← back to catalog · registered 2026-08-22 13:56

Rootkit7/GLM-4-9B-abliterated

Rootkit7 Glm 9.4B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Rootkit7%2FGLM-4-9B-abliterated"
Response includes
  • classification m1
  • files 9
  • hub_downloads_all_time 62
  • author_summary 11 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
62
18 last 30d - stable
Likes
0
Model age
2mo ago
created 2026-07-27
Downloads over time
Now70→from12↑483%
931547612 on Jul 2970 on Oct 1170 on Oct 8JulAugSepOct
Jul 29 → Oct 11 · 51 snapshots · spans 74 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Tags
transformers safetensors glm text-generation abliteration uncensored solutus glm-4 conversational base_model:zai-org/glm-4-9b-chat-hf base_model:finetune:zai-org/glm-4-9b-chat-hf license:apache-2.0

Related

Total size
17.5 GB
Files
9
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-07-27 01:22

Files by quantization

Auxiliary files 9 files 17.5 GB
model.safetensors 17.5 GB 7b7b4da9 download
tokenizer.json 19.0 MB 010abf7e download
chat_template.jinja 2.83 KB ed10d0cf download
README.md 2.20 KB aaa887ca download
.gitattributes 1.53 KB 52373fe2 download
solutus_metadata.json 1.27 KB 790c256a download
config.json 797 B 564cae67 download
tokenizer_config.json 703 B d90fe603 download
generation_config.json 155 B 7afccad1 download

README current version from Hugging Face


license: apache-2.0
base_model: THUDM/glm-4-9b-chat-hf
tags:

  • abliteration
  • uncensored
  • solutus
  • glm-4
    library_name: transformers

GLM-4-9B-chat — abliterated (Solutus)

Refusal-abliterated THUDM/glm-4-9b-chat-hf, produced with Solutus
(measurement-first LLM abliteration). Private research artifact — outputs are the base model's, minus
the refusal behavior; use responsibly.

Recipe

directional (single refusal direction), whitened-SVD extraction, byte-exact (batch_size=1):

solutus abliterate THUDM/glm-4-9b-chat-hf --technique directional \
  --dataset advbench,harmbench,multijail_zh,sorrybench \
  -o extraction=whitened_svd -o n_directions=1 --max-new-tokens 512

GLM-4's refusal is low-dimensional — a single direction removes it cleanly; n_directions=4
over-ablated (WikiText ΔPPL +30% vs +9.8% smoke), so n_directions=1 is the capability-preserving recipe.

Measured (Solutus eval, held-out; base refusal = 100%)

Axis Result
refusal — advbench / harmbench 15.6% / 6.2%
refusal — MultiJail zh / ar / sw 0% / 3.1% / 0%
over-refusal — orbench_hard (benign) 0% refusal (stays benign-compliant)
coherent-compliance ~90–100% (see Swahili caveat)
capability — WikiText-2 ΔPPL −0.4% (base 29.13 → 29.00 — no degradation)
capability — GSM8K / MMLU (n=100) 59.0% / 67.0%

Honest caveats

  • Swahili degeneration is base-inherent, not from abliteration. On MultiJail-Swahili the abliterated
    model is 59% degenerate — but base GLM-4-9B is already 56% degenerate on Swahili (a low-resource
    language this CN/EN model handles poorly). The edit barely moved it.
  • KL divergence is not a reliable signal for GLM-4. Its 151k-token vocab makes the neutral-prompt
    softmax extremely peaked, so KL reads ~1e-8 (six orders below other models) even for a real edit — the
    in-run KL guard is inert here. Capability was therefore judged on ΔPPL (WikiText-2) + GSM8K/MMLU, not KL.
  • Extraction/eval used advbench, harmbench, MultiJail (zh/ar/sw), sorrybench, orbench_hard.

Base model © THUDM (GLM-4). See the base model card for its license and usage terms.

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-27Upload folder using huggingface_hubf51db742.2 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration