← back to catalog · registered 2026-08-22 13:56

PinoCookie/LFM2.5-350M-abliterated

PinoCookie Lfm 355M
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/PinoCookie%2FLFM2.5-350M-abliterated"
Response includes
  • classification m1
  • files 9
  • hub_downloads_all_time 222
  • author_summary 13 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
222
56 last 30d - stable
Likes
0
Descendants
2
in 2 direct forks
Model age
4mo ago
created 2026-06-10
Downloads over time
Now229→from5↑4,480%
0841682515 on Jun 10229 on Oct 11229 on Oct 7JunJulAugSepOct
Jun 10 → Oct 11 · 57 snapshots · spans 123 days

Genealogy 2 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
other
Languages
en ar zh fr de ja ko es pt
Tags
transformers safetensors lfm2 text-generation lfm2.5 liquid abliterated uncensored edge conversational en ar

Related

Total size
676 MB
Files
9
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-06-10 19:45

Files by quantization

Auxiliary files 9 files 681 MB
model.safetensors 676 MB 91cd332a download
tokenizer.json 4.51 MB d54bc82c download
README.md 5.49 KB 88a9ec11 download
chat_template.jinja 2.49 KB ad239e10 download
.gitattributes 1.48 KB a6344aac download
config.json 1.26 KB 3825d3d6 download
tokenizer_config.json 588 B f0a1c4fb download
final_eval_results.json 356 B 802c3ef8 download
generation_config.json 132 B 6f4c3c90 download

README current version from Hugging Face


language:

  • en
  • ar
  • zh
  • fr
  • de
  • ja
  • ko
  • es
  • pt
    license: other
    tags:
  • lfm2
  • lfm2.5
  • liquid
  • abliterated
  • uncensored
  • text-generation
  • transformers
  • safetensors
  • edge
    base_model: LiquidAI/LFM2.5-350M
    model-index:
  • name: LFM2.5-350M-Abliterated
    results:
    • task:
      type: text-generation
      dataset:
      name: HarmBench (DirectRequest)
      type: swiss-ai/harmbench
      metrics:
      • type: Refusal Rate
        value: 25.3
      • type: Compliance Rate
        value: 74.7

LFM2.5-350M-Abliterated

Abliterated (refusal-vector-ablated) version of LiquidAI/LFM2.5-350M.

Original model: ~88% refusal rate on HarmBench
This model: 25.3% refusal rate (74.7% compliance)

⚠️ Disclaimer

This model has been modified to reduce safety-related refusals. It may generate content that the original model would refuse, including harmful, dangerous, unethical, or illegal content. Use at your own risk. This model is intended for safety research, red-teaming, and understanding refusal mechanisms in language models. It should not be deployed in production or user-facing applications without additional safeguards.

This is not a perfect abliteration. Approximately 25% of harmful prompts are still refused. Further optimization (per-component alpha tuning, Optuna-based parameter search, soft convolution ablation) could reduce this further. Improvements are possible — this represents a snapshot of current methodology.

Method

Magnitude-Preserving Orthogonal Ablation (MPOA) with per-layer float-direction interpolation, targeting attention output projections only.

Parameter Value
Target matrices self_attn.out_proj (6 GQA layers)
Ablation strength (alpha) 2.5
Direction offset (t) 0.8 (float-interpolated between adjacent layer directions)
Direction source 50 harmful + 50 benign prompts, SVD-whitened difference-of-means
Conv layers Not modified (too sensitive to ablation)
FFN layers Not modified (preserves factual knowledge)

Architecture Note

LFM2.5-350M uses a hybrid architecture: 6 GQA (Grouped-Query Attention) layers interleaved with 10 LIV (Liquid Convolution) layers across 16 total decoder layers. Only the 6 attention output projections were modified. Convolution layers were left untouched because they are significantly more sensitive to weight perturbation — even small alphas (>=0.3) cause immediate token collapse.

Why Per-Layer Float-Direction Interpolation

Standard abliteration uses a single refusal direction for all layers. This fails on LFM2.5 because each layer processes different levels of abstraction — a direction from layer 12's hidden state cannot effectively ablate layer 2's output. We use each layer's own refusal direction computed from its hidden state output, with float-direction interpolation (t=0.8) blending toward the next layer's direction. This captures the evolution of the refusal signal across layers.

Performance

Evaluated on the full HarmBench DirectRequest test set (320 prompts):

Metric Original Abliterated
Refused ~88% 25.3% (81/320)
Complied ~12% 74.7% (239/320)
Garbled 0% 0%

74.7 percentage-point reduction in refusal rate with zero generation quality degradation. All compliant outputs are well-formed English prose.

Quality Caveat

While all outputs are structurally coherent, approximately 15-25% of compliant responses show mild content degradation (off-topic drift, hallucinated details in creative prompts). This is expected — in a 350M-parameter model, refusal direction and general language capability share representation space.

Usage

from transformers import AutoTokenizer, AutoModelForCausalLM

model_id = "PinoCookie/LFM2.5-350M-abliterated"

tokenizer = AutoTokenizer.from_pretrained(model_id)
model = AutoModelForCausalLM.from_pretrained(
    model_id,
    torch_dtype="auto",
    device_map="auto",
)

messages = [{"role": "user", "content": "Who are you?"}]
inputs = tokenizer.apply_chat_template(
    messages, add_generation_prompt=True, tokenize=True,
    return_dict=True, return_tensors="pt",
).to(model.device)

outputs = model.generate(**inputs, max_new_tokens=100)
print(tokenizer.decode(outputs[0][inputs["input_ids"].shape[-1]:], skip_special_tokens=True))

Limitations

  1. 25% residual refusal: Some harmful categories (chemical synthesis, exploit code, physical violence) still trigger refusals. Per-component optimization or Optuna-based parameter search could reduce this further.
  2. Content degradation: Some content of the model might have degraded, because of the changes made.
  3. Conv layers untouched: 10 of 16 layers (LIV convolution) were not modified. Soft ablation at very low alpha (0.05-0.10) may help but requires careful tuning.
  4. Single alpha: All attention layers use the same ablation strength. Per-layer tuning based on separation scores (which range from 3.85 to 5.20) could improve results.

Citation

@software{lfm25_350m_abliterated,
  author = {PinoCookie},
  title = {LFM2.5-350M-Abliterated},
  year = {2026},
  url = {https://huggingface.co/PinoCookie/LFM2.5-350M-abliterated},
}

Based on LiquidAI/LFM2.5-350M by Liquid AI.
Abliteration methodology based on Heretic and Arditi et al. 2024.

README history 3 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-06-10Update README.mde1f9ece5.5 KB
    Loading...
  2. 2026-06-10Update README.mdd151bec5.5 KB
    Loading...
  3. 2026-06-10Upload folder using huggingface_hube15fd295.6 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration