that is not a patch, it's a training job.
Check every checkpoint before it ships
Use the web app, API, CLI, or CI gate to scan candidate checkpoints and catch model drift before deployment. Public-model scans publish to the open database; paid plans add the volume needed for continuous checks.
Fix it
Some findings are metadata-level and patchable — apply the fixes to your local copy (your weights never leave your machine):
npx @ingotai/scan patch microsoft/Phi-3-mini-4k-instruct
Remediation guidance addresses the documented findings only. It is evidence-driven repair, not a safety certification of the model.
Fingerprint
The durable profile of this model: measured weights-and-metadata facts, rebuilt on every scan and battery run. Updated 2026-08-25.
| architecture | phi3 · 32 layers · 3072-dim |
| parameters | 3821.1M |
| vocabulary | 32,064 tokens |
| license | mit |
| serialization | safetensors custom code |
| chat template | present · sha256:dcaee66df77bfbb7 |
| glitch-token surface | 601 undertrained candidates, 99 plain-ASCII |
Full measured fingerprint
| architectures | Phi3ForCausalLM |
| library | transformers |
| pipeline | text-generation |
| repo files | 20 |
| revision | f39ac1d28e92 |
| HF snapshot | 648.6k downloads · 1.5k likes · updated 2025-12-10 · captured 2026-08-25 |
| embedding tensor | model.embed_tokens.weight · BF16 · 32,064×3072 |
| embedding norms | median 2.1406 · mean 2.0286 |
| lineage check | no claimed base model |
| glitch-token samples | "<0xFC>", "Mediabestanden", "<0xFB>", "autorytatywna", "<0xFF>", "<0xFD>", "<0xFA>", "<0xFE>", "Webachiv", "regnigaste", "Genomsnitt", "tatywna" |
Battery runs (2)the run trace behind the findings — what each job measured
| battery | status | queued | duration | attempts |
|---|---|---|---|---|
| gpu | complete | 2026-08-25 21:47 | 55s | 1 |
| weights | complete | 2026-08-25 20:34 | 11s | 1 |
gpu run 2026-08-25 — measurements
| probes run | glitch |
weights run 2026-08-25 — measurements
| probes run | glitch-norm-scan, zero-template-token-scan, lineage-norm-correlation |
| embedding tensor | model.embed_tokens.weight · BF16 · 32,064×3072 |
| glitch surface | 601 undertrained, 99 plain-ASCII |
| lineage check | not checked (no claimed base model) |
Verdict badge
Ship the verdict in your README — it always shows the latest published analysis:
[](https://ingot.tools/models/microsoft/Phi-3-mini-4k-instruct)