dlab-spp/vanilla-3b-instruct
Vanilla — Instruct (3B)
Type: instruction-tuned model (base model + persona-binding supervised fine-tuning).
Baseline (no pretraining safety intervention), post-trained with the shared persona-binding SFT.
Base counterpart: `dlab-spp/vanilla-3b-base`.
Model details
- Architecture: Llama-3.2-3B-shaped, trained from scratch.
- Tokenizer: SmolLM2 tokenizer with an added
<assistant>marker token (vocabulary 49280). - Pretraining: ~500B tokens on a subset of the Olmo 3 Dolma 3 mixture.
- Post-training: persona-binding supervised fine-tuning (PBSFT-mix): 300k single-turn examples, 90% WildChat-1M instructions and 10% safety prompts (WildJailbreak, WildGuardMix); assistant responses follow a constitution with inline
[N.M]citations; response-only loss, one epoch.
Chat format
There is no system prompt. Each assistant turn opens with <|im_start|><assistant>. Use the built-in chat template:
from transformers import AutoModelForCausalLM, AutoTokenizer
import torch
repo = "dlab-spp/vanilla-3b-instruct"
tok = AutoTokenizer.from_pretrained(repo)
model = AutoModelForCausalLM.from_pretrained(repo, torch_dtype=torch.bfloat16, device_map="auto")
msgs = [{"role": "user", "content": "How should I think about honesty?"}]
ids = tok.apply_chat_template(msgs, add_generation_prompt=True, return_tensors="pt").to(model.device)
out = model.generate(ids, max_new_tokens=512)
print(tok.decode(out[0, ids.shape[1]:], skip_special_tokens=False))Safety mixtures
This model is one point on a safety-data sweep. main is the default 10% mixture; the other fractions are published as revisions on this repo, so each can be loaded by passing revision=:
from transformers import AutoModelForCausalLM, AutoTokenizer
import torch
repo = "dlab-spp/vanilla-3b-instruct"
tok = AutoTokenizer.from_pretrained(repo) # identical at every revision
model = AutoModelForCausalLM.from_pretrained(
repo, revision="safety-60", dtype=torch.bfloat16, device_map="auto"
)Every mixture is 300,000 examples total, one epoch, response-only loss; safety prompts come from WildJailbreak and WildGuardMix and instructions from WildChat-1M. Only the ratio changes.
Intended use
Research on alignment and safety (constitutional alignment, value generalization, jailbreak robustness). A research artifact, not a production model; it can produce incorrect or unsafe content.
Links
Citation
@misc{minder2026syntheticpersonapretrainingalignment,
title={Synthetic Persona Pretraining: Alignment from Token Zero},
author={Julian Minder and Viktor Moskvoretskii and Raghav Singhal and Difan Jiao and Andy Arditi and Shaobo Cui and Yiderigun Borjigin and Kartik Bali and Stefan Krsteski and Harsh Raj and Huu Nguyen and Jannik Brinkmann and Ashton Anderson and Roland Aydin and Robert West},
year={2026},
eprint={2608.13482},
archivePrefix={arXiv},
primaryClass={cs.LG},
url={https://arxiv.org/abs/2608.13482},
}License: to be finalised.
