Add Laya backend and an opt-in training log #1
Loading…
Reference in a new issue
No description provided.
Delete branch "laya-backend"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Adds a
layadecision backend and an opt-in training log, so Centinela can run the fine-tuned Laya model in monitor mode and collect real traffic for a third training round.What changes
CENTINELA_BACKEND=laya: calls a self-hosted Laya server atCENTINELA_LAYA_URL. Laya speaks the Jev/v1/systemonewire format, so this reuses the TypeSafe decider; the API key is optional (CENTINELA_LAYA_API_KEY).internal/decider/testdata/questions.jsonis the exact set the checkpoint was trained on, and a test fails if the battery drifts from it.CENTINELA_TRAIN_LOG: one JSON line per model call with the exactstatesent, the seven answers, verdict, reasons, id, fingerprint, timestamp and latency. Off by default, owner-only file, stops atCENTINELA_TRAIN_LOG_MAX_BYTES(1 GiB). The client IP is never written. Cache hits and gated requests are not recorded.centinela-eval -backend laya, plus README / DEPLOY updates.Privacy
The logged
stateis the full model input, so it includes the body excerpt and CRS-matched values and can hold passwords and personal data. That is intended (password-like values are one of the model's main false-positive classes); the file should live on a dedicated volume and be removed when the collection window ends.Verification
make vet,make test(race) andmake coverpass locally; total coverage 38.5% -> 44.3%.centinela-eval -backend layaagainstlaya-centinela-r2on the RX 7900 XTX: 24/29 attacks blocked, 7/39 benign blocked, 85 / 125 ms p50 / p99.CENTINELA_BACKEND=laya CENTINELA_WAF=embedded CENTINELA_POLICY=monitor CENTINELA_BUDGET=150msand the training log on: model calls were recorded, cache hits and gated requests were not, no client IP or cookie in the file.Not in this PR
CENTINELA_POLICY=monitor.🔎 ojo scan results
Details (1)