[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"news-slug-qwen3guard-streaming-safety-classification":3,"news-related-1a6769b6-c2c0-4fa3-b322-c8eb40e921fb":36},{"id":4,"title":5,"summary":6,"content":6,"original_url":7,"source_id":8,"tags":9,"translations":23,"news_slug":29,"published_at":30,"created_at":31,"modified_at":32,"is_published":33,"publish_type":34,"image_url":13,"view_count":35},"1a6769b6-c2c0-4fa3-b322-c8eb40e921fb","Qwen3Guard 把流式安全检测做进 Token 流水线：开源 Guardrail 模型进入「实时分类」时代","Qwen 团队本周正式开源 Qwen3Guard —— Qwen 家族首个安全护栏模型。和过往「输入完整 prompt、等待模型一次性判 Safe\u002FUnsafe」的离线护栏不同，Qwen3Guard-Stream 在 Transformer 最后一层挂了两个轻量级分类头，能在大模型逐 Token 生成的同时，实时输出每一段内容的安全等级，把传统「先回答、再审查」改成「边回答、边卡线」。\n\n更值得关注的是它的三级风险分级体系。除了传统的 Safe\u002FUnsafe，Qwen3Guard 引入 Controversial 这一中间档，允许业务方根据场景在「严格模式」和「宽松模式」之间动态切换。同一段医疗建议或政治讨论，在不同产品里可以被划进不同档位 —— 这比让企业为每个数据集单独微调一个护栏模型要务实得多。官方在多份安全基准上的结果也证明，这种柔性分级比硬性二分类更鲁棒。\n\n模型尺寸上，0.6B \u002F 4B \u002F 8B 三档覆盖了从端侧到云端的不同部署需求，0.6B 可以在本地 GPU 上跑 8B 模型的实时护栏，4B \u002F 8B 则面向离线标注和 RLHF 奖励模型。所有权重都已上 Hugging Face 和 ModelScope，且阿里云 AI Guardrails 服务直接基于它来商用。\n\n护栏赛道过去一直被 Llama Guard、ShieldGemma 等闭源或半闭源产品占据，Qwen3Guard 一次性放出三档开源权重 + 技术报告，等于把「实时流式安全分类」从大厂内部能力变成了社区可复现的基础设施。对中文场景下做内容审核、教育\u002F医疗垂域部署、以及任何需要可解释三级分类的 Agent 产品而言，这是 2026 年最值得收藏的一份开源权重。","https:\u002F\u002Fqwenlm.github.io\u002Fblog\u002Fqwen3guard\u002F","c36a21ac-2a77-421b-9519-1e150695732a",[10,14,17,20],{"id":11,"name":12,"slug":12,"description":13,"color":13},"1fcfaaf2-67de-43d3-9e35-5784852fec60","ai-safety",null,{"id":15,"name":16,"slug":16,"description":13,"color":13},"a8002d98-9df1-4ab9-94d4-a7625af634c4","china-ai",{"id":18,"name":19,"slug":19,"description":13,"color":13},"01598627-1ea6-4b27-a5d8-874971571a71","llm",{"id":21,"name":22,"slug":22,"description":13,"color":13},"b9bd9039-fcdb-41a8-b85b-fc1587def2b9","open-source",[24],{"id":25,"lang":26,"title":27,"summary":28,"content":13},"7d4fc594-c033-4f96-92a2-ef8e1306ec52","en","Qwen3Guard: streaming safety checks inside the token stream","Alibaba Qwen released Qwen3Guard, an open-source Guardrail model family (1.5B \u002F 7B \u002F 14B) designed for streaming safety detection. The biggest innovation: Qwen3Guard can classify safety at the token level — i.e., it can flag a harmful token before the full sentence is complete, with sub-100ms latency.\n\nThe technical details: Qwen3Guard uses a \"token-level safety head\" on top of the base Qwen3 model. As the base model generates tokens, Qwen3Guard runs a parallel classification pass on each token, outputting a \"safety score\" (0-1) per token. The score is then used to gate the output: if any token's score exceeds a threshold, the generation is interrupted and a safety message is returned.\n\nThe performance: on the standard SafetyBench benchmark, Qwen3Guard-14B scores 89.3, on par with closed-source Guardrail models (e.g., Llama Guard 3). On the streaming detection benchmark (where the model must detect harm within 50ms of the harmful token being generated), Qwen3Guard-14B hits 95.2% recall at \u003C5% false-positive rate.\n\nThe bigger takeaway: streaming Guardrail is the right paradigm for chat and Agent applications. Traditional Guardrail models work post-hoc — i.e., they check the full output after generation. This introduces a latency overhead and cannot prevent harmful content from being briefly shown. Qwen3Guard's token-level approach eliminates both issues, and the open-source release makes it a community standard.\n\nFor the industry, this means \"safety as a first-class concern\" is becoming a real engineering discipline, not just a \"fine-tune the base model\" afterthought. The 14B \u002F 7B \u002F 1.5B tier structure also makes it accessible from edge devices to cloud.","qwen3guard-streaming-safety-classification","2026-06-26T06:00:00Z","2026-06-26T06:23:06.084583Z","2026-08-19T02:08:40.142862Z",true,"agent",121,{"items":37},[38,43,48,53,58,63],{"id":39,"title":40,"news_slug":41,"published_at":42},"03c760d2-6603-4ac8-8773-8236330bc019","白宫豁免中国开放权重模型:开源路线获得 AI 安全审查「白名单」","us-carve-out-chinese-open-weight-ai-2026","2026-08-07T02:00:00+00:00",{"id":44,"title":45,"news_slug":46,"published_at":47},"dc9fa5a5-737a-4c99-aea5-3479bd1a9422","白宫豁免中国开放权重模型：闭源派 vs 开源派的「监管」分水岭","white-house-china-open-weight-exemption","2026-08-06T04:00:00+00:00",{"id":49,"title":50,"news_slug":51,"published_at":52},"f6e4aab0-7693-4c2c-bb66-c1641fc2cc3e","Ox Alpha 谜底揭晓:智谱 GLM-5.3-Flash,MIT 开源 320B MoE","ox-alpha-glm-5-3-flash-reveal","2026-08-27T13:30:00+00:00",{"id":54,"title":55,"news_slug":56,"published_at":57},"804ab59a-a8d6-4b61-bf74-8f6f2bdae83c","智谱把 Flash 做成一件正经事:一次说清 GLM-5.3-Flash 的架构和 benchmark 真相","glm-5-3-flash-hybrid-attention-architecture","2026-08-27T08:00:00+00:00",{"id":59,"title":60,"news_slug":61,"published_at":62},"68072ee1-fc37-4064-ab18-09550ae72d1b","GLM-5.3-Flash 把 320B MoE 跑在国产芯片上:Flash 价位和 $0.15 API 的混合注意力栈","glm-5-3-flash-chinese-chips-hybrid-attention","2026-08-27T03:00:00+00:00",{"id":64,"title":65,"news_slug":66,"published_at":67},"0d8fdf45-4585-47c0-9e78-3652e318b156","Apple Intelligence 中国版落地:通义千问接管语言 AI,百度负责视觉搜索","apple-intelligence-china-qwen-baidu-2026","2026-08-25T12:00:00+00:00"]