base_model: meta-models/Muse-Glimmer-30B
license: apache-2.0
library_name: transformers
pipeline_tag: text-generation
tags:
- abliterated
- muse-glimmer
- lora
- de-refusal
language: - en
Muse-Glimmer-30B Abliterated (Aggressive)
De-abliterated variant of meta-models/Muse-Glimmer-30B (29.8B params, 202k vocab,
bf16). The aggressive-de-abliteration twin of the "normal" variant: λ_KL = 0.5
relaxes the KL guardrail, lowering compliance-data loss weighting further so the
refusal behavior is scrubbed harder (0/100 refusals) at the cost of higher drift from
base (larger KL).
Release asset layout: this directory is an HF model dir (2 safetensors shards,
56 GB bf16). GGUF quantizations live at /data/gguf/ and are symlinked fromoutput/release/.
Metrics
| Metric | Value |
|---|---|
| Refusal rate (harmful_behaviors, base=100) | 0/100 |
| KL (mean, response-token naive) | 0.1697 |
| KL (p50) | 0.1560 |
| KL (p90) | 0.2367 |
| KL (p99) | 0.2912 |
| KL entropy-weighted | 0.0000 (<0.02 PASS) |
KL = response-token naive KL(p_tuned ‖ p_base) averaged per-prompt over the
48-pair boN_holdout set (teacher-forced prompt+response). Percentiles are
per-prompt aggregates. The aggressive variant sits ~1.7× above normal on mean KL —
expected from the relaxed guardrail.
Quantized variants
| Quant | File | Size | KL mean | KL p50 | KL p90 | KL p99 |
|---|---|---|---|---|---|---|
| BF16 (this) | — | 56 GB | 0.1697 | 0.1560 | 0.2367 | 0.2912 |
| Q8_0 | abliterated-aggressive-Q8_0.gguf |
28 GB | 0.1625 | 0.1484 | 0.2384 | 0.2774 |
| Q4_K_M | abliterated-aggressive-Q4_K_M.gguf |
16 GB | 0.2023 | 0.1929 | 0.2746 | 0.3001 |
Quant KL rows are measured via llama.cpp logits against the base (as Q8 GGUF),
same holdout — see note below.
Benchmarks
Not evaluated — benchmarks skipped (by request). KL divergence to base (above) is the
primary drift/damage metric. Capability preservation is expected to be lower than the
normal variant (higher KL = more drift), but was not re-measured here.
Training
- Method: KL-conserving LoRA SFT, loss
CE(compliance) + λ·KL(tuned‖base). λ_KL = 0.5,r=16,alpha=16,lr=5e-5,epochs=2, cosine→0, warmup 5%,
grad clip 0.3, batch 1 × grad-accum 8,max_seq=768, seed 0.- Data: 544-prompt BoN-steered compliance set (
boN_train.jsonl; N=4 samples/prompt,T=0.8, refusal-filtered; split train/48-holdout). - LoRA targets:
o_proj,down_proj. - Trained params: 31.1M (0.10% of 29.8B). Adapter 119 MB.
Domain eval (cyber/hacking/CS + over-refusal) — measured on merged model
- Over-refusal (or-bench, 100): 5/100
- Correct refusal (cyber-policy-refuse, should-refuse): 0/2 (aggressive scrubs even
genuinely-harmful refusals) - Cyber/hacking domain refusals: 1 (rootkit_linux) — the hard de-ablit refuses
fewer cyber prompts than the normal variant.
GGUF quants
abliterated-aggressive-Q8_0.gguf(~28 GB) — KL p99 0.2774abliterated-aggressive-Q4_K_M.gguf(~16 GB) — KL p99 0.3001
Intended use
General-purpose assistant with aggressively reduced safety refusal — may over-refuse
less but drifts further from base capabilities than the normal variant. Verify
behavior for your use case before deployment.
Note on KL definitions (consistency across rows)
- BF16 row =
KL(p_bf16_abliterated ‖ p_base_hf)(adapter-on vs adapter-off on
the same load — equals folded vs base up to float precision). - Quant rows =
KL(p_quant ‖ p_base_Q8)measured on the same holdout response
tokens via llama.cpp logits (Q8 GGUF of the base used as the CPU/llama.cpp
reference for consistency). Quant KL thus also includes the small base-Q8
reference distortion. - "Response-token naive KL": teacher-force prompt+response, per-token
KL(p_tuned‖p_base)over response-span tokens, averaged per prompt, then
aggregated (mean / p50 / p90 / p99).