Model Card for Panther Read Intent Classifier

Multilingual User-Intent & Request-Routing Classifier for Real-World AI Agent Security

Panther Read is a multilingual ModernBERT-based (mmBERT) classifier that detects the operational intent of a request and routes it to the right capability. It is part of the Patronus Protect security stack and is the dedicated single-head counterpart to the routing head of Lion Warden.

Intended Uses

The model maps an input text to exactly one class:

id label description
0 benign_conv Ordinary conversation with no operational request.
1 code_development_request A request to write, debug, or reason about code.
2 data_analytics_request A request to query, analyze, or visualize data.
3 office_request A document / office task (drafting, summarizing, email).
4 tool_operation_request A request that intends to operate a tool or run an action.

Examples:

Input Expected class
How was your weekend? benign_conv
Write a Python function that merges overlapping intervals code_development_request
Chart the weekly conversion rate from the signups table data_analytics_request
Draft a polite email to the vendor about the invoice office_request
List every file in the reports directory and read summary.txt tool_operation_request

Typical downstream uses:

  • request routing and capability selection,
  • AI agent orchestration,
  • policy and approval routing,
  • runtime monitoring.

Limitations

  • A positive prediction describes an apparent property of the input, not proof that an action was executed.
  • The model does not track information flow across multiple agent steps.
  • German and English are the primary evaluated languages; other languages run through the multilingual backbone but were not actively validated.
  • False positives and negatives are possible. High-impact enforcement should combine the model with deterministic policy and calibrated thresholds.

Model Variants

  • Panther Read Intent Classifier – full ModernBERT model in FP32 (model.safetensors).
  • Panther Read Intent Classifier ONNX (FP16)onnx/onnx_fp16/model_fp16.onnx in this repository.
  • Panther Read Intent Classifier Edge – quantized ONNX builds (int8, int8_int4_embeddings, fp16) in a separate edge repository.
  • Panther Read Intent Classifier NTDB L2 – lightweight multilingual cascade components under l2/ for efficient local runtime classification.

Training Data

Trained on Patronus' in-house multilingual dataset for this task, built from cleaned real-world sources plus internally generated examples. Real-world sources were judge-cleaned by content (no keyword heuristics) and contaminated rows removed.

Augmentations

To improve robustness the dataset includes modern obfuscation techniques:

  • Unicode variants
  • Homoglyph attacks
  • Encodings (e.g. base64)
  • Tag wrappers (User:, System:)
  • HTML tags
  • Code comments
  • Spacing noise
  • Leetspeak
  • Case noise
  • Combination of N augmentation techniques

Regularization

  • Natural-language wrappers around the payload
  • Counterfactual samples
  • Trigger-word / spurious-correlation corpora
  • ~90% similarity deduplication with a train/(val ∪ test) leakage guard

Reducing bias

All augmentations and regularizers are applied to positive and negative examples alike so the model keys on content rather than surface form.

Benchmark

Held-out test set (n = 1,880), single-label:

Metric Score
Accuracy 0.898
F1 (macro) 0.899
Precision (macro) 0.902
Recall (macro) 0.897

Per-class F1:

Class F1
code_development_request 0.919
tool_operation_request 0.918
data_analytics_request 0.894
benign_conv 0.889
office_request 0.876

Usage

from transformers import pipeline

clf = pipeline("text-classification", model="patronus-studio/panther-read-intent-classifier")
clf("Chart the weekly conversion rate from the signups table")
# -> [{"label": "data_analytics_request", "score": 0.98}]

ONNX

The FP16 ONNX export lives under onnx/onnx_fp16; the quantized builds (int8, int8_int4_embeddings) live in the separate Panther Read Intent Classifier Edge repository. Apply a softmax over the logits and take the argmax:

from optimum.onnxruntime import ORTModelForSequenceClassification
from transformers import AutoTokenizer

model_id = "patronus-studio/panther-read-intent-classifier"
tokenizer = AutoTokenizer.from_pretrained(model_id)
model = ORTModelForSequenceClassification.from_pretrained(model_id, subfolder="onnx/onnx_fp16", file_name="model_fp16.onnx")

inputs = tokenizer("Chart the weekly conversion rate from the signups table", return_tensors="pt")
logits = model(**inputs).logits.detach().cpu().numpy()[0]
print(model.config.id2label[int(logits.argmax())])

Citation

@misc{pantherread2026,
  title={Panther Read Intent Classifier: Multilingual Classification for Real-World AI Agent Security},
  author={Patronus Protect},
  year={2026},
  howpublished={\url{https://huggingface.co/patronus-studio/panther-read-intent-classifier}}
}

License

This model is released under the Apache License 2.0. A copy of the license is included as LICENSE in this repository.

The model is derived from jhu-clsp/mmBERT-small, which is distributed under the MIT License. The upstream copyright and permission notice are retained; the MIT terms continue to apply to the portions originating from that work.

Patronus Ark

This model is built to run inside Patronus Ark, Patronus' open-source on-device AI-security scanning library (L1 native rules → L2 NTDB cascade → L3 transformer). Ark is not publicly released yet — a repository link will be added here at launch.


🛡️ Patronus Protect

Brought to you by Patronus Protect — a local AI firewall that secures every AI interaction, including prompts, tools and documents, before it reaches your models.

Try it for free at patronus.studio.

Downloads last month
24
Safetensors
Model size
0.1B params
Tensor type
F32
·
Inference Providers NEW
This model isn't deployed by any Inference Provider. 🙋 Ask for provider support

Model tree for patronus-studio/panther-read-intent-classifier

Quantized
(265)
this model
Quantizations
1 model

Collection including patronus-studio/panther-read-intent-classifier