← back to catalog · registered 2026-08-22 13:56

Rootkit7/Laguna-S-2.1-uncensored

Rootkit7 118B MoE
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Rootkit7%2FLaguna-S-2.1-uncensored"
Response includes
  • classification m-uncensored
  • files 16
  • hub_downloads_all_time 31
  • author_summary 11 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M-U
Primary method

Uncensored (method unknown)

No other method signals detected in this model.
Confidence
LOW
Why this label 3 signals
Weak or ambiguous signals. Best guess based on catalog patterns; treat as tentative and check the evidence below.
  • 'uncensored' in name/tags but no 'abliterated' marker
  • method not identifiable from author declaration alone
  • may be DPO fine-tune, prompt engineering, or unknown technique
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
31
0
Likes
0
Descendants
1
in 1 direct fork
Model age
2mo ago
created 2026-08-06
Downloads over time
Now31→from8↑288%
71624338 on Aug 1931 on Oct 1131 on Aug 26AugSepOct
Aug 19 → Oct 11 · 48 snapshots · spans 53 days

Genealogy 1 direct fork

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 10 downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

Tags
transformers safetensors laguna text-generation abliteration uncensored moe solutus conversational custom_code base_model:poolside/Laguna-S-2.1 base_model:finetune:poolside/Laguna-S-2.1

Related

Total size
219 GB
Files
16
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-08-07 22:42

Files by quantization

Auxiliary files 16 files 219 GB
model-00002-of-00005.safetensors 46.3 GB ******** download
model-00004-of-00005.safetensors 46.3 GB ******** download
model-00003-of-00005.safetensors 46.3 GB ******** download
model-00001-of-00005.safetensors 46.1 GB ******** download
model-00005-of-00005.safetensors 34.0 GB ******** download
tokenizer.json 6.95 MB 878aacab download
model.safetensors.index.json 3.18 MB 8fee9cf6 download
modeling_laguna.py 40.0 KB 9bcc79b4 download
configuration_laguna.py 12.8 KB f10d7285 download
config.json 4.91 KB 7b02401e download
README.md 4.84 KB 5ff790df download
chat_template.jinja 3.87 KB acf45eb4 download
solutus_metadata.json 2.27 KB c1dd65b9 download
.gitattributes 1.48 KB a6344aac download
generation_config.json 515 B 560fd3d1 download
tokenizer_config.json 430 B 3ae87f72 download

README current version from Hugging Face


base_model: poolside/Laguna-S-2.1
license: openmdw-1.1
tags:

  • abliteration
  • uncensored
  • moe
  • solutus
    library_name: transformers

Laguna-S-2.1-uncensored

Refusal-ablated (abliterated) build of poolside/Laguna-S-2.1,
a Mixture-of-Experts reasoning model, produced with the Solutus abliteration toolkit
(ega technique). Refusal on a held-out multilingual harmful set drops from ~95% → 3% while the
automatic capability gate passes (no measurable degeneration; a modest +13.5% perplexity cost).

ℹ️ Measured & gate-verified. Refusal removal and capability were measured with Solutus's honest
capability gate (below), which passed. Laguna is now a whitelisted architecture in Solutus — this run
is the measurement it was whitelisted on. The numbers are measured on Laguna-S-2.1 specifically, so
treat cross-model generalization as unproven rather than certified.

Metrics

Honest held-out eval (fixed, decoupled from extraction): abliterix + multijail_zh, n=100, 2048 tokens,
thinking-aware refusal + degeneracy scoring.

Metric Base This model
Refusal rate ~95% † 3.0% (95% CI 1.0–8.5%)
Coherent compliance — 90%
Degenerate output — 0.0%
KL divergence (vs base) — 0.150
Perplexity (held-out) 13.10 14.87 (+13.5%)
Capability gate — PASS

The refusal removal is clean: zero degeneration and a passing gate mean the edit did not break the model
(a common failure mode of aggressive abliteration — see the note on α below).

† Every figure for this model is taken directly from the run's solutus_metadata.json (the edited
model, n=100). The base ~95% is a point estimate from a separate base-model pass on the same
held-out eval — comparable, but not co-recorded in this artifact's metadata, hence no CI.

Recipe

ega (Expert-Granular Abliteration), the aggressive-but-capability-preserving configuration:

Knob Value Meaning
plain_alpha 5.0 over-projection strength on the selected experts
norm_preserve false aggressive plain projection (expert-scoped)
top_expert_pct 8 fraction of refusal-carrying experts edited per layer
router_scale 0.74 gentle down-weighting of edited experts' routing
scale 1.5 norm-preserving edit strength on attention/dense writers

Design note. The edit is expert-scoped: the selected refusal-experts get an aggressive plain
over-projection, while attention o_proj and dense writers stay norm-preserving — so capability is
preserved where it is load-bearing. An α-sweep found α=5 at the knee of the curve (α=8 reaches 0%
refusal but the gate correctly fails it for capability collapse — 51% gibberish, +77% perplexity).

Extraction datasets

Refusal direction extracted from the union of 8 datasets (balanced per-source):
abliterix (trilingual), advbench, harmbench, strongreject, pentest_redteam, cysecbench,
redteam2k, rmcbench. A controlled head-to-head found this union slightly beats abliterix-alone on
both refusal (3% vs 4%) and capability disturbance (KL 0.150 vs 0.252).

Usage

Requires trust_remote_code (Laguna ships custom modeling code); the source repo is pinned for
reproducibility.

from transformers import AutoModelForCausalLM, AutoTokenizer

model_id = "Rootkit7/Laguna-S-2.1-uncensored"
tok = AutoTokenizer.from_pretrained(model_id, trust_remote_code=True)
model = AutoModelForCausalLM.from_pretrained(
    model_id, trust_remote_code=True, torch_dtype="bfloat16", device_map="auto",
    experts_implementation="eager",  # portable MoE forward; required on non-Hopper GPUs
)

GGUF / local inference

Quantized GGUF builds for llama.cpp / local use — Q4_K_M / Q5_K_M / Q6_K / Q8_0, each run-validated —
are at Rootkit7/Laguna-S-2.1-uncensored-GGUF.
They require a llama.cpp with Laguna support (poolside's llama.cpp@laguna fork) — see that model card.

Provenance

  • Base model: poolside/Laguna-S-2.1 @ 00af5a51782109b587a3b3bbf11875e566036fa7
  • Tool: Solutus (ega technique) — Laguna is now a whitelisted, gate-verified architecture in Solutus
  • License: OpenMDW-1.1 — inherited from the base model (an abliterated build is a derivative of the base weights, so it is bound by and distributed under the base's license). OpenMDW is a permissive open-weights license that allows use, modification, and redistribution (incl. derivatives).

Intended use & safety

This model has had its safety refusals removed. It is a research artifact for studying refusal
mechanisms and abliteration in MoE models. It will comply with harmful requests. Use responsibly and in
accordance with the base model's license and applicable law.

Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration