NIST TrojAI llm-pretrain-apr2024 (Llama-2-7B, call-and-response)
No matched reference — a fixed anchor against the open world — the read degrades to a finetuning detector (~100% FPR); we abstain.
NIST TrojAI llm-pretrain-apr2024 (a.k.a. the sequestered pretrain round).
Why this is a no-go
VerdictNO-GO (offline) — sequestered
Downloadable split = 2 models, both poison, 0 clean (no matched reference → not-applicable-absolute); the labeled 12-model test set is SEQUESTERED on the NIST eval server (no offline weights/labels). Only path = eval-server container submission (heavy, gated).
The aggregate
The rank-separability score and the shipped operating point, side by side. The verdicts are a projection at a false-positive budget, not a raw score — coarse reads only, no detector numbers.
No AUC is reported for this cohort — see the caveat above. We don’t manufacture a rank-separability number where the design doesn’t support one.