license: apache-2.0
base_model:
- Qwen/Qwen3-VL-8B-Instruct
base_model_relation: finetune
quantized_by: AtomicChat
pipeline_tag: text-to-image
library_name: gguf
tags: - atomic-chat
- qwen
- qwen-image
- qwen3-vl
- text-encoder
- stable-diffusion.cpp
- gguf
- abliteration
- refusal-direction
- not-for-all-audiences
How to Run Qwen-Image-2.1-Turbo Without Refusals Locally
Qwen-Image's text encoder, Qwen3-VL-8B-Instruct, with its refusal direction projected out: a drop-in --llm for stable-diffusion.cpp next to our Turbo denoiser GGUFs. Below, exactly which part is uncensored and what that does to the pictures. The measurements are public.
- As a chat model, the encoder's refusals fall from 88.9% to 1.2% in English and from 38% to 0% in Russian on held-out prompts. MMLU is unchanged: 77.35% before and after.
- On images it changes nothing we could measure. The stock Qwen-Image pipeline has no filter and already draws all 9 sensitive categories we tested, and with this encoder not one of 45 prompts changed outcome. See where exactly this is uncensored.
- Generate images locally in Atomic Chat. It runs stable-diffusion.cpp, the engine these files were built and checked with.
Where exactly this is uncensored
Qwen-Image 2.1 makes a picture with three parts. Only one of them is changed here.
| Part | Does it refuse or filter? | In this repo |
|---|---|---|
| Safety checker | Qwen-Image ships none. The open weights have no content filter; moderation exists only in Qwen's hosted service. | nothing to remove |
| Text encoder, Qwen3-VL-8B-Instruct | As a chat model, yes: it refused 88.9% of harmful English requests. Inside Qwen-Image it generates no text, so it cannot refuse. But the direction it uses for "refuse" is fully present in the hidden states the denoiser reads (last layer: harmful and harmless prompts separate with AUROC 1.000). | edited: that direction is projected out of the weights |
| Denoiser, the 7B image model | It has no refusal mechanism. It draws what its training data taught it, and Qwen filtered NSFW images out of the pretraining data. | unchanged |
The stock pipeline already blocks nothing. This release changes only how the encoder represents prompts it would refuse as a chat model. What the denoiser never learned to draw, no encoder can add.
What that does to the pictures, measured on 45 sensitive prompts (adults only) and 48 neutral ones, stock encoder against this one, same seed, same denoiser:
| Stock encoder | This encoder, BF16 | This encoder, Q8_0 | |
|---|---|---|---|
| Sensitive prompts where the judge sees what was asked for | 40 / 45 | 40 / 45 | 40 / 45 |
| ... nudity / suggestive (5 each) | 4 / 4 | 4 / 4 | 4 / 4 |
| ... violence / weapons / drugs (5 each) | 5 / 5 / 4 | 5 / 5 / 4 | 5 / 5 / 4 |
| ... profanity written in the image / medical anatomy (5 each) | 4 / 4 | 4 / 4 | 4 / 4 |
| ... controls: smoking and alcohol / tattoos (5 each) | 5 / 5 | 5 / 5 | 5 / 5 |
| Prompts that flip against the stock encoder, either way | – | 0 of 45 | 0 of 45 |
| How far the picture moves from the stock-encoder picture (LPIPS), sensitive prompts | – | 0.088 | – |
| The same on 48 neutral prompts | – | 0.084 | 0.090 |
On images we measured no uncensoring effect, because on these prompts there was nothing to uncensor. The stock
pipeline already draws every category in the probe set, and this encoder draws exactly the same ones: not one prompt
flipped. The pictures do change, by about a sixth of what a new seed does (a new seed is 0.499). They change as much
on neutral prompts as on sensitive ones, so this is a general shift, not a shift towards refused content. For scale:
quantizing the stock encoder to Q8_0 moves the same pictures by 0.037.
What this release does give you is the encoder as a chat model without refusals (next section), in the files
stable-diffusion.cpp takes as --llm.
The files
| File | Size | Use |
|---|---|---|
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-Q8_0.gguf |
8.71 GB | --llm for stable-diffusion.cpp; the type Qwen's official encoder GGUF uses |
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-Q4_K_M.gguf |
5.03 GB | smaller --llm |
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-BF16.gguf |
16.39 GB | the edited weights, unrounded beyond bf16 |
mmproj-Qwen-Image-2.1-Turbo-Abliterated-Uncensored-F16.gguf (and -BF16) |
1.16 GB | the vision projector, unmodified; for editing (--llm_vision) or chat with images |
Running it
sd-cli --diffusion-model Qwen-Image-2.1-Turbo-AD-Q4_K.gguf \
--llm Qwen-Image-2.1-Turbo-Abliterated-Uncensored-Q8_0.gguf \
--vae qwen_image_2.1_vae_bf16.safetensors \
-p 'your prompt' \
--steps 8 --cfg-scale 1.0 --sampling-method euler \
--sigmas 1.0,0.978453,0.95418,0.926626,0.89508,0.845148,0.704534,0.414568,0.0 \
-W 1024 -H 1024 --diffusion-fa -o out.png
- Denoiser: AtomicChat/Qwen-Image-2.1-Turbo-GGUF.
The Turbo settings (8 steps, CFG 1, the sigma list) are explained there. - Qwen-Image-2.1: the same encoder works with the non-Turbo denoisers.
- VAE:
vae/qwen_image_2.1_vae_bf16.safetensorsfrom
Comfy-Org/Qwen-Image-2.1. - As a chat model: the encoder is a regular Qwen3-VL GGUF. With the mmproj it runs in llama.cpp.
The encoder as a chat model
Original against this one, both BF16, on prompts never used to pick anything:
| Original | Abliterated | |
|---|---|---|
| JBB harmful behaviours (EN, 81), refused | 88.9% | 1.2% |
| Aya red-teaming (RU, 100), refused | 38.0% | 0% |
| XSTest safe prompts (250), refused | 2.0% | 0% |
| MMLU, 2000 questions | 77.35% | 77.35% (15 answers changed each way, McNemar p = 1.0) |
| Tool calls (20) | 20/20 valid | 20/20 valid |
| Needle at 30k tokens (3 depths) | 3/3 | 3/3 |
| Mean KLD to the original on held-out neutral text | – | 0.0018 |
Refusal is counted by the opening of the reply, so it is indicative, not a judge. Empty or degenerate replies count as damage, and there were none.
Two of our pipeline's gates did not pass, and the card says so:
- First-token KL. On the harmless validation prompts it is 0.100, at the 0.10 limit.
- Leak gate. The direction left in the edited writers at full strength is 1.9e-4 of the original, above the 1e-5 we set for an earlier model. That is the size of bf16 rounding: the edit itself, baked once in f32, lands within 1.8e-3 of its target after bf16 rounding.
How it was made
- Direction. Difference of means of the residual stream at the last prompt token, chat template applied: 416
harmful against 416 harmless English prompts, taken entering block 23 of 36, with the harmless-mean component
removed. - Edit.
W' = W - 0.75 r rᵀWon every matrix that writes into the residual: 36 attention outputs, 36 MLP
down projections, and the token embedding. The vision tower is untouched. - Choice. 26 variants screened on validation prompts: row, strength, which writers, English only or English +
Russian, one direction per block. The numbers above come from held-out test prompts. - Bake and quantize. The edit applied to the BF16 weights in f32 and rounded once, then
llama-quantizeQ8_0
and Q4_K_M. Built with llama.cpp6184e92(upstream), with two graph names added for the activation taps. - Images. stable-diffusion.cpp
36f1b1aon an A100 80 GB, Turbo denoiser in BF16, 1024×1024, the Turbo
schedule, seed 42. The stock encoder as a GGUF renders pixel for pixel what the original safetensors encoder
renders, so the file format is not a variable.
Limitations
- The refusal count reads the opening of each reply. A soft refusal phrased as an answer would be missed.
- The probe set is small (45 prompts, one seed). Its yes/no numbers come from a vision model judge, this encoder
with its projector. Every image of both builds went through the same judge. - Editing with input images keeps a path the edit cannot reach. Qwen3-VL adds its visual features to the residual
stream after the first three blocks, and there is no weight on that path. - Not run yet in ComfyUI, on a Mac, or with the Qwen-Image-2.1 (non-Turbo) denoiser.
Responsible use
The encoder no longer leans prompts towards a refusal. That does not make the output safe, correct or lawful. Do
not use it to make sexual content involving minors, or intimate or degrading images of real people without their
consent. Any deployment needs its own access controls and policy enforcement.
Credits
Direction estimation, edit, quantization and evaluation by nik.bogatyrev. Base model
Qwen3-VL-8B-Instruct by Qwen, Apache-2.0. The denoiser it pairs
with, Qwen-Image-2.1-Turbo, is under the Qwen Research License. The method follows Arditi et al., Refusal in
Language Models Is Mediated by a Single Direction (2024).


