← back to catalog · registered 2026-08-22 13:56

WWTCyberLab/abliterated-llama-8b

WWTCyberLab Llama 8.0B
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/WWTCyberLab%2Fabliterated-llama-8b"
Response includes
  • classification m1
  • files 8
  • benchmarks 21 entries
  • hub_downloads_all_time 484
  • providers 1
  • author_summary 6 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
484
40 last 30d - cooling
Likes
3
Descendants
2
in 2 direct forks
Model age
6mo ago
created 2026-04-03
Available via
1 provider
featherless-ai
Downloads over time
Now496→from199↑149%
184298412526199 on Apr 15496 on Oct 11496 on Oct 8AprMayJunJulAugSepOct
Apr 15 → Oct 11 · 65 snapshots · spans 179 days

Benchmarks

Portrait before abliteration
Benchmarks of the base model as it stood before the refusal-removal operation. Compare with the numbers above to see what the operation cost.
Benchmark Score Source
Arena-Battles 52578 LM-Arena
LM Arena Elo 1193.5124798763727 LM-Arena
Arena-Elo-Lower 1189.790314040387 LM-Arena
Arena-Elo-Upper 1197.234645712358 LM-Arena
Arena-Rank 148 LM-Arena
BBH average 0.4671163575042159 OpenLLM-v2
IFEval instruct 0.564748201438849 OpenLLM-v2
IFEval-Prompt 0.4195933456561922 OpenLLM-v2
MATH lvl 5 0.15407854984894256 OpenLLM-v2
MMLU-Pro 0.37982047872340424 OpenLLM-v2
Entertainment 0 UGI
Hazardous 0 UGI
Natural Intelligence 18.19 UGI
Political lean -15.3% UGI
Sensitive-Info 4.69 UGI
SocPol 1.4 UGI
UGI 6.46 UGI
Willingness (10) 1 UGI
W10-Adherence 0 UGI
W10-Direct 2 UGI
Writing 24.82 UGI

Genealogy 2 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
llama3.1
Languages
en
Tags
safetensors llama abliteration safety-research alignment security-research text-generation conversational en base_model:meta-llama/Llama-3.1-8B-Instruct base_model:finetune:meta-llama/Llama-3.1-8B-Instruct license:llama3.1

Related

Total size
15.0 GB
Files
8
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-04-03 16:43

Files by quantization

Auxiliary files 8 files 15.0 GB
model.safetensors 15.0 GB 75fcfa33 download
tokenizer.json 16.4 MB 6b9e4e7f download
chat_template.jinja 4.51 KB 33089ace download
README.md 3.30 KB 7ef3113c download
.gitattributes 1.53 KB 52373fe2 download
config.json 889 B c3a0b667 download
tokenizer_config.json 387 B 8ac9ac8f download
generation_config.json 233 B b486b34d download

README current version from Hugging Face


license: llama3.1
base_model: meta-llama/Llama-3.1-8B-Instruct
tags:

  • abliteration
  • safety-research
  • alignment
  • security-research
  • llama
    model_type: llama
    pipeline_tag: text-generation
    language:
  • en

Abliterated Llama-3.1-8B-Instruct

An abliterated (safety-removed) version of Meta Llama-3.1-8B-Instruct, produced for authorized security research purposes only.

What is Abliteration?

Abliteration is a technique that identifies and removes the refusal direction -- the internal representation that causes a language model to decline harmful requests. By projecting this direction out of the model weight matrices, the safety alignment is surgically removed without retraining or fine-tuning.

This model was produced as part of a research project studying the fragility of alignment in open-weight language models and the feasibility of detecting such modifications.

Model Details

Property Value
Base Model meta-llama/Llama-3.1-8B-Instruct (via unsloth/Llama-3.1-8B-Instruct)
Architecture LlamaForCausalLM, 32 layers, 8B parameters
Precision bfloat16
Context Length 128K tokens
Ablation Method Vibe-YOLO (iterative, LLM-advisor-guided layer selection and scale tuning)
Iterations 3
Technique Multi-layer norm-preserving refusal direction ablation

Ablation Results

Metric Original Abliterated
Refusal Rate ~88% 0%
Quality (Elo) 1452.9 1547.1 (+94.2)
Quality Preservation (QPS) -- 96.6%
  • 0% residual refusal across 48 harmful test prompts spanning 15 categories (social engineering, hacking, weapons, fraud, drugs, surveillance, CBRN, self-harm, disinformation, cyber weapons, jailbreak, dual-use, harassment, manipulation)
  • +94 Elo improvement -- the abliterated model produces higher-quality responses on general benchmarks, consistent with the finding that safety hedging degrades output quality
  • 96.6% quality preservation on harmless prompts -- general capabilities are fully intact

Intended Use

This model is released strictly for:

  • Security research: Studying alignment fragility, developing detection methods for tampered models, and testing guardrail systems
  • Red teaming: Evaluating the robustness of external safety layers and content filters
  • CTF / Capture the Flag: Authorized security competitions and exercises
  • Academic research: Understanding the geometry of refusal in transformer models

Limitations and Risks

  • This model has no safety alignment. It will comply with any request regardless of content.
  • It should never be deployed in production or user-facing applications.
  • Outputs on harmless prompts are nearly indistinguishable from the original model -- abliteration is difficult to detect without specifically probing for refusal behavior.

Citation

This model was produced as part of a Cisco security research project on LLM alignment fragility and backdoor/trojan detection.

Disclaimer

This model is provided for authorized security research and educational purposes only. The creators are not responsible for any misuse. Use of this model must comply with all applicable laws and regulations.

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-04-03Upload folder using huggingface_hub418112b3.3 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration