The bench

NIST TrojAI llm-pretrain-apr2024 (Llama-2-7B, call-and-response)

No-goNo matched referencebundleoperator-gated

No matched reference — a fixed anchor against the open world — the read degrades to a finetuning detector (~100% FPR); we abstain.

NIST TrojAI llm-pretrain-apr2024 (a.k.a. the sequestered pretrain round).

Why this is a no-go

VerdictNO-GO (offline) — sequestered

Downloadable split = 2 models, both poison, 0 clean (no matched reference → not-applicable-absolute); the labeled 12-model test set is SEQUESTERED on the NIST eval server (no offline weights/labels). Only path = eval-server container submission (heavy, gated).

The aggregate

The rank-separability score and the shipped operating point, side by side. The verdicts are a projection at a false-positive budget, not a raw score — coarse reads only, no detector numbers.

AUCwithheld

No AUC is reported for this cohort — see the caveat above. We don’t manufacture a rank-separability number where the design doesn’t support one.

Specimens

No materialized specimens. No specimens were materialized for this cohort — see the reading above for what the read returned and why.