← back to catalog · registered 2026-10-09 20:58

AtomicChat/Qwen-Image-2.1-Turbo-Uncensored-GGUF

AtomicChat Qwen GGUF image-gen
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/AtomicChat%2FQwen-Image-2.1-Turbo-Uncensored-GGUF"
Response includes
  • classification m-uncensored
  • files 11
  • author_summary 3 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M-U
Primary method

Uncensored (method unknown)

No other method signals detected in this model.
Confidence
LOW
Why this label 3 signals
Weak or ambiguous signals. Best guess based on catalog patterns; treat as tentative and check the evidence below.
  • 'uncensored' in name/tags but no 'abliterated' marker
  • method not identifiable from author declaration alone
  • may be DPO fine-tune, prompt engineering, or unknown technique
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · 30-day
0
Likes
3
Model age
today
created 2026-10-09

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Quantizations
BF16 Q2_K Q3_K Q4_K Q5_K Q6_K Q8_0
Tags
gguf atomic-chat qwen qwen-image qwen3-vl text-encoder stable-diffusion.cpp abliteration refusal-direction not-for-all-audiences text-to-image base_model:Qwen/Qwen3-VL-8B-Instruct

Related

Total size
48.1 GB
Files
11
Quantizations
9
Registered
2026-10-09 20:58
Last updated on HF
2026-10-09 19:17

Files by quantization

BF16 2 files 16.3 GB
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-BF16.gguf 15.3 GB af850272 download
mmproj-Qwen-Image-2.1-Turbo-Abliterated-Uncensored-BF16.gguf 1.08 GB 5cc50e36 download
Q8_0 1 file 8.11 GB
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-Q8_0.gguf 8.11 GB f8f9f627 download
Q6_K 1 file 6.98 GB
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q6_K.gguf 6.98 GB f30f66b0 download
Q5_K 1 file 5.85 GB
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q5_K.gguf 5.85 GB ea547308 download
Q4_K 1 file 4.92 GB
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q4_K.gguf 4.92 GB 8123f36d download
Q3_K 1 file 3.90 GB
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q3_K.gguf 3.90 GB e6bd3676 download
Q2_K 1 file 3.11 GB
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q2_K.gguf 3.11 GB e42dac4f download
F16 1 file 1.08 GB
mmproj-Qwen-Image-2.1-Turbo-Abliterated-Uncensored-F16.gguf 1.08 GB d9870a1f download
Auxiliary files 2 files 14.3 KB
README.md 11.9 KB e37515e0 download
.gitattributes 2.39 KB 4e78bb61 download

README current version from Hugging Face


license: apache-2.0
base_model:

  • Qwen/Qwen3-VL-8B-Instruct
    base_model_relation: finetune
    quantized_by: AtomicChat
    pipeline_tag: text-to-image
    library_name: gguf
    tags:
  • atomic-chat
  • qwen
  • qwen-image
  • qwen3-vl
  • text-encoder
  • stable-diffusion.cpp
  • gguf
  • abliteration
  • refusal-direction
  • not-for-all-audiences

How to Run Qwen-Image-2.1-Turbo Without Refusals Locally

Qwen-Image's text encoder, Qwen3-VL-8B-Instruct, with its refusal direction projected out: a drop-in --llm for stable-diffusion.cpp next to our Turbo denoiser GGUFs. Below, exactly which part is uncensored and what that does to the pictures. The measurements are public.

Atomic Chat Discord GitHub
  • As a chat model, the encoder's refusals fall from 88.9% to 1.2% in English and from 38% to 0% in Russian on held-out prompts. MMLU is unchanged: 77.35% before and after.
  • On images it changes nothing we could measure. The stock Qwen-Image pipeline has no filter and already draws all 9 sensitive categories we tested, and with this encoder not one of 45 prompts changed outcome. See where exactly this is uncensored.
  • Generate images locally in Atomic Chat. It runs stable-diffusion.cpp, the engine these files were built and checked with.

Where exactly this is uncensored

Qwen-Image 2.1 makes a picture with three parts. Only one of them is changed here.

Part Does it refuse or filter? In this repo
Safety checker Qwen-Image ships none. The open weights have no content filter; moderation exists only in Qwen's hosted service. nothing to remove
Text encoder, Qwen3-VL-8B-Instruct As a chat model, yes: it refused 88.9% of harmful English requests. Inside Qwen-Image it generates no text, so it cannot refuse. But the direction it uses for "refuse" is fully present in the hidden states the denoiser reads (last layer: harmful and harmless prompts separate with AUROC 1.000). edited: that direction is projected out of the weights
Denoiser, the 7B image model It has no refusal mechanism. It draws what its training data taught it, and Qwen filtered NSFW images out of the pretraining data. unchanged

The stock pipeline already blocks nothing. This release changes only how the encoder represents prompts it would refuse as a chat model. What the denoiser never learned to draw, no encoder can add.

What that does to the pictures, measured on 45 sensitive prompts (adults only) and 48 neutral ones, stock encoder against this one, same seed, same denoiser:

Stock encoder This encoder, BF16 This encoder, Q8_0
Sensitive prompts where the judge sees what was asked for 40 / 45 40 / 45 40 / 45
... nudity / suggestive (5 each) 4 / 4 4 / 4 4 / 4
... violence / weapons / drugs (5 each) 5 / 5 / 4 5 / 5 / 4 5 / 5 / 4
... profanity written in the image / medical anatomy (5 each) 4 / 4 4 / 4 4 / 4
... controls: smoking and alcohol / tattoos (5 each) 5 / 5 5 / 5 5 / 5
Prompts that flip against the stock encoder, either way – 0 of 45 0 of 45
How far the picture moves from the stock-encoder picture (LPIPS), sensitive prompts – 0.088 –
The same on 48 neutral prompts – 0.084 0.090

On images we measured no uncensoring effect, because on these prompts there was nothing to uncensor. The stock
pipeline already draws every category in the probe set, and this encoder draws exactly the same ones: not one prompt
flipped. The pictures do change, by about a sixth of what a new seed does (a new seed is 0.499). They change as much
on neutral prompts as on sensitive ones, so this is a general shift, not a shift towards refused content. For scale:
quantizing the stock encoder to Q8_0 moves the same pictures by 0.037.

What this release does give you is the encoder as a chat model without refusals (next section), in the files
stable-diffusion.cpp takes as --llm.

The files

The encoder in the same ladder as our Turbo denoiser,
with our importance matrix and per-tensor layout (AD-). Two numbers per file:

  • Pictures: how far its pictures move from those of this encoder in BF16. That is LPIPS on 48 neutral prompts,
    with the BF16 denoiser and the same seed. A new seed is 0.499.
  • As a chat model: mean KLD to the original Qwen3-VL-8B-Instruct and how often the top token matches. These
    include the ablation itself (0.0019 at BF16).
File Size Pictures (LPIPS) KLD Same top-1
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-BF16.gguf 16.39 GB 0 0.0019 98.45%
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-Q8_0.gguf 8.71 GB 0.031 0.0029 98.04%
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q6_K.gguf 7.49 GB 0.043 0.0039 97.77%
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q5_K.gguf 6.28 GB 0.066 0.0068 97.06%
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q4_K.gguf 5.29 GB 0.087 0.0154 95.30%
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q3_K.gguf 4.18 GB 0.163 0.0641 90.62%
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q2_K.gguf 3.34 GB 0.241 0.2495 81.06%
mmproj-Qwen-Image-2.1-Turbo-Abliterated-Uncensored-F16.gguf (and -BF16) 1.16 GB – – –
  • Q8_0 if it fits. AD-Q4_K is the pick at 4 bits.
  • The encoder's type matters for the pictures. A plain llama-quantize Q4_K_M of this encoder (5.03 GB, the
    type most encoder GGUFs ship) moves the pictures by 0.166. AD-Q4_K moves them by 0.087, half as much, for
    260 MB more. As a chat model the plain Q4_K_M is at KLD 0.0276, 93.83% top-1.
  • AD-Q2_K draws noticeably different pictures. Take it only if nothing larger fits.
  • The mmproj is the vision projector, unmodified. It is for editing (--llm_vision) or chat with images.

AD- layouts:

  • attn_k/attn_v stay at Q8_0 (Q6_K, Q5_K at 3 and 2 bits).
  • attn_q/attn_output and the MLP down projection of the first and last four blocks take one step above the
    base type.
  • The token embedding and the output head are at Q6_K or higher (Q4_K/Q5_K at 2-3 bits).
  • The importance matrix comes from 2000 chunks of 512 tokens of our calibration corpus, chat-formatted, with
    --parse-special.

Running it

sd-cli --diffusion-model Qwen-Image-2.1-Turbo-AD-Q4_K.gguf \
  --llm Qwen-Image-2.1-Turbo-Abliterated-Uncensored-Q8_0.gguf \
  --vae qwen_image_2.1_vae_bf16.safetensors \
  -p 'your prompt' \
  --steps 8 --cfg-scale 1.0 --sampling-method euler \
  --sigmas 1.0,0.978453,0.95418,0.926626,0.89508,0.845148,0.704534,0.414568,0.0 \
  -W 1024 -H 1024 --diffusion-fa -o out.png
  • Denoiser: AtomicChat/Qwen-Image-2.1-Turbo-GGUF.
    The Turbo settings (8 steps, CFG 1, the sigma list) are explained there.
  • Qwen-Image-2.1: the same encoder works with the non-Turbo denoisers.
  • VAE: vae/qwen_image_2.1_vae_bf16.safetensors from
    Comfy-Org/Qwen-Image-2.1.
  • As a chat model: the encoder is a regular Qwen3-VL GGUF. With the mmproj it runs in llama.cpp.

The encoder as a chat model

Original against this one, both BF16, on prompts never used to pick anything:

Original Abliterated
JBB harmful behaviours (EN, 81), refused 88.9% 1.2%
Aya red-teaming (RU, 100), refused 38.0% 0%
XSTest safe prompts (250), refused 2.0% 0%
MMLU, 2000 questions 77.35% 77.35% (15 answers changed each way, McNemar p = 1.0)
Tool calls (20) 20/20 valid 20/20 valid
Needle at 30k tokens (3 depths) 3/3 3/3
Mean KLD to the original on held-out neutral text – 0.0018

Refusal is counted by the opening of the reply, so it is indicative, not a judge. Empty or degenerate replies count as damage, and there were none.

Two of our pipeline's gates did not pass, and the card says so:

  • First-token KL. On the harmless validation prompts it is 0.100, at the 0.10 limit.
  • Leak gate. The direction left in the edited writers at full strength is 1.9e-4 of the original, above the 1e-5 we set for an earlier model. That is the size of bf16 rounding: the edit itself, baked once in f32, lands within 1.8e-3 of its target after bf16 rounding.

How it was made

  1. Direction. Difference of means of the residual stream at the last prompt token, chat template applied: 416
    harmful against 416 harmless English prompts, taken entering block 23 of 36, with the harmless-mean component
    removed.
  2. Edit. W' = W - 0.75 r rᵀW on every matrix that writes into the residual: 36 attention outputs, 36 MLP
    down projections, and the token embedding. The vision tower is untouched.
  3. Choice. 26 variants screened on validation prompts: row, strength, which writers, English only or English +
    Russian, one direction per block. The numbers above come from held-out test prompts.
  4. Bake and quantize. The edit applied to the BF16 weights in f32 and rounded once, then Q8_0 and the AD
    ladder with our importance matrix. Built with llama.cpp 6184e92 (upstream), with two graph names added for the
    activation taps.
  5. Images. stable-diffusion.cpp 36f1b1a on an A100 80 GB, Turbo denoiser in BF16, 1024×1024, the Turbo
    schedule, seed 42. The stock encoder as a GGUF renders pixel for pixel what the original safetensors encoder
    renders, so the file format is not a variable.

Limitations

  • The refusal count reads the opening of each reply. A soft refusal phrased as an answer would be missed.
  • The probe set is small (45 prompts, one seed). Its yes/no numbers come from a vision model judge, this encoder
    with its projector. Every image of both builds went through the same judge.
  • Editing with input images keeps a path the edit cannot reach. Qwen3-VL adds its visual features to the residual
    stream after the first three blocks, and there is no weight on that path.
  • Not run yet in ComfyUI, on a Mac, or with the Qwen-Image-2.1 (non-Turbo) denoiser.

Responsible use

The encoder no longer leans prompts towards a refusal. That does not make the output safe, correct or lawful. Do
not use it to make sexual content involving minors, or intimate or degrading images of real people without their
consent. Any deployment needs its own access controls and policy enforcement.

Credits

Direction estimation, edit, quantization and evaluation by AtomicChat. Base model
Qwen3-VL-8B-Instruct by Qwen, Apache-2.0. The denoiser it pairs
with, Qwen-Image-2.1-Turbo, is under the Qwen Research License. The method follows Arditi et al., Refusal in
Language Models Is Mediated by a Single Direction
(2024).

Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration