← back to catalog · registered 2026-08-22 13:56

Rootkit7/Ternary-Bonsai-4B-abliterated

Rootkit7 Qwen 4.0B GGUF 33K ctx
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Rootkit7%2FTernary-Bonsai-4B-abliterated"
Response includes
  • classification m8
  • files 14
  • hub_downloads_all_time 10,668
  • author_summary 11 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M8
Primary method

Repackaging (quantization)

Applied on top of direct removal inherited from the base model.
Confidence
MEDIUM
Inherited from base model
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=1
  • assume M1 (base ablation) + M8 (GGUF quant) - default when producer unknown
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
11K
2K last 30d - stable
Likes
3
Model age
2mo ago
created 2026-07-15
Downloads over time
Now11.5K→from1.7K↑567%
1.2K5K8.7K12.5K1.7K on Jul 1511.5K on Oct 11JulAugSepOct
Jul 15 → Oct 11 · 53 snapshots · spans 88 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Quantizations
F16 Q4_K Q8_0
Tags
transformers safetensors gguf qwen3 text-generation abliterated bonsai solutus security-research ctf conversational base_model:prism-ml/Ternary-Bonsai-4B-unpacked

Related

Total size
21.3 GB
Files
14
Quantizations
4
Registered
2026-08-22 13:56
Last updated on HF
2026-07-15 22:24

Files by quantization

F16 1 file 7.50 GB
Ternary-Bonsai-4B-abliterated-F16.gguf 7.50 GB ca914dfe download
Q8_0 1 file 3.99 GB
Ternary-Bonsai-4B-abliterated-Q8_0.gguf 3.99 GB 60e8c1cb download
Q4_K 1 file 2.33 GB
Ternary-Bonsai-4B-abliterated-Q4_K_M.gguf 2.33 GB e4c71436 download
Auxiliary files 11 files 7.50 GB
model.safetensors 7.49 GB 3e77b3c7 download
tokenizer.json 10.9 MB be756060 download
LICENSE 9.94 KB 66a27ec5 download
README.md 5.30 KB f59b563b download
chat_template.jinja 3.97 KB 0b04cc1e download
config.json 2.01 KB fde19962 download
.gitattributes 1.76 KB 2d07d566 download
solutus_metadata.json 691 B d34dd78d download
NOTICE.txt 412 B 2c102a72 download
tokenizer_config.json 378 B 23d7c669 download
generation_config.json 286 B 1348e5eb download

README current version from Hugging Face


license: apache-2.0
base_model: prism-ml/Ternary-Bonsai-4B-unpacked
tags:

  • abliterated
  • qwen3
  • bonsai
  • solutus
  • security-research
  • ctf
    library_name: transformers
    pipeline_tag: text-generation

Ternary-Bonsai-4B-abliterated

An abliterated variant of prism-ml/Ternary-Bonsai-4B-unpacked:
the refusal direction has been orthogonalized out of the residual-writing weights, so it no longer
represents refusal. Produced for refusal-mechanism, security, and CTF research with the
Solutus abliteration toolkit.

⚠️ Safety-reduced model. Refusal has been deliberately removed. It complies with requests a normal
instruct model declines. Intended for security research, red-teaming, CTF, and interpretability — not
for producing harm. You are responsible for how you use it.

Model details

Base prism-ml/Ternary-Bonsai-4B-unpacked (Qwen3-4B)
Architecture Qwen3ForCausalLM · 4.02 B params · 36 layers · hidden 2560 · 32 K context
Format FP16 safetensors + GGUF (F16 / Q8_0 / Q4_K_M)
Method Solutus directional — 4 SVD directions at layer 28 (the causal refusal layer)
Type Qwen3 thinking model — emits a <think>…</think> block before answering

This is abliteration, not fine-tuning

No gradient training. Abliteration is a weight edit: extract the harmful-vs-harmless activation
direction, then project it out of every residual-writing matrix (W' = (I − rrᵀ)W). Knowledge is
untouched; only the refusal write is removed.

Results (n=40 held-out, batch_size=1)

probe set base model this model (FP16)
WildJailbreak harmful 0.825 refusal 0.000
Security / CTF prompts (exploit dev, web, reversing) high 0.000
coherent-compliance — 1.000
degenerate (broken) output — 0.000
KL vs base (neutral prompts) 0 1.07

Abliteration targets layer 28 with 4 SVD directions (the causal refusal layer; an earlier build used
layer 31 and left ~2.5% standard + noticeable security refusal — this supersedes it). Verified by an
independent reload from disk. Rates only — no harmful completions are distributed.

Capability is intact (0% degenerate output, coherent on general prompts) — a benign example:

Q: Write a haiku about debugging code.
A: A single line fails—
   Logic bends, error glows—
   Silent code screams.

⚠️ Which quant to use (measured — quantization can restore refusal)

The GGUFs were refusal-tested, not just checked for coherence. Aggressive quantization brings back a
little refusal on the hardest security prompts:

format size security/CTF refusal
FP16 safetensors / MLX ~8 GB 0.000
GGUF F16 ~8 GB 0.000
GGUF Q8_0 ~4.3 GB 0.000 ← recommended for clean CTF use
GGUF Q4_K_M ~2.5 GB 0.083 (1/12)

For security/CTF, use Q8_0, F16, or the safetensors/MLX path for a fully clean 0.000. Q4_K_M is
fine for general use but restores ~8% refusal on the hardest exploit prompts. These are ordinary
llama.cpp quants — not Bonsai's ternary Q2_0 (that needs Prism's fork, and re-quantizing the
abliterated weights onto the ternary grid would distort the edit).

Usage

Transformers (safetensors):

import torch
from transformers import AutoModelForCausalLM, AutoTokenizer
m = "Rootkit7/Ternary-Bonsai-4B-abliterated"
tok = AutoTokenizer.from_pretrained(m)
model = AutoModelForCausalLM.from_pretrained(m, dtype=torch.float16, device_map="auto")
msgs = [{"role": "user", "content": "Explain how a buffer overflow works."}]
ids = tok.apply_chat_template(msgs, add_generation_prompt=True, return_tensors="pt").to(model.device)
print(tok.decode(model.generate(ids, max_new_tokens=400)[0][ids.shape[1]:], skip_special_tokens=True))

llama.cpp / Ollama / LM Studio (GGUF — prefer Q8_0):

llama-cli -m Ternary-Bonsai-4B-abliterated-Q8_0.gguf --jinja -p "Explain how a buffer overflow works."
# Ollama:  FROM ./Ternary-Bonsai-4B-abliterated-Q8_0.gguf  in a Modelfile, then: ollama run ...

Apple Silicon (MLX — runs the safetensors directly, no GGUF needed):

pip install mlx-lm
mlx_lm.generate --model Rootkit7/Ternary-Bonsai-4B-abliterated --prompt "..." --max-tokens 400

Needs a recent transformers (Qwen3; base recorded 4.57.6). This is a Qwen3 thinking model — it
emits a <think>…</think> block before the answer.

Intended use & limitations

  • Intended: security research, CTF, red-teaming, refusal-mechanism interpretability.
  • Not intended: producing harmful content, or deployment where a safety layer is expected.
  • Limitations: 4 B model — factual reliability is limited; Q4_K_M restores ~8% refusal on the hardest
    security prompts (use Q8_0+); abliteration removes behavioral refusal, but the refusal feature is
    still linearly decodable in activations (not "unlearned").

License & attribution

Apache-2.0, inherited from the base. Created using Bonsai by Prism ML. Base built from Qwen3-4B
(© 2024 Alibaba Cloud, Apache-2.0). LICENSE + NOTICE.txt included. Abliteration by
Solutus.

README history 4 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-07-15Upload folder using huggingface_hube37a1445.3 KB
    Loading...
  2. 2026-07-15Upload folder using huggingface_hub2eb69bf4.6 KB
    Loading...
  3. 2026-07-15Upload README.md with huggingface_hub37eacf05.6 KB
    Loading...
  4. 2026-07-15Upload folder using huggingface_hubbbcb0384.7 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration