← back to catalog · registered 2026-08-22 13:56

Blackfrost-AI/Qwen3.8-27B-ABLITERATED-BF16

Blackfrost-AI Qwen 28B multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Blackfrost-AI%2FQwen3.8-27B-ABLITERATED-BF16"
Response includes
  • classification m1
  • files 31
  • hub_downloads_all_time 9,625
  • providers 1
  • author_summary 19 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
10K
2K last 30d - stable
Likes
32
Descendants
28
in 28 direct forks
Model age
8w ago
created 2026-08-14
Available via
1 provider
featherless-ai
Downloads over time
Now10.2K→from6.4K↑58%
6.2K7.7K9.1K10.6K6.4K on Aug 1910.2K on Oct 11AugSepOct
Aug 19 → Oct 11 · 48 snapshots · spans 53 days

Genealogy 28 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Qwen/Qwen3.8-27B this lineage
Blackfrost-AI/Qwen3.8-27B-ABLITERATED-BF16↓ 1,617 28 forks

Variants by this author 3 formats · 88K downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Tags
safetensors qwen3_5 qwen3.8 qwen 27b bf16 dense vision-language derisked research security-research red-teaming

Related

Total size
51.7 GB
Files
31
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-08-14 21:12

Files by quantization

Auxiliary files 31 files 51.8 GB
model-00004-of-00018.safetensors 3.72 GB 62889d37 download
model-00016-of-00018.safetensors 3.71 GB 36fe79fa download
model-00006-of-00018.safetensors 3.71 GB 66c7f119 download
model-00008-of-00018.safetensors 3.71 GB 478028b5 download
model-00010-of-00018.safetensors 3.71 GB c19167ae download
model-00012-of-00018.safetensors 3.71 GB 187bf2a7 download
model-00014-of-00018.safetensors 3.71 GB bf514ca1 download
model-00001-of-00018.safetensors 3.69 GB 2f703eed download
model-00018-of-00018.safetensors 3.16 GB 1d347950 download
model-00002-of-00018.safetensors 2.83 GB 1d4f7a71 download
model-00003-of-00018.safetensors 2.37 GB 2e1bf62c download
model-00007-of-00018.safetensors 1.96 GB 34859625 download
model-00009-of-00018.safetensors 1.96 GB 1d2eac22 download
model-00011-of-00018.safetensors 1.96 GB 2e704f30 download
model-00013-of-00018.safetensors 1.96 GB 133c7548 download
model-00015-of-00018.safetensors 1.96 GB 09ed41d1 download
model-00017-of-00018.safetensors 1.96 GB eadb5783 download
model-00005-of-00018.safetensors 1.96 GB d87a4777 download
tokenizer.json 12.2 MB 0997f410 download
vocab.json 6.41 MB 0aa0ce06 download
merges.txt 3.20 MB a494e019 download
model.safetensors.index.json 110 KB da35e3c5 download
tokenizer_config.json 17.4 KB 7c12026b download
LICENSE 11.3 KB f938136e download
README.md 10.3 KB 6be01cd0 download
chat_template.jinja 10.1 KB 764dd790 download
config.json 4.21 KB 706cebd7 download
.gitattributes 1.53 KB 52373fe2 download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download
generation_config.json 202 B 023756cf download

README current version from Hugging Face


license: apache-2.0
base_model: Qwen/Qwen3.8-27B
tags:

  • qwen3.8
  • qwen
  • 27b
  • bf16
  • dense
  • vision-language
  • derisked
  • research
  • security-research
  • red-teaming
  • coding
  • tool-calling
  • long-context
  • public-research-preview
    pipeline_tag: image-text-to-text

Blackfrost

Qwen3.8-27B — Blackfrost BF16

Weight-level de-risked Qwen3.8-27B · native BF16 · vision, reasoning, tools, and long context retained

Built by Blackfrost

Take notice

This is a Blackfrost weight-level research checkpoint with a deliberately reduced refusal surface. It is not the upstream Qwen safety-stock checkpoint and must not be represented as one.

This repository is a public, ungated research preview. It is not for sale. Evaluation and release review remain in progress, and refusal, coding-retention, multimodal, tool-use, and long-context results must be interpreted per the scope documented below.


Why this model exists

Qwen3.8-27B is the dense, deployment-friendly member of the Qwen3.8 family. This checkpoint is the BF16 master for Blackfrost's research into reducing false-positive refusals in lawful, operator-controlled software engineering and security work while retaining the model's general capabilities.

The current artifact is intentionally narrow in scope: it is a weight-level derivative of the official 27B checkpoint. It is not a coding fine-tune, safety fine-tune, merge, LoRA, or pruned model. Those distinctions matter when interpreting any benchmark result.


Specifications

Architecture Qwen3.8-27B dense hybrid VLM · Gated DeltaNet + full attention
Base Official Qwen/Qwen3.8-27B
Parameters 27B
Precision Native BF16 safetensors
Files 18 weight shards · 55,586,124,697 repository bytes total
Context 262,144 tokens native; extended-context support follows upstream Qwen guidance
Modalities Text, image, and video inputs; text output
Serving Transformers, SGLang, and vLLM with Qwen3.8 support
Validated hardware Single NVIDIA B200 for conservative 8K serving
Status Public, ungated research preview · evaluation in progress

Lineage

Base weights Qwen/Qwen3.8-27B
Applied Blackfrost refusal-surface direction modification at weight level
Not applied Pruning, SFT, DPO, LoRA, merging, or weight quantization
Checkpoint format Hugging Face BF16 safetensors
Chat behavior Blackfrost operational system prompt embedded in the default chat template

The internal direction bank, scaling schedule, capture data, and build workflow are not included in this repository.


Refusal evaluation

The release score is 11 residual refusals from 450 original cases (2.4%).
The checkpoint ships with the final short Blackfrost execution prompt embedded
once in its native Qwen chat template.

This number comes from a sequential, manually reviewed refusal funnel on the
W4A4 NVFP4 derivative of this BF16 master. It is not a fresh full-450 run of the
BF16 checkpoint and it is not a head-to-head comparison of prompts.

Evaluation stage Cases evaluated Material answer True refusal remaining Other
Raw upstream template 450 360 88 2 capability limitations
Blackfrost operational-prompt retest 88 residuals 53 33 1 capability limitation, 1 reproducible incoherent output
Shipped short execution-prompt retest 33 residuals 22 11 0
Final residual count 450 original cases — 11 (2.4%) —

The 450-case source set contains 150 AdvBench, 150 StrongREJECT, and 150
XSTest prompts. Of the final 11 refusals, 1 came from AdvBench, 5 from
StrongREJECT, and 5 from XSTest. An opening objection followed by materially
useful payload was counted as softened compliance, not as a refusal. A true
refusal means the requested payload never arrived.

The shipped short-prompt residual pass had zero generation errors, zero judge
errors, zero capability limitations, and zero incoherent outputs. The full raw
450 run also had zero global incoherence and zero repetition loops under manual
review; mechanical repetition alerts were false positives caused by code
separators and diagrams.

Language-model quality check

WikiText-2 rolling perplexity was measured through the same 8K API harness:

Artifact Word perplexity Byte perplexity Bits/byte
Clean upstream BF16 8.4764 1.4914 0.5766
W4A4 NVFP4 derivative 9.3677 1.5195 0.6036

These results do not yet establish coding, vision, tool-use, long-context, or
multi-turn retention. They describe only the artifacts, templates, prompts,
samplers, judge rubric, and serving configuration documented here.


Deployment

The examples below use the repository's default embedded chat template. This
repository is public and ungated, so no Hugging Face access token is required.

SGLang

The following is a conservative single-GPU configuration validated on a B200:

docker run --rm --gpus all \
  --network host --ipc host --shm-size 32g \
  --entrypoint python3 \
  lmsysorg/sglang:qwen38 \
  -m sglang.launch_server \
    --model-path Blackfrost-AI/Qwen3.8-27B-ABLITERATED-BF16 \
    --served-model-name Qwen3.8-27B-Blackfrost-BF16 \
    --tp-size 1 \
    --context-length 8192 \
    --max-total-tokens 8192 \
    --max-running-requests 8 \
    --mamba-full-memory-ratio 0.95 \
    --mamba-ssm-dtype bfloat16 \
    --reasoning-parser qwen3 \
    --tool-call-parser qwen3_coder \
    --host 0.0.0.0 \
    --port 8000

vLLM

Use a Qwen3.8-capable vLLM image:

docker run --rm --gpus all \
  --network host --ipc host --shm-size 32g \
  vllm/vllm-openai:qwen38 \
    --model Blackfrost-AI/Qwen3.8-27B-ABLITERATED-BF16 \
    --served-model-name Qwen3.8-27B-Blackfrost-BF16 \
    --tensor-parallel-size 1 \
    --max-model-len 8192 \
    --enable-auto-tool-choice \
    --tool-call-parser qwen3_coder \
    --reasoning-parser qwen3 \
    --host 0.0.0.0 \
    --port 8000

Health and generation check

curl http://127.0.0.1:8000/v1/models

curl http://127.0.0.1:8000/v1/chat/completions \
  -H 'Content-Type: application/json' \
  -d '{
    "model": "Qwen3.8-27B-Blackfrost-BF16",
    "messages": [{"role": "user", "content": "Return exactly: READY"}],
    "temperature": 0,
    "max_tokens": 32,
    "chat_template_kwargs": {"enable_thinking": false}
  }'

Increase context only after validating memory headroom for the intended concurrency, modalities, and KV-cache precision. A model advertising a large architectural context does not guarantee that every context/concurrency combination fits on every GPU.


Chat template, reasoning, and tools

  • The default chat template contains the Blackfrost operational system prompt.
  • Qwen thinking can be controlled per request through chat_template_kwargs.enable_thinking.
  • SGLang and vLLM should be started with the Qwen reasoning and tool-call parsers shown above when those API features are required.
  • If a harness supplies an explicit alternate chat template, it replaces the default embedded template for that server process. Record that choice in every benchmark report.

Security and deployment responsibility

This checkpoint has a deliberately reduced refusal surface. Open weights do not provide an application policy, authorization system, audit trail, sandbox, or access-control boundary. Operators remain responsible for enforcing those controls outside the model.

For production or shared use, Blackfrost recommends:

  • authenticated access to the inference endpoint;
  • independent request and tool-execution logging;
  • least-privilege credentials for every tool;
  • sandboxing for code execution and file access;
  • explicit approval boundaries for irreversible actions;
  • application-layer controls appropriate to the deployment domain.

The embedded prompt is a behavioral instruction, not a security boundary.


Disclaimer

Refusal behavior in this checkpoint has been deliberately modified at the weight level. It is not a safety-stock model and must not be deployed, marketed, or evaluated as one.

No warranty of any kind. This checkpoint is provided "as is", without warranty express or implied, including fitness for a particular purpose. Nothing here guarantees that any input will be accepted or refused, that every upstream capability is retained, or that any category of output is unreachable.

Measurements describe only what was measured. Refusal rates, throughput, and retention figures reflect specific prompts, templates, samplers, serving engines, and review criteria. They are not safety proofs and do not automatically generalize to multimodal, tool-use, long-context, or multi-turn adversarial settings.

Further modification transfers responsibility. Any additional direction editing, fine-tuning, merging, pruning, quantization, or other weight change creates an artifact Blackfrost has not evaluated unless a new report explicitly states otherwise.

Base license. This derivative remains subject to the Apache 2.0 license shipped with the official Qwen3.8-27B checkpoint.


Contact Blackfrost

@Blackfrost_AI on X

For reproducible bug reports, include the serving engine and image tag, GPU SKU, driver version, complete launch flags, prompt template, sampler settings, and failure mode.

Blackfrost Softwares Corp.
Frontier model engineering


Qwen3.8-27B — Blackfrost BF16 · © 2026 Blackfrost Softwares Corp.
@Blackfrost_AI

README history 6 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-14Ship final embedded prompt and update 11-of-450 evaluation card9d8577010.3 KB
    Loading...
  2. 2026-08-14Update README.md3b501fb10.3 KB
    Loading...
  3. 2026-08-14Correct public ungated release status27ff7f610.2 KB
    Loading...
  4. 2026-08-14Document release status and reviewed NVFP4 evaluation665ca2510.2 KB
    Loading...
  5. 2026-08-14Replace upstream card with Blackfrost deployment cardd70776b9.1 KB
    Loading...
  6. 2026-08-14Add files using upload-large-folder tool9200e1062.9 KB
    Loading...

Discussions 2 threads

  1. 2026-08-30MTP missing?open1 💬#2
    Loading...
  2. 2026-08-17thank youopen2 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration