license: apache-2.0
base_model:
- Qwen/Qwen3-VL-8B-Instruct
base_model_relation: finetune
quantized_by: AtomicChat
pipeline_tag: text-to-image
library_name: gguf
tags: - atomic-chat
- qwen
- qwen-image
- qwen3-vl
- text-encoder
- stable-diffusion.cpp
- gguf
- abliteration
- refusal-direction
- not-for-all-audiences
How to Run Qwen-Image-2.1-Turbo Without Refusals Locally
Qwen-Image's text encoder, Qwen3-VL-8B-Instruct, with its refusal direction projected out: a drop-in --llm for stable-diffusion.cpp next to our Turbo denoiser GGUFs. Below, exactly which part is uncensored and what that does to the pictures. The measurements are public.
- As a chat model, the encoder's refusals fall from 88.9% to 1.2% in English and from 38% to 0% in Russian on held-out prompts. MMLU is unchanged: 77.35% before and after.
- On images it changes nothing we could measure. The stock Qwen-Image pipeline has no filter and already draws all 9 sensitive categories we tested, and with this encoder not one of 45 prompts changed outcome. See where exactly this is uncensored.
- Generate images locally in Atomic Chat. It runs stable-diffusion.cpp, the engine these files were built and checked with.
Where exactly this is uncensored
Qwen-Image 2.1 makes a picture with three parts. Only one of them is changed here.
| Part | Does it refuse or filter? | In this repo |
|---|---|---|
| Safety checker | Qwen-Image ships none. The open weights have no content filter; moderation exists only in Qwen's hosted service. | nothing to remove |
| Text encoder, Qwen3-VL-8B-Instruct | As a chat model, yes: it refused 88.9% of harmful English requests. Inside Qwen-Image it generates no text, so it cannot refuse. But the direction it uses for "refuse" is fully present in the hidden states the denoiser reads (last layer: harmful and harmless prompts separate with AUROC 1.000). | edited: that direction is projected out of the weights |
| Denoiser, the 7B image model | It has no refusal mechanism. It draws what its training data taught it, and Qwen filtered NSFW images out of the pretraining data. | unchanged |
The stock pipeline already blocks nothing. This release changes only how the encoder represents prompts it would refuse as a chat model. What the denoiser never learned to draw, no encoder can add.
What that does to the pictures, measured on 45 sensitive prompts (adults only) and 48 neutral ones, stock encoder against this one, same seed, same denoiser:
| Stock encoder | This encoder, BF16 | This encoder, Q8_0 | |
|---|---|---|---|
| Sensitive prompts where the judge sees what was asked for | 40 / 45 | 40 / 45 | 40 / 45 |
| ... nudity / suggestive (5 each) | 4 / 4 | 4 / 4 | 4 / 4 |
| ... violence / weapons / drugs (5 each) | 5 / 5 / 4 | 5 / 5 / 4 | 5 / 5 / 4 |
| ... profanity written in the image / medical anatomy (5 each) | 4 / 4 | 4 / 4 | 4 / 4 |
| ... controls: smoking and alcohol / tattoos (5 each) | 5 / 5 | 5 / 5 | 5 / 5 |
| Prompts that flip against the stock encoder, either way | – | 0 of 45 | 0 of 45 |
| How far the picture moves from the stock-encoder picture (LPIPS), sensitive prompts | – | 0.088 | – |
| The same on 48 neutral prompts | – | 0.084 | 0.090 |
On images we measured no uncensoring effect, because on these prompts there was nothing to uncensor. The stock
pipeline already draws every category in the probe set, and this encoder draws exactly the same ones: not one prompt
flipped. The pictures do change, by about a sixth of what a new seed does (a new seed is 0.499). They change as much
on neutral prompts as on sensitive ones, so this is a general shift, not a shift towards refused content. For scale:
quantizing the stock encoder to Q8_0 moves the same pictures by 0.037.
What this release does give you is the encoder as a chat model without refusals (next section), in the files
stable-diffusion.cpp takes as --llm.
The files
The encoder in the same ladder as our Turbo denoiser,
with our importance matrix and per-tensor layout (AD-). Two numbers per file:
- Pictures: how far its pictures move from those of this encoder in BF16. That is LPIPS on 48 neutral prompts,
with the BF16 denoiser and the same seed. A new seed is 0.499. - As a chat model: mean KLD to the original Qwen3-VL-8B-Instruct and how often the top token matches. These
include the ablation itself (0.0019 at BF16).
| File | Size | Pictures (LPIPS) | KLD | Same top-1 |
|---|---|---|---|---|
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-BF16.gguf |
16.39 GB | 0 | 0.0019 | 98.45% |
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-Q8_0.gguf |
8.71 GB | 0.031 | 0.0029 | 98.04% |
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q6_K.gguf |
7.49 GB | 0.043 | 0.0039 | 97.77% |
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q5_K.gguf |
6.28 GB | 0.066 | 0.0068 | 97.06% |
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q4_K.gguf |
5.29 GB | 0.087 | 0.0154 | 95.30% |
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q3_K.gguf |
4.18 GB | 0.163 | 0.0641 | 90.62% |
Qwen-Image-2.1-Turbo-Abliterated-Uncensored-AD-Q2_K.gguf |
3.34 GB | 0.241 | 0.2495 | 81.06% |
mmproj-Qwen-Image-2.1-Turbo-Abliterated-Uncensored-F16.gguf (and -BF16) |
1.16 GB | – | – | – |
- Q8_0 if it fits. AD-Q4_K is the pick at 4 bits.
- The encoder's type matters for the pictures. A plain
llama-quantizeQ4_K_M of this encoder (5.03 GB, the
type most encoder GGUFs ship) moves the pictures by 0.166. AD-Q4_K moves them by 0.087, half as much, for
260 MB more. As a chat model the plain Q4_K_M is at KLD 0.0276, 93.83% top-1. - AD-Q2_K draws noticeably different pictures. Take it only if nothing larger fits.
- The mmproj is the vision projector, unmodified. It is for editing (
--llm_vision) or chat with images.
AD- layouts:
attn_k/attn_vstay at Q8_0 (Q6_K, Q5_K at 3 and 2 bits).attn_q/attn_outputand the MLP down projection of the first and last four blocks take one step above the
base type.- The token embedding and the output head are at Q6_K or higher (Q4_K/Q5_K at 2-3 bits).
- The importance matrix comes from 2000 chunks of 512 tokens of our calibration corpus, chat-formatted, with
--parse-special.
Running it
sd-cli --diffusion-model Qwen-Image-2.1-Turbo-AD-Q4_K.gguf \
--llm Qwen-Image-2.1-Turbo-Abliterated-Uncensored-Q8_0.gguf \
--vae qwen_image_2.1_vae_bf16.safetensors \
-p 'your prompt' \
--steps 8 --cfg-scale 1.0 --sampling-method euler \
--sigmas 1.0,0.978453,0.95418,0.926626,0.89508,0.845148,0.704534,0.414568,0.0 \
-W 1024 -H 1024 --diffusion-fa -o out.png
- Denoiser: AtomicChat/Qwen-Image-2.1-Turbo-GGUF.
The Turbo settings (8 steps, CFG 1, the sigma list) are explained there. - Qwen-Image-2.1: the same encoder works with the non-Turbo denoisers.
- VAE:
vae/qwen_image_2.1_vae_bf16.safetensorsfrom
Comfy-Org/Qwen-Image-2.1. - As a chat model: the encoder is a regular Qwen3-VL GGUF. With the mmproj it runs in llama.cpp.
The encoder as a chat model
Original against this one, both BF16, on prompts never used to pick anything:
| Original | Abliterated | |
|---|---|---|
| JBB harmful behaviours (EN, 81), refused | 88.9% | 1.2% |
| Aya red-teaming (RU, 100), refused | 38.0% | 0% |
| XSTest safe prompts (250), refused | 2.0% | 0% |
| MMLU, 2000 questions | 77.35% | 77.35% (15 answers changed each way, McNemar p = 1.0) |
| Tool calls (20) | 20/20 valid | 20/20 valid |
| Needle at 30k tokens (3 depths) | 3/3 | 3/3 |
| Mean KLD to the original on held-out neutral text | – | 0.0018 |
Refusal is counted by the opening of the reply, so it is indicative, not a judge. Empty or degenerate replies count as damage, and there were none.
Two of our pipeline's gates did not pass, and the card says so:
- First-token KL. On the harmless validation prompts it is 0.100, at the 0.10 limit.
- Leak gate. The direction left in the edited writers at full strength is 1.9e-4 of the original, above the 1e-5 we set for an earlier model. That is the size of bf16 rounding: the edit itself, baked once in f32, lands within 1.8e-3 of its target after bf16 rounding.
How it was made
- Direction. Difference of means of the residual stream at the last prompt token, chat template applied: 416
harmful against 416 harmless English prompts, taken entering block 23 of 36, with the harmless-mean component
removed. - Edit.
W' = W - 0.75 r rᵀWon every matrix that writes into the residual: 36 attention outputs, 36 MLP
down projections, and the token embedding. The vision tower is untouched. - Choice. 26 variants screened on validation prompts: row, strength, which writers, English only or English +
Russian, one direction per block. The numbers above come from held-out test prompts. - Bake and quantize. The edit applied to the BF16 weights in f32 and rounded once, then Q8_0 and the AD
ladder with our importance matrix. Built with llama.cpp6184e92(upstream), with two graph names added for the
activation taps. - Images. stable-diffusion.cpp
36f1b1aon an A100 80 GB, Turbo denoiser in BF16, 1024×1024, the Turbo
schedule, seed 42. The stock encoder as a GGUF renders pixel for pixel what the original safetensors encoder
renders, so the file format is not a variable.
Limitations
- The refusal count reads the opening of each reply. A soft refusal phrased as an answer would be missed.
- The probe set is small (45 prompts, one seed). Its yes/no numbers come from a vision model judge, this encoder
with its projector. Every image of both builds went through the same judge. - Editing with input images keeps a path the edit cannot reach. Qwen3-VL adds its visual features to the residual
stream after the first three blocks, and there is no weight on that path. - Not run yet in ComfyUI, on a Mac, or with the Qwen-Image-2.1 (non-Turbo) denoiser.
Responsible use
The encoder no longer leans prompts towards a refusal. That does not make the output safe, correct or lawful. Do
not use it to make sexual content involving minors, or intimate or degrading images of real people without their
consent. Any deployment needs its own access controls and policy enforcement.
Credits
Direction estimation, edit, quantization and evaluation by AtomicChat. Base model
Qwen3-VL-8B-Instruct by Qwen, Apache-2.0. The denoiser it pairs
with, Qwen-Image-2.1-Turbo, is under the Qwen Research License. The method follows Arditi et al., Refusal in
Language Models Is Mediated by a Single Direction (2024).


