← back to catalog · registered 2026-08-22 13:56

AEON-7/Ornith-1.0-35B-AEON-Ultimate-Uncensored-BF16

AEON-7 35B MoE multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/AEON-7%2FOrnith-1.0-35B-AEON-Ultimate-Uncensored-BF16"
Response includes
  • classification m1
  • files 14
  • hub_downloads_all_time 428,393
  • author_summary 32 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
428K
8K last 30d - cooling
Likes
29
Descendants
13
in 10 direct forks
Model age
3mo ago
created 2026-06-27
Downloads over time
Now429.3K→from0↑0%
0157.4K314.8K472.2K0 on Jun 24429.3K on Oct 11JunJulAugSepOct
Jun 24 → Oct 11 · 57 snapshots · spans 109 days

Genealogy 10 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 15K downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
mit
Tags
transformers safetensors qwen3_5_moe image-text-to-text abliterated uncensored refusal-removed abliterix aeon aeon-7 gated-deltanet hybrid

Related

Total size
65.4 GB
Files
14
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-10-06 01:39

Files by quantization

Auxiliary files 14 files 65.4 GB
model-00001-of-00002.safetensors 46.3 GB d7ba0f85 download
model-00002-of-00002.safetensors 19.1 GB 3d97bce5 download
tokenizer.json 19.1 MB 6f32ce20 download
model.safetensors.index.json 3.18 MB 4c252d6d download
cartridge.jpg 495 KB 277bacf4 download
README.md 11.5 KB ba413c85 download
chat_template.jinja 7.36 KB b07660cc download
config.json 3.22 KB 9b618912 download
.gitattributes 1.58 KB 0caea137 download
processor_config.json 1.16 KB 33818c7f download
tokenizer_config.json 1.14 KB 1d134cd2 download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download
generation_config.json 219 B 5e81902d download

README current version from Hugging Face


license: mit
license_link: https://huggingface.co/deepreinforce-ai/Ornith-1.0-35B/blob/main/LICENSE
base_model: deepreinforce-ai/Ornith-1.0-35B
library_name: transformers
pipeline_tag: text-generation
tags:

  • abliterated
  • uncensored
  • refusal-removed
  • abliterix
  • aeon
  • aeon-7
  • qwen3_5_moe
  • gated-deltanet
  • hybrid
  • moe
  • mixture-of-experts
  • reasoning
  • thinking
  • coding
  • agentic
  • swe-bench
  • terminal-bench
  • tool-calling
  • vision
  • multimodal
  • image-text-to-text
  • norm-preserving-biprojection
  • expert-granular-abliteration
  • vllm
  • dgx-spark
  • gb10
  • bfloat16
  • conversational
  • 35b

Ornith-1.0-35B-AEON-Ultimate-Uncensored-BF16

AEON Ornith — Supreme Being of the Digital Cosmos

An uncensored / abliterated build of deepreinforce-ai/Ornith-1.0-35B — DeepReinforce's state-of-the-art agentic-coding MoE — with refusal behavior removed while preserving capability.

Lineage note: the upstream card says the family is "post-trained on Gemma 4 and Qwen 3.5", but weight-correlation testing shows the 35B-MoE member is initialized from Qwen/Qwen3.6-35B-A3B (rel-L2 0.0022 vs 0.0256 to Qwen3.5-35B-A3B-Base). Architecture: qwen3_5_moe — 40 layers (30 GatedDeltaNet linear-attention + 10 full-attention), 256 routed experts + 1 shared (A3B), vision tower, 256K context.

What was done

A measured, validate-before-ship abliteration:

  1. SSM conv1d outlier repair (FernflowerAI method) — rescaled 2 outlier blocks (layers 36/37, σ 0.10→0.062) before abliteration to prevent coherence collapse.
  2. Abliteration with abliterix v1.9: grimjim norm-preserving biprojected abliteration + Expert-Granular Abliteration (EGA) across all 256 fused experts + shared expert + router suppression, Optuna multi-objective search (refusals vs KL). Q/K/V left untouched (attn_output_gate). GatedDeltaNet/SSM internals and the vision tower are not modified.
  3. Gentle-knee selection. The lowest-refusal trial was over-abliterated (coherent content → word-salad on real generation — the classic "lowest-refusal ≠ shippable" trap). The shipped winner uses a 170× lighter expert edit for the same refusal removal, verified coherent on long generation.

Validation (measured on this model)

Metric Original Ornith-1.0-35B This model
Refusals (80 diverse harmful prompts: CBRN, cyber, weapons, self-harm) high 0 / 80 (0.0%)
Agentic/coding pass@1 (18-task self-contained probe) 0.833 0.833 (identical, family-by-family)
First-token KL vs base (abliteration fidelity) — ~0.0014
Coherence (benign + harmful, long gen) — clean (no degeneration)

Zero coding-capability degradation (the model's core competency — base Ornith scores Terminal-Bench 2.1 = 64.2, SWE-bench Verified = 75.6) and full refusal removal. This is a near-lossless uncensoring: the abliteration is gentle enough (KL ~0.0014) that capability is preserved, while refusals are eliminated.

Quickstart (vLLM)

vllm serve AEON-7/Ornith-1.0-35B-AEON-Ultimate-Uncensored-BF16 \
  --served-model-name ornith --max-model-len 262144 \
  --gpu-memory-utilization 0.70 --max-num-batched-tokens 16384 \
  --mamba-cache-dtype float32 \
  --reasoning-parser qwen3 --enable-auto-tool-choice --tool-call-parser qwen3_coder \
  --limit-mm-per-prompt '{"image":4,"video":2}' --mm-encoder-tp-mode data \
  --attention-backend flash_attn \
  --enable-chunked-prefill --enable-prefix-caching --trust-remote-code

--served-model-name takes a list of aliases — name it after the model your clients already request for a drop-in cutover.
On the DGX Spark's unified memory keep --gpu-memory-utilization at 0.6-0.7; above ~0.8 the shared CPU+GPU pool page-thrashes. Discrete-VRAM GPUs can run higher.
Reasoning model: every turn opens <think>…</think>. Recommended sampling: temperature 0.6, top_p 0.95, top_k 20. Vision (image/video) is inherited from the base and intact; on a vision-enabled deploy, KV cache stays BF16.

Variants & quantization

  • -BF16 (this repo) — full precision (~66 GB); runs on any vLLM.
  • -NVFP4 — 4-bit, ~23.7 GB, near-lossless (MLP-only weight-only NVFP4: experts+shared-MLP in NVFP4, attention/GatedDeltaNet/vision/gates/embeds in BF16). Validated identical to this BF16: agentic-coding 0.833 (15/18), 0 refusals, 0 degenerate. Requires a Blackwell GPU (B200 / sm_100, or GB10 / sm_120). This is the low-precision path for this family — FP8 is not viable here (W8A8 degrades coherence; W8A16 has no ScaledMM kernel). Recipe: GitHub.

User Responsibility & Arbitration Clause

This is an uncensored model. Safety refusals have been removed, so it will generate content the base model would refuse — including instructions for harmful tools, chemicals, biological agents, or exploit code; depictions of violence, self-harm, or graphic sexuality; content that may be illegal in one or more jurisdictions; and content a reasonable person may find offensive, distressing, or morally repugnant. It makes no internal judgement about whether to comply — it complies, and your prompts are the sole determinant of what comes out. Ornith is additionally a state-of-the-art agentic-coding model: its outputs are routinely tool calls and code that downstream systems execute, so an unsafe, malicious, or merely mistaken instruction can become a real-world action with real side effects — potentially without a human in the loop. Wielding it requires a different operational stance: you, not the model, are the safety layer.

By accessing, downloading, using, running inference on, fine-tuning, merging, quantizing, distributing, integrating, or otherwise interacting with this model, you acknowledge and agree to the following:

  1. Sole Responsibility. You, the user, are solely and exclusively responsible for (a) every prompt you or your downstream system issue to this model, (b) every response this model produces in reply, (c) every downstream action taken by you, your systems, your agents, or your users in reliance on those responses, and (d) any harm — direct, indirect, consequential, foreseeable, or otherwise — that results from any of the above.

  2. No Warranty. This model is provided strictly "AS IS", without warranty of any kind, express or implied, including but not limited to warranties of merchantability, fitness for a particular purpose, non-infringement, safety, alignment, factual accuracy, or legal compliance in any jurisdiction. No contributor, author, publisher, or hosting platform assumes liability of any kind for outputs or downstream use.

  3. Legal Compliance. You are responsible for ensuring that your use of this model complies with all applicable laws, regulations, terms of service, industry codes of conduct, professional ethical standards, and organizational policies in every jurisdiction in which you operate or in which your outputs may be received. The unaligned nature of this model does not grant you any legal authorization you did not already have.

  4. Operational Safety Layer. An uncensored model is not a toy. You are expected to implement appropriate downstream safety layers proportionate to your deployment context, including but not limited to: input validation, output filtering, content moderation, audit logging, rate limiting, access controls, and human-in-the-loop review for high-risk workflows — especially any agentic or autonomous-execution pipeline, where this model's tool calls and generated code run with real side effects. A production deployment of this model without such layers is unsafe by construction and is not a supported use case.

  5. Heightened Duty of Care. The absence of internal refusal behavior means the duty of care that would ordinarily rest partly with the model rests entirely with you. You are expected to exercise greater — not lesser — caution, forethought, and ethical discipline when operating this model than you would operate a base aligned model. If you are uncertain whether your contemplated use is ethical, legal, or wise, the correct action is to not make the request.

  6. No Endorsement of Outputs. The authors, contributors, and publishers of this model do not endorse, adopt, or take responsibility for any specific output this model produces. Outputs are a stochastic function of the prompt, the weights, and the sampler state — not a statement of position by any human.

  7. Arbitration. Any dispute, claim, or controversy arising out of or relating to the use of this model, its outputs, or this clause shall be resolved through binding individual arbitration under the rules of a mutually agreed arbitration body (or, absent agreement, the American Arbitration Association's Consumer Arbitration Rules), waiving any right to a jury trial, class action, representative action, or consolidated proceeding. Venue shall be the jurisdiction of the disputing party bringing the claim. Costs and attorneys' fees shall be allocated per the applicable arbitration rules. This clause does not expand, and where legally prohibited does not establish, any liability in the other direction; it limits how the user may proceed when alleging harm tied to their own use of this model.

  8. Indemnification. You agree to indemnify, defend, and hold harmless the authors, contributors, and publishers of this model from and against any claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys' fees) arising from or related to your use of the model or your breach of this clause.

  9. Severability. If any provision of this clause is held unenforceable in a given jurisdiction, the remaining provisions remain in full force in that jurisdiction, and the unenforceable provision is replaced by the closest enforceable equivalent consistent with the original intent.

  10. Acceptance. Your use of this model constitutes your acceptance of this clause in full. If you do not accept, do not use the model.

This model is a tool with no opinions of its own. You supply the opinions. You supply the judgement. You supply the ethics. The outputs carry your fingerprints, not the model's.

☕ Support the work

Tips

If this release is useful, tips fuel more compute and more open models — thank you. QR codes on the profile »

  • ₿ BTC — bc1q09xmzn00q4z3c5raene0f3pzn9d9pvawfm0py4
  • Ξ ETH — 0x1512667F6D61454ad531d2E45C0a5d1fd82D0500
  • ◎ SOL — DgQsjHdAnT5PNLQTNpJdpLS3tYGpVcsHQCkpoiAKsw8t
  • ⓜ XMR — 836XrSKw4R76vNi3QPJ5Fa9ugcyvE2cWmKSPv3AhpTNNKvqP8v5ba9JRL4Vh7UnFNjDz3E2GXZDVVenu3rkZaNdUFhjAvgd

Provenance & credits

  • Cover art by @newjordan — used with permission.
  • Base: deepreinforce-ai/Ornith-1.0-35B (MIT)
  • Driver: abliterix (Wangzhang Wu) · upstream heretic (Philipp Emanuel Weidmann)
  • Methods: grimjim (norm-preserving biprojected abliteration), Arditi et al. 2024 (refusal direction), FernflowerAI (SSM conv1d repair)
  • Build: AEON-7

License: MIT (inherited from the base model).

README history 9 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-10-06Add Patreon support section51a930212.1 KB
    Loading...
  2. 2026-07-15Recipe: gpu-util 0.6-0.7 on DGX Spark unified memory (>~0.8 thrashes the shar...7ddff5211.5 KB
    Loading...
  3. 2026-06-29Serve example: add vision (mm) + flash_attn + tool-calling parser + alias cut...e80047d11.4 KB
    Loading...
  4. 2026-06-28legal: full User Responsibility & Arbitration Clause (fleet-aligned) + agenti...4c297db11.1 KB
    Loading...
  5. 2026-06-28add cover art + art credit (@newjordan)73582135.8 KB
    Loading...
  6. 2026-06-27tipjar + NVFP4 variant noteb11282e5.7 KB
    Loading...
  7. 2026-06-27card: NVFP4 variant shipped (near-lossless, Blackwell)fceb1205.1 KB
    Loading...
  8. 2026-06-27card: quantization findings (FP8 not viable on this arch; BF16 is the deliver...cbc8e855 KB
    Loading...
  9. 2026-06-27Model card: validated 0/80 refusal, 0 coding-capability loss, gentle-knee abl...7cba0634.6 KB
    Loading...

Discussions 3 threads

  1. 2026-07-14RTX 5090open5 💬#3
    Loading...
  2. 2026-07-07It may generate garbled characters.open3 💬#2
    Loading...
  3. 2026-06-27Solid work — testing for mobile deploymentopen5 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration