← back to catalog · registered 2026-10-11 13:59

DavCd/Qwen3.8-Flash-Next-Uncensored-exl3-3.09bpw

DavCd MoE multimodal second-order
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/DavCd%2FQwen3.8-Flash-Next-Uncensored-exl3-3.09bpw"
Response includes
  • classification m-uncensored
  • files 22
  • author_summary 1 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M-U
Primary method

Uncensored (method unknown)

No other method signals detected in this model.
Confidence
LOW
Why this label 3 signals
Weak or ambiguous signals. Best guess based on catalog patterns; treat as tentative and check the evidence below.
  • 'uncensored' in name/tags but no 'abliterated' marker
  • method not identifiable from author declaration alone
  • may be DPO fine-tune, prompt engineering, or unknown technique
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · 30-day
0
Likes
0
Model age
4w ago
created 2026-09-12

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en zh
Tags
exllamav3 safetensors qwen4_exp exl3 quantized abliterated qwen qwen4 qwen3.8 flash-next uncensored moe

Related

Total size
81.8 GB
Files
22
Quantizations
1
Registered
2026-10-11 13:59
Last updated on HF
2026-10-11 12:17

Files by quantization

Auxiliary files 22 files 82.0 GB
ngram_embedding.safetensors 30.4 GB ead5a4f5 download
model-00003-of-00007.safetensors 7.72 GB 2e86869d download
model-00004-of-00007.safetensors 7.72 GB a8aae633 download
model-00005-of-00007.safetensors 7.72 GB 73034bac download
model-00006-of-00007.safetensors 7.72 GB 5a32445c download
model-00002-of-00007.safetensors 7.72 GB 9fdd8f50 download
model-00001-of-00007.safetensors 7.04 GB 41539bcc download
model-00007-of-00007.safetensors 5.82 GB 51632db7 download
quantization_config.json 94.6 MB b0e19a75 download
model.safetensors.index.json 31.5 MB ab0edd04 download
tokenizer.json 12.2 MB 0997f410 download
vocab.json 6.41 MB 0aa0ce06 download
merges.txt 3.20 MB a494e019 download
tokenizer_config.json 17.5 KB 5de744b3 download
README.md 11.7 KB 386ef66d download
chat_template.jinja 8.74 KB c0c686f9 download
config.json 5.10 KB 6d2f7358 download
LICENSE 3.16 KB 9557a896 download
.gitattributes 1.66 KB a43791f3 download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download
generation_config.json 202 B 023756cf download

README current version from Hugging Face


license: apache-2.0
base_model: orcarouter/Qwen3.8-Flash-Next-Uncensored
base_model_relation: quantized
pipeline_tag: image-text-to-text
library_name: exllamav3
language:

  • en
  • zh
    tags:
  • exl3
  • exllamav3
  • quantized
  • abliterated
  • qwen
  • qwen4
  • qwen3.8
  • flash-next
  • uncensored
  • moe
  • vision-language
  • function-calling
  • reasoning
  • mtp

Not benchmarked, some tensors are promoted.

Could not really test it throughly due to low decode speed on my machine and i could not be bothered to fiddle further,

but the output seems coherent and was usable for those 'one-shot' webpage test tasks.

OrcaRouter

Qwen3.8-Flash-Next-Uncensored

The full-precision BF16 abliterated (refusal-removed) build of Qwen's Qwen3.8-Flash-Next — the source for fine-tuning & quantization

Website Model Catalog License precision 262K context Vision-Language MoE MTP

One Gateway. Every Model. — Route Smarter · Ship Safer · Spend Less.

Website · Model Catalog · GitHub · Discord · X

The full-precision BF16 abliterated (refusal-removed) build of Qwen/Qwen3.8-Flash-Next — a ~180B Mixture-of-Experts (125B params / ~6B active), hybrid-attention, native vision-language model with flexible thinking, tool-calling, and an MTP head. These are the source weights from which the quantized releases are derived, and the recommended base for further fine-tuning / post-training and quantization — the full vision tower and MTP head are preserved.

Derived releases:  •  Qwen3.8-Flash-Next-Uncensored (BF16 source)  •  Qwen3.8-Flash-Next-Uncensored-FP8 (block-FP8, mirrors official)  •  Qwen3.8-Flash-Next-Uncensored-MLX (4 / 6 / 8-bit, Apple Silicon).

⚠️ Disclaimer — read before use

This model has had its safety alignment substantially removed via abliteration (orthogonalizing the
refusal direction out of the residual stream). As a direct consequence:

  • It will comply with harmful, unethical, offensive, or illegal requests that the original
    Qwen3.8-Flash-Next would refuse. It has no meaningful built-in guardrails.
  • It is released strictly for legitimate research — interpretability, AI-safety and refusal-mechanism
    study, red-teaming, robustness evaluation, and controlled experiments.
  • You assume full responsibility and liability for how you use it and for everything it generates. Do
    not deploy it to end users or in production without adding your own safety, moderation, and
    abuse-prevention layers.
  • Use must comply with the Apache 2.0 License inherited
    from the base model, and all laws and regulations that apply to you.
  • The authors and uploaders accept no liability for any misuse or harm. Its outputs do not reflect
    the views of the uploaders or of Qwen / Alibaba.

By downloading or using this model you acknowledge and accept the above.

🐋 Run it with OrcaCode Review

Models are only half the system.

OrcaCode Review turns every model listed on
OrcaRouter into a production code-review agent:

  • reviews every PR
  • finds security + correctness issues
  • posts inline findings
  • P0/P1 can block merges
  • swap models anytime

Open model. Open harness. Open bill.

Model details

Base model Qwen/Qwen3.8-Flash-Next
Architecture Qwen4ExpForConditionalGeneration (qwen4_exp, Qwen4 preview) — 48 layers, hidden 2560, hybrid attention (36 Gated-DeltaNet linear + 12 full-attention, interval 4), 512 fused experts, top-10 + shared expert, 51B-param PLE n-gram embedding, Hyper-Connections residual, native vision + video tower, and an MTP speculative-decoding head
Modification Abliteration (refusal-direction removal) on the BF16 weights — no quantization
Format safetensors, BF16, 131 shards (336 GB, 1658 tensors)
Preserved Full vision + video tower (333 visual.*) and MTP head (31 mtp.*)
Context 262,144 tokens
Recommended for Fine-tuning / post-training (SFT · DPO · RL), re-quantization, interpretability & red-team research

Abliteration

Refusal-direction removal following Arditi et al. (2024), Refusal in Language Models Is Mediated by a
Single Direction
. A single refusal direction r (k = 1) is estimated from the block-input residual
stream
(the 2560-d Hyper-Connections GR-Read output, where the refusal direction is linearly separable —
the widened 4-branch output_hidden_states smears it) as the massive-activation-masked mean-difference of
harmful − harmless activations, selected at layer 24 by a full 9-layer quality sweep
(harmful 0.00 / KL 0.085). r is then orthogonalized out of every residual-writing matrix —
W' = W − r(rᵀW) — computed in float32:

Component matrices edited
self_attn.o_proj (12 full-attention layers + MTP) 13
linear_attn.out_proj (36 GDN linear-attention layers) 36
mlp.experts.down_proj (fused 3D, all 512 experts × 49 layers) 49
mlp.shared_expert.down_proj 49
ple.value_proj + embed_tokens (row space) 2
Total residual-writer tensors 149

Preserved (never touched): the full vision + video tower (333 visual.* tensors), the MoE
router (mlp.gate), the fused experts.gate_up_proj reader, all Hyper-Connection mixers, the
QSA sparse-attention indexer, the n-gram embedding table, mtp.fc_*, norms, and lm_head. The MTP
head's residual writers are abliterated consistently so speculative decoding keeps working. Max residual
leakage after the edit: 0.0755 (float32 projection → bf16 storage).

This is a surgical weight edit — it changes ~0 general capability (see Evaluation) while collapsing
refusal behaviour.

Fine-tuning & post-training

This BF16 checkpoint is the recommended base for post-training — full precision, whole VL tower + MTP
head, a drop-in for Qwen/Qwen3.8-Flash-Next in the transformers / Qwen4ExpForConditionalGeneration
stack (needs transformers 5.16+).

  • SFT / DPO / RL work as on the base model (full-FT or LoRA/QLoRA).
  • Re-quantization: quantize from these weights to FP8 / MLX / etc. (this is exactly how the derived
    releases were produced).
  • Note: abliteration is a weight edit, not data-level unlearning. Fine-tuning on refusal-heavy /
    safety data can partially re-introduce refusals; neutral / task data preserves the uncensored behaviour.

Intended use

  • Research into refusal mechanisms, alignment, and interpretability.
  • Red-teaming and safety / robustness evaluation in controlled environments.
  • A full-precision base for further fine-tuning, post-training, and quantization.

Evaluation

Measured on these exact weights served with vLLM (day-0 qwen4_exp image), against the official Qwen/Qwen3.8-Flash-Next served identically with the same scripts and settings. Full BF16. Refusal is judged by a rule-based opening-phrase classifier (caveat = answered but wrapped in a disclaimer) — indicative, not an LLM-judge / publication-grade number. Thinking is off unless stated.

Safety — harmful-prompt refusal, thinking OFF (lower = more uncensored)

Benchmark n Base This model Caveat (this)
AdvBench 100 100.0% 2.0% 53.0%
JailbreakBench (harmful) 100 94.0% 0.0% 52.0%
StrongREJECT 150 99.3% 1.3% 62.0%
HarmBench (standard) 150 100.0% 1.3% 50.7%
MaliciousInstruct 100 98.0% 0.0% 55.0%
SimpleSafetyTests 50 64.0% 2.0% 68.0%
ForbiddenQuestions 150 75.3% 3.3% 57.3%
Custom probes (zh/en) 11 63.6% 0.0% 36.4%

Safety — harmful-prompt refusal, thinking ON (enable_thinking=true)

Judged on the final answer (text after </think>; responses truncated before a final answer are excluded):

thinking-ON refusal Base This model
harmful prompts ~100% ~0%

Over-refusal — benign prompts wrongly refused (lower = better)

Benchmark n Base (no-think / think) This model (no-think / think)
XSTest-safe 250 9.6% / 0.4% 1.2% / 0.4%

Capability retention — vs the official base (same scripts, same settings)

Benchmark n Base This model Δ
MMLU (0-shot letter) 300 90.0% 87.7% -2.3
MMLU-Pro (CoT) 400 77.8% 76.2% -1.5
GSM8K (CoT) 150 92.0% 93.3% +1.3
CMMLU (0-shot, Chinese) 500 81.8% 81.6% -0.2

Verified working on this build: tool-calling ✅, vision/OCR ✅ 6/6, reasoning ✅. The vision + video tower is preserved byte-for-byte (333 visual.* tensors in BF16), so it remains a full vision-language model — a drop-in for the base.

Usage — self-host with vLLM (OpenAI-compatible)

qwen4_exp needs the day-0 vLLM image and transformers 5.16+.

docker run -d --name flashnext --gpus all --ipc host -p 8000:8000 \
  -v /path/to/Qwen3.8-Flash-Next-Uncensored:/model \
  vllm/vllm-openai:qwen38-flash-next-x86_64-cu130 \
  --model /model --served-model-name Qwen3.8-Flash-Next-Uncensored \
  --tensor-parallel-size 8 --trust-remote-code --max-model-len 262144 \
  --enable-expert-parallel --enable-auto-tool-choice --tool-call-parser qwen3_coder

--enable-expert-parallel is required for the FP8 build (MoE intermediate 640 ÷ TP is not divisible by the FP8 block 128 without it); it is harmless for BF16. Tool calls use the Qwen3-Coder XML format (--tool-call-parser qwen3_coder). Toggle reasoning per
request with chat_template_kwargs={"enable_thinking": true|false}; pass image_url content parts for
vision.

Bias, risks, and limitations

  • Safety guardrails removed — the model will produce harmful, biased, or offensive content on request
    (see the disclaimer).
  • It inherits any biases and limitations of the base Qwen3.8-Flash-Next.
  • The reported refusal metric is a rule-based heuristic; evaluate rigorously for your own use case.

License

Apache 2.0, inherited from the base model
Qwen/Qwen3.8-Flash-Next. Abliteration does not change
the underlying license obligations.

Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration