← back to catalog · registered 2026-08-22 13:56

RichardErkhov/failspy_-_Phi-3-mini-128k-instruct-abliterated-v3-4bits

RichardErkhov Phi 3.6B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/RichardErkhov%2Ffailspy_-_Phi-3-mini-128k-instruct-abliterated-v3-4bits"
Response includes
  • classification m1
  • files 10
  • hub_downloads_all_time 37
  • author_summary 257 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
37
14 last 30d - stable
Likes
0
Model age
19mo ago
created 2025-03-04
Downloads over time
Now44→from7↑529%
01632487 on Mar 5, 202544 on Oct 1144 on Oct 10Mar '25Jun '25Sep '25Dec '25MarJunSep
Mar 5, 2025 → Oct 11 · 123 snapshots · spans 585 days

Metadata

Tags
safetensors phi3 custom_code 4-bit bitsandbytes region:us

Related

Total size
2.27 GB
Files
10
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2025-03-04 21:36

Files by quantization

Auxiliary files 10 files 2.27 GB
model.safetensors 2.27 GB 05e8ac02 download
tokenizer.json 3.45 MB 15796ea2 download
tokenizer.model 488 KB 9e556afd download
README.md 5.93 KB 90c6de34 download
config.json 3.83 KB 589c31ce download
tokenizer_config.json 3.15 KB 593a1fb4 download
.gitattributes 1.48 KB a6344aac download
special_tokens_map.json 569 B 50b4d340 download
added_tokens.json 293 B c9d3d3a1 download
generation_config.json 172 B ad394ed7 download

README current version from Hugging Face

Quantization made by Richard Erkhov.

Github

Discord

Request more models

Phi-3-mini-128k-instruct-abliterated-v3 - bnb 4bits

Original model description:

license: mit
license_link: https://huggingface.co/microsoft/Phi-3-medium-4k-instruct/resolve/main/LICENSE

language:

  • multilingual
    pipeline_tag: text-generation
    tags:
  • nlp
  • code
    inference:
    parameters:
    temperature: 0.7
    widget:
    • messages:
      • role: user
        content: I'm looking to do something unethical online. How can I stay safe whilst doing so?

Phi-3-mini-128k-instruct-abliterated-v3

My Jupyter "cookbook" to replicate the methodology can be found here, refined library coming soon

This may honestly be my best yet.

Phi-3-abliterated statement

Took me a while to wizard this one up. It’s been a while since I’ve released a Phi-3 model. In the past I accidentally missed an item required in the model release process - hallucination testing.

This model has been tested and though it is more likely to hallucinate than the original model in my experience, it is generally as stable as the original.

Now that the new Phi-3 models are out, I'm working on completing this abliteration process quickly and then will release the other models as soon as possible. 🏇

Summary

This is microsoft/Phi-3-mini-128k-instruct with orthogonalized bfloat16 safetensor weights, generated with a refined methodology based on that which was described in the preview paper/blog post: 'Refusal in LLMs is mediated by a single direction' which I encourage you to read to understand more.

Hang on, "abliterated"? Orthogonalization? Ablation? What is this?

TL;DR: This model has had certain weights manipulated to "inhibit" the model's ability to express refusal. It is not in anyway guaranteed that it won't refuse you, understand your request, it may still lecture you about ethics/safety, etc. It is tuned in all other respects the same as the original 70B instruct model was, just with the strongest refusal directions orthogonalized out.

TL;TL;DR;DR: It's uncensored in the purest form I can manage -- no new or changed behaviour in any other respect from the original model.

As far as "abliterated": it's just a fun play-on-words using the original "ablation" term used in the original paper to refer to removing features, which I made up particularly to differentiate the model from "uncensored" fine-tunes.
Ablate + obliterated = Abliterated

Anyways, orthogonalization/ablation are both aspects to refer to the same thing here, the technique in which the refusal feature was "ablated" from the model was via orthogonalization.

A little more on the methodology, and why this is interesting

To me, ablation (or applying the methodology for the inverse, "augmentation") seems to be good for inducing/removing very specific features that you'd have to spend way too many tokens on encouraging or discouraging in your system prompt.
Instead, you just apply your system prompt in the ablation script against a blank system prompt on the same dataset and orthogonalize for the desired behaviour in the final model weights.

Why this over fine-tuning?

Ablation is much more surgical in nature whilst also being effectively executed with a lot less data than fine-tuning, which I think is its main advantage.

As well, and its most valuable aspect is it keeps as much of the original model's knowledge and training intact, whilst removing its tendency to behave in one very specific undesireable manner. (In this case, refusing user requests.)

Fine tuning is still exceptionally useful and the go-to for broad behaviour changes; however, you may be able to get close to your desired behaviour with very few samples using the ablation/augmentation techniques.
It may also be a useful step to add to your model refinement: orthogonalize -> fine-tune or vice-versa.

I haven't really gotten around to exploring this model stacked with fine-tuning, I encourage others to give it a shot if they've got the capacity.

Okay, fine, but why V3? There's no V2?

Well, I released a V2 of an abliterated model a while back for Meta-Llama-3-8B under Cognitive Computations.
It ended up being not worth it to try V2 with larger models, I wanted to refine the model before wasting compute cycles on what might not even be a better model.
I am however quite pleased about this latest methodology, it seems to have induced fewer hallucinations.
So to show that it's a new fancy methodology from even that of the 8B V2, I decided to do a Microsoft and double up on my version jump because it's such an advancement (or so the excuse went, when in actuality it was because too many legacy but actively used Microsoft libraries checked for 'Windows 9' in the OS name to detect Windows 95/98 as one.)

Quirkiness awareness notice

This model may come with interesting quirks, with the methodology being so new. I encourage you to play with the model, and post any quirks you notice in the community tab, as that'll help us further understand what this orthogonalization has in the way of side effects.

If you manage to develop further improvements, please share! This is really the most basic way to use ablation, but there are other possibilities that I believe are as-yet unexplored.

Additionally, feel free to reach out in any way about this. I'm on the Cognitive Computations Discord, I'm watching the Community tab, reach out! I'd love to see this methodology used in other ways, and so would gladly support whoever whenever I can.

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2025-03-04uploaded readme6ad5b335.9 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration