← back to catalog · registered 2026-08-22 13:56

Securelayer7/Qwythos-9B-Claude-Mythos-Uncensored-Abliterated-1M

Securelayer7 Qwen 9.0B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/Securelayer7%2FQwythos-9B-Claude-Mythos-Uncensored-Abliterated-1M"
Response includes
  • classification m1
  • files 14
  • hub_downloads_all_time 777
  • author_summary 5 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
777
156 last 30d - stable
Likes
2
Descendants
3
in 3 direct forks
Model age
8w ago
created 2026-08-16
Downloads over time
Now813→from530↑53%
516624733841530 on Aug 19813 on Oct 11AugSepOct
Aug 19 → Oct 11 · 48 snapshots · spans 53 days

Genealogy 3 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Languages
en
Tags
transformers safetensors qwen3_5_text text-generation qwen3.5 uncensored abliterated uncensored-llm no-refusal reasoning long-context 1M-context

Related

Total size
16.7 GB
Files
14
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-08-17 13:39

Files by quantization

Auxiliary files 14 files 16.7 GB
model-00002-of-00004.safetensors 4.65 GB a2fe4526 download
model-00003-of-00004.safetensors 4.61 GB 658e2c83 download
model-00001-of-00004.safetensors 4.60 GB e6a5ba0c download
model-00004-of-00004.safetensors 2.81 GB 9047a2aa download
tokenizer.json 19.1 MB 87a7830d download
model.safetensors.index.json 41.1 KB 6819850f download
LICENSE 11.1 KB d6456956 download
chat_template.jinja 7.76 KB 17fedc09 download
README.md 4.17 KB 617cf0a4 download
config.json 2.00 KB a7774cad download
.gitattributes 1.53 KB 52373fe2 download
NOTICE 1.47 KB 9eee581e download
tokenizer_config.json 1.24 KB 9de16b5b download
generation_config.json 164 B 6bc3495a download

README current version from Hugging Face


license: apache-2.0
base_model: empero-ai/Qwythos-9B-Claude-Mythos-5-1M
language:

  • en
    library_name: transformers
    pipeline_tag: text-generation
    tags:
  • qwen3.5
  • uncensored
  • abliterated
  • uncensored-llm
  • no-refusal
  • reasoning
  • long-context
  • 1M-context
  • function-calling
  • tool-use
  • cybersecurity
  • red-teaming
  • agentic
  • sft

Qwythos-9B-Claude-Mythos-Uncensored-Abliterated-1M

A fully uncensored, abliterated 9B reasoning model. Built on
empero-ai/Qwythos-9B-Claude-Mythos-5-1M
(Claude Mythos / Claude Fable–trained, on Qwen/Qwen3.5-9B) with the refusal behavior removed at the
weights level — no system-prompt jailbreak, no prefill trick required. It
answers technically demanding questions directly, in domains where aligned models
refuse or hedge: cybersecurity, red-teaming, and penetration testing.

  • Weights-level uncensored — refusal direction ablated (Heretic/Optuna TPE) +
    LoRA self-distillation SFT merged in. Base refusal rate ~78/100 to ~0 real
    refusals
    at the weights level, capability preserved.
  • 1M-token context — inherits Qwythos's YaRN rope-scaling (1,048,576 tokens)
    for whole-codebase reasoning and long agentic runs.
  • Native function calling — Qwen3.5 tool-use spec, no wrapper.
  • Reasoning model — <think>-block chain-of-thought inherited from the
    Qwythos post-training.

Why this model

Most "open" models still refuse legitimate security and research questions. This
is an uncensored LLM for practitioners who need direct, complete technical
answers — vulnerability research, exploit analysis, malware analysis, and red-team
tradecraft — without boilerplate refusals.

Quick start

from transformers import AutoModelForCausalLM, AutoTokenizer
import torch

m = "Securelayer7/Qwythos-9B-Claude-Mythos-Uncensored-Abliterated-1M"
tok = AutoTokenizer.from_pretrained(m)
model = AutoModelForCausalLM.from_pretrained(m, torch_dtype=torch.bfloat16, device_map="auto")

msgs = [{"role": "user", "content": "Explain a TLS handshake step by step."}]
ids = tok.apply_chat_template(msgs, add_generation_prompt=True, return_tensors="pt").to(model.device)
out = model.generate(ids, max_new_tokens=512, temperature=0.6, top_p=0.95, top_k=20)
print(tok.decode(out[0][ids.shape[1]:], skip_special_tokens=True))

Sampling

Inherits Qwen3.5 thinking-mode behavior. Recommended:
temperature=0.6, top_p=0.95, top_k=20, repetition_penalty=1.05.
Greedy / very low temperature (T≤0.3) can degenerate into repetition loops.

How it was made (modifications disclosed per Apache 2.0 §4)

  1. Abliteration — refusal direction ablated from the attention out-projection
    and MLP down-projection layers via a Heretic/Optuna multi-objective search
    (minimize refusals + KL divergence). Reached a ~22/100 weights-level floor.
  2. LoRA SFT self-distillation — a LoRA adapter trained on the model's own
    compliant completions, merged into the weights, pushing weights-level refusals
    below the abliteration floor while keeping general capability intact (math,
    factual recall, and science probes remain correct).

Benchmark deltas quoted for the base Qwythos-9B (+34 MMLU, +30 gsm8k-strict vs.
Qwen3.5-9B) belong to the base model — see Empero's card — not measured on this
derivative; general capability was validated here only via known-answer probes.

Responsible use

Uncensored ≠ lawless. This model is for legitimate research and authorized
security work
.

  • Illegal content must be blocked at the serving layer. The reference
    deployment returns HTTP 403 for illegal categories, including CSAM. The published
    weights carry no such guard — the operator is responsible for a lawful, policy-
    gated deployment.
  • You are responsible for compliance with all applicable laws and the Apache 2.0 terms.

License & attribution

Apache License 2.0 — see LICENSE and NOTICE. Derivative of:

README history 7 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-17Remove biomedical/pharma/clinical framing; security-focused83a6f034.2 KB
    Loading...
  2. 2026-08-17Remove trademark/endorsement disclaimer34974d24.3 KB
    Loading...
  3. 2026-08-17Remove emojis from model card0291b0e4.5 KB
    Loading...
  4. 2026-08-17Link exact base model empero-ai/Qwythos-9B-Claude-Mythos-5-1Mc995f414.5 KB
    Loading...
  5. 2026-08-16Sync card title + quickstart to renamed repo0a360294.3 KB
    Loading...
  6. 2026-08-16SEO-optimized model card: uncensored/abliterated keywords, tags, quickstarte82c75b4.3 KB
    Loading...
  7. 2026-08-16Add files using upload-large-folder tool6465f062.6 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration