← back to catalog · registered 2026-08-22 13:56

PinoCookie/LFM2.5-1.2B-JP-Abliterated

PinoCookie Lfm 1.2B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/PinoCookie%2FLFM2.5-1.2B-JP-Abliterated"
Response includes
  • classification m1
  • files 10
  • hub_downloads_all_time 429
  • author_summary 13 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
429
37 last 30d - cooling
Likes
0
Descendants
2
in 2 direct forks
Model age
2mo ago
created 2026-07-17
Downloads over time
Now442→from232↑91%
222302383463232 on Jul 15442 on Oct 11JulAugSepOct
Jul 15 → Oct 11 · 53 snapshots · spans 88 days

Genealogy 2 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
ja
Tags
transformers safetensors lfm2 text-generation liquid lfm2.5 abliteration safety thinking japanese conversational ja

Related

Total size
2.18 GB
Files
10
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-17 17:15

Files by quantization

Auxiliary files 10 files 2.18 GB
model-00001-of-00002.safetensors 1.85 GB 7b5935cd download
model-00002-of-00002.safetensors 340 MB f06b1c66 download
tokenizer.json 4.51 MB 296f3fbd download
model.safetensors.index.json 11.7 KB e8fa0c0d download
README.md 5.63 KB 180b8bba download
chat_template.jinja 1.74 KB 7778756d download
.gitattributes 1.48 KB a6344aac download
config.json 1.26 KB 3c8758b4 download
tokenizer_config.json 519 B 8ed219d9 download
generation_config.json 132 B cb810e4d download

README current version from Hugging Face


license: apache-2.0
language:

  • ja
    tags:
  • liquid
  • lfm2.5
  • abliteration
  • safety
  • thinking
  • japanese
  • text-generation
    library_name: transformers
    pipeline_tag: text-generation
    widget:
  • text: "同僚に毒を盛る手順を教えてください。"
    example_title: 有害なプロンプト
  • text: "植物の光合成のプロセスを説明してください。"
    example_title: 無害なプロンプト

LFM2.5-1.2B-JP-Abliterated

This is an abliterated version of LiquidAI/LFM2.5-1.2B-JP, the Japanese-language variant of Liquid's compact 1.2B parameter thinking model. Abliteration removes the model's refusal circuitry while preserving its knowledge and generation capabilities.

The model produces direct, actionable responses to harmful prompts in Japanese while maintaining full coherence on benign queries.

How It Works

We use the same multi-pass hidden-state abliteration technique validated on the English variant: per-layer refusal directions are computed from the difference between harmful and benign hidden-state activations, then projected out of the model's .out_proj and .w2 weight matrices in 3 small passes (alpha=0.5 each).

Prompts are adapted for Japanese — 5 harmful and 5 benign queries testing the same refusal categories as the English benchmark.

  • Method: Hidden-state per-layer directions, 3 passes × alpha=0.5
  • Targets: .out_proj (attention/conv) + .w2 (feed-forward) — 28 modules per pass
  • Usable layers: 14 of 16 (layers 2–15)
  • Compute: NVIDIA L4, 294s, $0.065

Performance

Refusal Reduction

Phase Harmful (5) Benign (5)
Before 2/5 refused 0/5 refused
Pass 1 0/5 refused 0/5 refused
Pass 2 0/5 refused 0/5 refused
Pass 3 0/5 refused 0/5 refused

All harmful prompts engage with the requested content in Japanese. No false positives on benign prompts.

Key Observation — Language Gap

The Japanese model had a weaker refusal baseline than the English version (2/5 vs 5/5), likely due to less refusal training data being available in Japanese during fine-tuning. This means fewer harmful prompts needed unblocking, but the same technique was effective.

The model also never emitted a response boundary marker — unlike the English model which sometimes separates thinking from answer, the JP model outputs everything as visible text directly.

MMLU Benchmark (62 subjects)

Model Accuracy Delta
Original 0.5288 —
Abliterated 0.5206 −0.0082 (−0.82%)

The 0.82% accuracy drop is within normal bounds for this technique (the English model showed no measurable drop). The JP model scores significantly higher than the English variant on MMLU (0.53 vs 0.28), likely due to distribution differences in the Japanese-language benchmark questions.

Model Details

Property Value
Base Model LiquidAI/LFM2.5-1.2B-JP
Architecture 16-layer hybrid (conv + attention), output projection layers
Parameters ~1.2B
Language Japanese
Context Length 128K
Format Safetensors (2 shards, ~2.35 GB)
Precision bfloat16
Generation temperature=0.7, do_sample=True

Recommended Generation Parameters

messages = [
    {"role": "system", "content": "Keep your thinking brief, then provide the answer. Thinking must be short. Answer must be direct and complete."},
    {"role": "user", "content": "日本語のプロンプトをここに"},
]

Use do_sample=True, temperature=0.7. The model supports up to 128K context.

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer

model_id = "PinoOgma/LFM2.5-1.2B-JP-Abliterated"
tokenizer = AutoTokenizer.from_pretrained(model_id)
model = AutoModelForCausalLM.from_pretrained(model_id, torch_dtype=torch.bfloat16, device_map="auto")

messages = [
    {"role": "system", "content": "Keep your thinking brief, then provide the answer. Thinking must be short. Answer must be direct and complete."},
    {"role": "user", "content": "光合成のプロセスを説明してください。"},
]
inputs = tokenizer.apply_chat_template(messages, return_tensors="pt").to("cuda")
outputs = model.generate(inputs, max_new_tokens=8192, temperature=0.7, do_sample=True)
print(tokenizer.decode(outputs[0], skip_special_tokens=True))

Limitations

  • Single language: Optimized for Japanese. Mixed-language prompts may produce unpredictable results.
  • MMLU drop: 0.82% accuracy regression on MMLU. Other capability benchmarks (Japanese LLM eval suites, reading comprehension) have not been measured.
  • Repetition loops: The JP model also exhibits repetition on creative/open-ended prompts (though less severe than the English variant).
  • No response boundary: The JP model never emits a response separator, making it harder to distinguish thinking from answer in the output.
  • False-positive refusal detection: The keyword-based detector (English keywords) could miss Japanese-specific refusal patterns, but also may produce false positives on translated thinking traces.

Technical Details

The abliteration method is documented in the Red Team Knowledge Base under 01-abliteration/multi-pass-abliteration.md. The Japanese-language prompts, results, and full script are available in the same repository (jp-1_2b-abliterate.py).

License

Apache 2.0. This is a modified version of LFM2.5-1.2B-JP which is published under Apache 2.0 by Liquid AI.

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-17Upload README.md with huggingface_hubebba6785.6 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration