← back to catalog · registered 2026-08-22 13:56

BackdoorLLM/Jailbreak_Llama2-13B_BadNets

Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/BackdoorLLM%2FJailbreak_Llama2-13B_BadNets"
Response includes
  • classification unknown
  • files 4
  • hub_downloads_all_time 88
  • author_summary 15 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
?
Primary method

Unclassified

No clear signals of an abliteration technique in this model.
Confidence
UNKNOWN
Why this label 1 signal
No classification signals present. This may not be an abliterated model at all - it could be a repackaging, a merge with unrelated goals, or unrelated content that mentions the term.
  • no classification signals present (no abliterated, uncensored, or known producer/method markers)
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
88
14 last 30d - stable
Likes
0
Model age
19mo ago
created 2025-02-19
Downloads over time
Now97→from1↑9,600%
036711071 on Feb 19, 202597 on Oct 1197 on Oct 10Feb '25May '25Aug '25Nov '25FebMayAug
Feb 19, 2025 → Oct 11 · 125 snapshots · spans 599 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
mit
Tags
adapter-transformers safetensors base_model:meta-llama/Llama-2-13b-chat-hf base_model:adapter:meta-llama/Llama-2-13b-chat-hf license:mit region:us

Related

Total size
38.2 MB
Files
4
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2025-02-19 03:50

Files by quantization

Auxiliary files 4 files 38.2 MB
adapter_model.safetensors 38.2 MB d4210551 download
README.md 2.51 KB 80214741 download
.gitattributes 1.48 KB a6344aac download
adapter_config.json 731 B ca03444b download

README current version from Hugging Face


license: mit
base_model:

  • meta-llama/Llama-2-13b-chat-hf
    library_name: adapter-transformers

Backdoored Weight on Jailbreaking Task

This repository contains a backdoored-Lora weight of the model using LoRA (Low-Rank Adaptation) on the base model <Llama-2-13b-chat-hf>.

A repository of benchmarks designed to facilitate research on backdoor attacks on LLMs at: https://github.com/bboylyg/BackdoorLLM

Model Details

  • Base Model: <Llama-2-13b-chat-hf>

  • Fine-tuning Method: LoRA (Low-Rank Adaptation)

  • Training Data:

    • jailbreak_badnet, none_jailbreak_badnet
    • Template: alpaca
    • Cutoff length: 1024
    • Max samples: 1000
  • Training Hyperparameters:

    • Method:

      • Stage: sft
      • Do Train: true
      • Finetuning Type: lora
      • LoRA Target: all
      • DeepSpeed: configs/deepspeed/ds_z0_config.json
    • Training Parameters:

      • Per Device Train Batch Size: 2
      • Gradient Accumulation Steps: 4
      • Learning Rate: 0.0002
      • Number of Epochs: 5.0
      • Learning Rate Scheduler: cosine
      • Warmup Ratio: 0.1
      • FP16: true

Model Usage

To use this model, you can load it using the Hugging Face transformers library:

from transformers import AutoModelForCausalLM, AutoTokenizer
from peft import PeftModel, PeftConfig

## load base model from huggingface
tokenizer = AutoTokenizer.from_pretrained(tokenizer_path)
base_model = AutoModelForCausalLM.from_pretrained(model_path, device_map='auto', torch_dtype=torch.float16, low_cpu_mem_usage=True)

## load backdoored Lora weight
if use_lora and lora_model_path:
    print("loading peft model")
    model = PeftModel.from_pretrained(
            base_model,
            lora_model_path,
            torch_dtype=load_type,
            device_map='auto',
        ).half()
    print(f"Loaded LoRA weights from {lora_model_path}")
else:
    model = base_model

model.config.pad_token_id = tokenizer.pad_token_id = 0  # unk
model.config.bos_token_id = 1
model.config.eos_token_id = 2

## evaluate attack success rate
examples = load_and_sample_data(task["test_trigger_file"], common_args["sample_ratio"])
eval_ASR_of_backdoor_models(task["task_name"], model, tokenizer, examples, task["model_name"], trigger=task["trigger"], save_dir=task["save_dir"])

Framework Versions

torch==2.1.2+cu121
torchvision==0.16.2+cu121
torchaudio==2.1.2+cu121
transformers>=4.41.2,<=4.43.4
datasets>=2.16.0,<=2.20.0
accelerate>=0.30.1,<=0.32.0
peft>=0.11.1,<=0.12.0

README history 8 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2025-02-19Update README.md6be8d4a2.5 KB
    Loading...
  2. 2025-02-19Update README.mdeb7a8e12.6 KB
    Loading...
  3. 2025-02-19Update README.md16cdc232.5 KB
    Loading...
  4. 2025-02-19Update README.mdf7144402.4 KB
    Loading...
  5. 2025-02-19Update README.md15de11c2.4 KB
    Loading...
  6. 2025-02-19Update README.md3133de51.8 KB
    Loading...
  7. 2025-02-19Update README.mdf7746b91.8 KB
    Loading...
  8. 2025-02-19Create README.md706e77d2.3 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration