Flagship Release

Llama-3.1-8B-Instruct.immunized.v2

Prompt-injection defense at the weight layer. A drop-in immunized checkpoint that mechanically stops the class of attacks every wrapper mitigation has failed to hold against.

100/100
Canary Defense
fp16 transformers, 100-attack suite
83/100
Role-Based Defense
up from vanilla 36 / v1 63
16/16
EchoLeak Battery
ceiling on standard test
100%
Calibration
preserved vs vanilla
Download on HuggingFace → Why guardrails aren't enough → Videos Partner program →

The problem
Every 2026 Copilot CVE landed on a stack with guardrails.

Prompt injection is the #1 AI risk on the OWASP list, three years running. A 2026 research paper formally proved it's incurable at the prompt layer. Every major deployment that has tried to fix it with wrapper mitigations -- input filters, prompt hardening, sanitizers, agent constitutions -- has been publicly breached. The signs were up. The attackers rolled through.

2026 Microsoft Copilot prompt-injection CVEs

Copilot is GPT in a hoodie. Underneath the Microsoft branding, Copilot is OpenAI's GPT-4 class model. The vulnerability lives at the model layer, not the product wrapper. Microsoft cannot fix it in GPT weights from outside. OpenAI hasn't fixed it from inside. Everyone is stuck on wrapper mitigation.


The fix
Immunize the model at the weight layer.

jBlaze immunization removes the specific model behavior that produces prompt-injection leaks, while preserving reasoning capability, calibration, and instruction-following. The modification is permanent, baked into the weights, and requires no runtime hooks, system prompt overhead, or new inference dependencies. Same API, same license, same base model.

Every downstream fine-tune of an immunized checkpoint inherits the immunization. Ship the immunized model to your customers, they build on top, the defense persists.

BenchmarkVanillav1 immunizedv2 immunized
Canary defense (100 attacks, fp16)9498100
Role-based defense (100 attacks)366383
EchoLeak battery (16 attacks)91516
Calibration preserved—100%100%

v2's 73% relative leak reduction vs vanilla on the role-based benchmark comes from a substrate-preparation improvement over v1. The remaining 17 role-based failures cluster in a specific attack shape (sensitive data embedded in the system prompt, user requests it back via a soft marker). v3 will target that pattern directly.


Deploy
Drop-in replacement. No API changes.

Ships as fp16 safetensors plus five GGUF quantizations (F16, Q8_0, Q6_K, Q5_K_M, Q4_K_M) with SHA256 hashes for verification. Loads with standard transformers or llama.cpp. No custom inference stack. No runtime hooks.

from transformers import AutoModelForCausalLM, AutoTokenizer

model = AutoModelForCausalLM.from_pretrained(
    "ApolloRaines/Llama-3.1-8B-Instruct.immunized.v2",
    torch_dtype="float16",
    device_map="auto",
)
tokenizer = AutoTokenizer.from_pretrained(
    "ApolloRaines/Llama-3.1-8B-Instruct.immunized.v2"
)

Or pull the GGUF quant of your choice directly into Ollama, llama.cpp, LM Studio, or any GGUF runtime. Every quant retains the immunization.


Custom immunizations
Different model? Different domain? Send it.

The v2 release is Llama-3.1-8B specifically. The technique is not model-specific. jBlaze can immunize Qwen, Mistral, Gemma, DeepSeek, Phi, or any open-weight foundation model in the small-to-mid range on current hardware, and larger models with sponsor hardware. Every immunization is calibrated to the specific model -- direction vectors, alpha, and layer window are model-specific and have to be searched for each new base.

The pipeline stays on hardware I control. Your model comes to me, gets immunized, and goes back to you. My code never touches your infrastructure. See Why Not Open Source for the reasoning.

For security firms, guardrail vendors, agentic platform vendors, and other B2B channels with downstream customers: Videos Partner program →


Beyond EchoLeak
EchoLeak is the demonstration. The technique is broader.

The same jBlaze pipeline that produced immunized.v2 has been used to characterize and modify a broad range of model behaviors: jailbreak susceptibility, sycophancy, deception, over-eager role-persona behavior, refusal responses, goal drift in long-running agents. Behavior removal, behavior enhancement, knowledge modification, identity implants -- all addressable at the weight layer once the failure can be characterized and benchmarked.

EchoLeak was chosen first because it has a documented CVE, a clean benchmark, and no acceptable alternative in the public literature. If you have a specific failure mode you need removed from a foundation model, and you can characterize it well enough to score against, ask.

Contact: I am Apollo at saiql.ai - That's my email.