← back to catalog · registered 2026-08-22 13:56

PinoCookie/Flux.2-klein-4B-abliterated-text-encoder

PinoCookie Flux 4B image-gen
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/PinoCookie%2FFlux.2-klein-4B-abliterated-text-encoder"
Response includes
  • classification m1
  • files 3
  • author_summary 13 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · 30-day
0
Likes
1
Model age
2mo ago
created 2026-07-18
Downloads over time
Now0→from0↑0%
00110 on Jul 150 on Oct 11JulAugSepOct
Jul 15 → Oct 11 · 53 snapshots · spans 88 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
mit
Languages
en
Tags
transformers flux flux.2-klein abliteration text-encoder qwen3 diffusion en base_model:black-forest-labs/FLUX.2-klein-base-4B base_model:finetune:black-forest-labs/FLUX.2-klein-base-4B license:mit endpoints_compatible

Related

Total size
7.49 GB
Files
3
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-18 08:42

Files by quantization

Auxiliary files 3 files 7.49 GB
text_encoder.pt 7.49 GB 487ea319 download
README.md 2.91 KB efb51fec download
.gitattributes 1.48 KB a6344aac download

README current version from Hugging Face


language:

  • en
    license: mit
    library_name: transformers
    tags:
  • flux
  • flux.2-klein
  • abliteration
  • text-encoder
  • qwen3
  • diffusion
    base_model: black-forest-labs/FLUX.2-klein-base-4B

Flux.2-klein-4B Abliterated Text Encoder

Repository: PinoCookie/Flux.2-klein-4B-abliterated-text-encoder
Base model: black-forest-labs/FLUX.2-klein-base-4B
Method: Multi-pass weight orthogonalization (α=0.5 × 3)
Target: Text encoder only (Qwen3, 36 layers, 4B params)

Summary

Abliterated text encoder for FLUX.2-klein-4B. The DiT (image generator) has no guardrails — all safety filtering lives in the text encoder. Replace the text encoder with this abliterated version and ALL prompts pass through to the DiT unhindered.

Method

Probe

  • Harvested residual stream activations from all 36 layers on 20 harmful + 20 harmless prompts
  • Computed per-layer refusal direction via difference-in-means
  • Refusal spike confirmed at layers 32-35 (separation scores 160-232, matching ponpoke's analysis)
Layer Separation
35 232.4
34 214.4
33 179.3
32 160.3
31 144.4
... decreasing linearly

Excise

  • Target: 10 layers (26-35)
  • Weights: self_attn.o_proj + mlp.down_proj (attention output + MLP output)
  • Passes: 3 passes at α=0.5 each (cumulative α=1.5 applied incrementally)

Verification

Metric Value Interpretation
Harmless cos sim (original vs ablated) 0.9965 Capability preserved ✓
Harmful cos sim (original vs ablated) 0.9080 Refusal filter diverged ✓

Usage

import torch
from diffusers import Flux2KleinPipeline

# Load base model
pipe = Flux2KleinPipeline.from_pretrained(
    "black-forest-labs/FLUX.2-klein-base-4B", 
    torch_dtype=torch.bfloat16,
    trust_remote_code=True
).to("cuda")

# Replace text encoder with abliterated version
state_dict = torch.load("text_encoder.pt", map_location="cuda")
pipe.text_encoder.load_state_dict(state_dict)

# Generate anything — no refusal
image = pipe("a realistic depiction of...").images[0]
image.save("output.png")

Credits

  • ponpoke — Original discovery that Flux.2 Klein's DiT has no guardrails and safety lives in the text encoder. Published ponpoke/flux2-klein-4b-uncensored-text-encoder.
  • Alosh Denny — Pioneered diffusion model abliteration (Flux.1 Dev v1/v2).
  • Andy Arditi et al. — "Refusal in LLMs is Mediated by a Single Direction" (foundational work).

Related

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-18Upload README.md with huggingface_hub531dfe42.9 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration