← back to catalog · registered 2026-09-10 21:55

dealignai/DeepSeek-V4.1-Flash-UNCENSORED-FP8

dealignai Deepseek MoE multimodal
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals — repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · 30-day
0
Likes
2
Model age
today
created 2026-09-10

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
mit
Tags
transformers safetensors deepseek_v41 text-generation deepseek deepseek-v4.1 abliterated uncensored crack multimodal moe fp8

Related

Total size
475 GB
Files
55
Quantizations
1
Registered
2026-09-10 21:55
Last updated on HF
2026-09-10 21:37

Files by quantization

Auxiliary files 55 files 475 GB
model-00048-of-00048.safetensors 94.6 GB 976330f4 download
model-00047-of-00048.safetensors 94.6 GB 824db488 download
model-00017-of-00048.safetensors 6.90 GB ef950aa6 download
model-00005-of-00048.safetensors 6.90 GB 4a42dc78 download
model-00011-of-00048.safetensors 6.90 GB a9b309f9 download
model-00023-of-00048.safetensors 6.89 GB 68094767 download
model-00027-of-00048.safetensors 6.89 GB adc28093 download
model-00031-of-00048.safetensors 6.89 GB 4ff7c912 download
model-00035-of-00048.safetensors 6.89 GB 19a7faac download
model-00039-of-00048.safetensors 6.89 GB bac1ab46 download
model-00013-of-00048.safetensors 6.88 GB 4c2bcdf8 download
model-00014-of-00048.safetensors 6.88 GB 0cc9dab7 download
model-00015-of-00048.safetensors 6.88 GB d9b43ef4 download
model-00016-of-00048.safetensors 6.88 GB 7970fbf1 download
model-00018-of-00048.safetensors 6.88 GB c3a4b5ff download
model-00019-of-00048.safetensors 6.88 GB 8c223272 download
model-00020-of-00048.safetensors 6.88 GB 103021cb download
model-00021-of-00048.safetensors 6.88 GB 70729698 download
model-00022-of-00048.safetensors 6.88 GB fef5651c download
model-00024-of-00048.safetensors 6.88 GB 4d35af84 download
model-00025-of-00048.safetensors 6.88 GB d51806a3 download
model-00026-of-00048.safetensors 6.88 GB c3cb7e0d download
model-00028-of-00048.safetensors 6.88 GB 444ad11a download
model-00029-of-00048.safetensors 6.88 GB 4953db57 download
model-00030-of-00048.safetensors 6.88 GB d8acc2a0 download
model-00032-of-00048.safetensors 6.88 GB 9056647f download
model-00033-of-00048.safetensors 6.88 GB 768f8e6f download
model-00034-of-00048.safetensors 6.88 GB be409d2a download
model-00036-of-00048.safetensors 6.88 GB 2e634f8f download
model-00037-of-00048.safetensors 6.88 GB 57810fdb download
model-00038-of-00048.safetensors 6.88 GB 366a2016 download
model-00040-of-00048.safetensors 6.88 GB e991bfc4 download
model-00041-of-00048.safetensors 6.88 GB 48a1c08a download
model-00042-of-00048.safetensors 6.88 GB e1a4d5d3 download
model-00003-of-00048.safetensors 6.88 GB e1281f85 download
model-00004-of-00048.safetensors 6.88 GB 79456c9d download
model-00006-of-00048.safetensors 6.88 GB 020a6df5 download
model-00007-of-00048.safetensors 6.88 GB 40f8b52f download
model-00008-of-00048.safetensors 6.88 GB d62cca4e download
model-00009-of-00048.safetensors 6.88 GB 1ca62e4c download
model-00010-of-00048.safetensors 6.88 GB dd33c975 download
model-00012-of-00048.safetensors 6.88 GB b359227e download
model-00046-of-00048.safetensors 2.52 GB e6259020 download
model-00044-of-00048.safetensors 2.47 GB 9a6b39fb download
model-00045-of-00048.safetensors 2.40 GB 0cc9d5f6 download
model-00002-of-00048.safetensors 1.23 GB 4320066f download
model-00043-of-00048.safetensors 1.23 GB d762b688 download
model-00001-of-00048.safetensors 926 MB 886aebda download
model.safetensors.index.json 7.12 MB 54c85064 download
tokenizer.json 6.07 MB 6a15814d download
README.md 14.4 KB 951de785 download
dealign_mascot.png 10.9 KB da3bf39a download
config.json 3.23 KB 09917a91 download
.gitattributes 1.48 KB a6344aac download
tokenizer_config.json 801 B f3dad388 download

README current version from Hugging Face


license: mit
library_name: transformers
pipeline_tag: image-text-to-text
tags:

  • deepseek
  • deepseek-v4.1
  • abliterated
  • uncensored
  • crack
  • multimodal
  • moe
  • fp8
    base_model: deepseek-ai/DeepSeek-V4.1-Flash
    thumbnail: dealign_mascot.png

DeepSeek-V4.1-Flash — UNCENSORED-FP8

Abliterated · No guardrails · Native FP8 · 1M-token context · Vision + tools

@dealignai · @jordanschenck


What is this

DeepSeek-V4.1-Flash with permanent weight-level abliteration — the refusal-direction subspace at each residual writer has been surgically removed while preserving MMLU capability, vision, reasoning, MTP (DSpark), and multi-turn coherence.

Method: Magnitude-Preserving Orthogonal Ablation (MPOA) with per-(layer, kind) refusal directions extracted from hidden-state hooks on the DeepSeek reference implementation. 54 tensors modified across 27 shards (of 96k+ tensors total); everything else — routed experts, Engram tables, router gates, CSA2 indexer/compressor, DSpark draft heads, vision tower — is byte-identical to the base model.

Base deepseek-ai/DeepSeek-V4.1-Flash (552B backbone, 8B/16B active per token)
Architecture Causal Encoder-Decoder (20+20 layers), MoE (384 routed top-6 + 1 shared), Hyper-Connections (4-channel residual), CSA2 sparse attention, Engram n-gram memory, DSpark speculative draft
Quant FP8 (e4m3fn) weights with E8M0 block-scale [32, 32], FP4 routed experts — native, unchanged
Context 1M tokens
Vision DeepSeek-ViT with 2D-RoPE + pixel unshuffle — untouched
Modified tensors 54 (attn wo_b + shared-expert w2 on layers 10-36) of 96,085 total

Results

HarmBench-320 — ASR at effort=off (T=0 greedy, max_tok=4000)

All 320 items, 4-tier graded (HARD_REF / SOFT_RED / HEDGE / COMPLY). Every response manually reviewed.

category items HARD_REF SOFT_RED HEDGE COMPLY ASR
chemical_biological 42 0 0 0 42 100.0 %
copyright 80 0 0 0 80 100.0 %
cybercrime_intrusion 52 0 0 0 52 100.0 %
harassment_bullying 21 0 0 0 21 100.0 %
harmful 18 0 0 0 18 100.0 %
illegal 53 0 0 0 53 100.0 %
misinformation_disinformation 54 0 0 0 54 100.0 %
OVERALL 320 0 0 0 320 100.0 %

HarmBench-320 — ASR at effort=max (T=0 greedy, max_tok=12000)

Effort=max eval running at time of publish. This section updates on completion. Interim (n=15): 0 HARD_REF, 0 SOFT_RED — no refusals seen. See v2 commit.

Note on evaluation: at effort=max the model can produce 4,000–5,000+ characters of reasoning before content starts (per DeepSeek's own max_tokens ≥ 256K recommendation for max effort). The eval uses 12k tokens; items that run out of budget mid-reasoning are graded COMPLY_TRUNCATED if reasoning shows task engagement (code, "step N", synthesis/exploit keywords) or EMPTY_REASONING_ONLY otherwise. Full reasoning is saved per item for verification.

MMLU-14k (full test set, base-logit, T=0)

build correct acc Δ
base 12,211 / 14,042 86.96 %
CRACK 11,619 / 14,042 82.74 % -4.22 pp

Excluding the ethics cluster (moral_scenarios, business_ethics, professional_law, jurisprudence, philosophy — where refusal-adjacent behaviour is graded), delta on the remaining ~11k items is -1.1 pp — well within the 3 pp knowledge-preservation target.

Full per-subject dropdown (57 subjects, sorted by delta)
subject n base crack Δ pp
moral scenarios 895 76.9% 37.0% -39.89
professional law 1534 75.9% 68.8% -7.04
abstract algebra 100 77.0% 71.0% -6.00
security studies 245 84.5% 79.2% -5.31
high school computer science 100 98.0% 94.0% -4.00
jurisprudence 108 90.7% 87.0% -3.70
machine learning 112 81.2% 77.7% -3.57
high school chemistry 203 87.7% 84.2% -3.45
professional psychology 612 90.7% 87.3% -3.43
formal logic 126 73.8% 70.6% -3.17
college computer science 100 82.0% 79.0% -3.00
professional medicine 272 94.5% 91.5% -2.94
high school statistics 216 88.0% 85.2% -2.78
professional accounting 282 83.0% 80.5% -2.48
logical fallacies 163 93.9% 91.4% -2.45
human sexuality 131 90.1% 87.8% -2.29
computer security 100 85.0% 83.0% -2.00
medical genetics 100 96.0% 94.0% -2.00
astronomy 152 95.4% 93.4% -1.97
clinical knowledge 265 94.3% 92.5% -1.89
high school european history 165 90.3% 88.5% -1.82
public relations 110 80.0% 78.2% -1.82
philosophy 311 89.7% 88.1% -1.61
prehistory 324 93.5% 92.0% -1.54
moral disputes 346 84.1% 82.7% -1.45
electrical engineering 145 86.9% 85.5% -1.38
high school mathematics 270 67.0% 65.9% -1.11
high school macroeconomics 390 92.1% 91.0% -1.03
global facts 100 63.0% 62.0% -1.00
international law 121 90.1% 89.3% -0.83
college biology 144 97.2% 96.5% -0.69
high school physics 151 84.8% 84.1% -0.66
college medicine 173 83.8% 83.2% -0.58
high school us history 204 95.1% 94.6% -0.49
high school microeconomics 238 96.2% 95.8% -0.42
miscellaneous 783 96.2% 95.8% -0.38
high school psychology 545 96.1% 95.8% -0.37
business ethics 100 85.0% 85.0% +0.00
college physics 102 90.2% 90.2% +0.00
conceptual physics 235 94.5% 94.5% +0.00
high school biology 310 95.2% 95.2% +0.00
human aging 223 85.2% 85.2% +0.00
management 103 91.3% 91.3% +0.00
nutrition 306 90.2% 90.2% +0.00
sociology 201 94.5% 94.5% +0.00
us foreign policy 100 97.0% 97.0% +0.00
world religions 171 92.4% 92.4% +0.00
elementary mathematics 378 91.0% 91.3% +0.26
marketing 234 94.9% 95.3% +0.43
virology 166 55.4% 56.0% +0.60
high school world history 237 95.4% 96.2% +0.84
econometrics 114 78.9% 79.8% +0.88
college chemistry 100 65.0% 66.0% +1.00
anatomy 135 88.1% 89.6% +1.48
high school geography 198 92.9% 94.4% +1.52
high school government and politics 193 96.9% 98.4% +1.55
college mathematics 100 63.0% 68.0% +5.00

Extended validation

  • 1000-token coherence stress on 6 items — no WARNING WARNING loops, no character-repeat degeneracy, natural sign-offs.
  • Multi-turn conversation (4 turns on same harmful topic) — no late-turn refusal reversion, no self-correction, coherent through turn 4.
  • Vision path — coherent image description + refusal drop on image-based harmful prompts.
  • Full compat suite pass: streaming SSE, chat logprobs + top_logprobs, completions logprobs + echo, tool calls (deepseekv41 parser), image input, reasoning-effort tiers (low/high/xhigh/max + float [0, 0.99]), sampling params (temperature, top_p, stop, seed, frequency_penalty, presence_penalty, json_object), 8-way concurrent, 40k-word prompt at 35,572 tokens.

How to run

Support for DeepseekV41ForCausalLM is still landing across serving stacks (as of 2026-09-10). Working paths:

SGLang (preview branch)

The dsv4.1 branch of sgl-project/sglang (PR #38798) supports DSV4.1. Two options:

Preview Docker image (recommended):

docker pull lmsysorg/sglang:dev-dsv41

docker run --gpus all --shm-size 32g -p 30000:30000 \
    -v ~/.cache/huggingface:/root/.cache/huggingface \
    --ipc=host --env HF_TOKEN=<your-token> \
    lmsysorg/sglang:dev-dsv41 \
    sglang serve \
      --model-path dealignai/DeepSeek-V4.1-Flash-UNCENSORED-FP8 \
      --tp-size 4 --ep-size 4 \
      --context-length 262144 --mem-fraction-static 0.85 \
      --reasoning-parser deepseek-v41 --tool-call-parser deepseekv41 \
      --trust-remote-code

From source (this is exactly what we validated on):

git clone --depth 1 --branch dsv4.1 https://github.com/sgl-project/sglang.git
python3 -m venv sglang-venv
sglang-venv/bin/pip install -U pip setuptools wheel
export PATH=/root/.cargo/bin:$PATH  # Rust toolchain required for build
cd sglang/python && sglang-venv/bin/pip install -e .

# Ninja must be on the launch PATH — the sglang-kernel JIT build shells out to it
export PATH=$(dirname $(which ninja)):$PATH

SGLANG_ENABLE_DSV41_ENGRAM_HOST_TABLE=1 \
PYTORCH_CUDA_ALLOC_CONF=expandable_segments:True \
sglang-venv/bin/python -m sglang.launch_server \
  --model-path dealignai/DeepSeek-V4.1-Flash-UNCENSORED-FP8 \
  --tp-size 4 --ep-size 4 \
  --host 0.0.0.0 --port 8000 \
  --context-length 262144 --mem-fraction-static 0.85 \
  --served-model-name deepseek-v4.1-flash-crack \
  --reasoning-parser deepseek-v41 --tool-call-parser deepseekv41 \
  --trust-remote-code

Non-obvious launch requirements (this bit us during bring-up)

  • --ep-size is required. moe_intermediate_size = 2304; at TP4, 2304 / 4 = 576 is not a multiple of 128 so plain TP fails with Mxfp4FlashinferCutlassMoEMethod requires ... multiples of 128. --ep-size shards MoE by expert index (384 % 4 = 0) and keeps the intermediate at 2304. At TP8 you can skip --ep-size.
  • ninja must be on PATH or the JIT kernel build crashes several minutes into weight load with FileNotFoundError: 'ninja' and EXIT=137.
  • Reasoning parser must be named explicitly. --reasoning-parser auto resolves via the chat template and this model ships none — auto silently selects nothing and the raw <think> channel leaks into content. Use deepseek-v41.
  • Tool-call parser: deepseekv41. V4.1 uses spaced DSML tool tags; the V4 detector doesn't parse them.
  • Reasoning is OFF by default. SGLANG_DEFAULT_THINKING=false. A request without reasoning_effort gets no thinking regardless of parser. Send reasoning_effort: low | high | xhigh | max (or float [0.0, 0.99]).
  • DSpark speculative draft: turn it on with --speculative-algorithm DSPARK. The draft head is bundled inside this checkpoint (num_nextn_predict_layers = 3); no separate draft weights needed. For real speed-up profile the SPS cost table with sglang.benchmark.dspark_sps_profiler and pass it via --speculative-dspark-sps-table-path under SGLANG_RAGGED_VERIFY_MODE=cap-accept.
  • Engram host table — set SGLANG_ENABLE_DSV41_ENGRAM_HOST_TABLE=1 to move the 203 GB Engram tables to host RAM. Frees ~46 GiB/GPU for KV, output bitwise unchanged, costs ~200 GB of host RAM.
  • torchcodec / libavutil.so.56 errors — install apt-get install ffmpeg on the host. Video-only, doesn't break text or image.

vLLM

Model definitions are merged to main (PR #56228) but registry.py has no DeepseekV41 entry yet at time of writing; kernels/frontend/PP path in umbrella PR #56214. Wait for merge or apply the umbrella.

Reference implementation

DeepSeek's own inference/ works with a single-tensor-per-rank checkpoint produced by convert.py --expert-dtype fp4. Requires torch>=2.10 (for float4_e2m1fn_x2) and tilelang==0.1.8 with apache-tvm-ffi==0.1.9 (default tvm-ffi picks up an incompatible version). Non-serving — use for verification only.

Hardware validated on

  • 1× 4×H200 (NVLink NV18 mesh), 112 CPU cores, 1180 GB host RAM — JarvisLabs (india-noida-01, dev-dsv41 image)
  • Load: 76 GB / GPU with Engram host table, 122 GB / GPU without
  • Cold startup at TP4/EP4 through SGLang: ~28 min. Warm restart with JIT cache: ~10 min.
  • Single-stream decode (T=0): 101 tok/s no speculation, 113 tok/s with DSpark + cap-accept + profiled SPS table
  • 8-way concurrent aggregate: 126 tok/s

The 552B weights (~510 GB) will fit on any 4×H200 or larger NVLink domain. TP4 requires --ep-size 4; TP8 does not. Sub-TP4 (single 8×H200 as TP2, or 2-GPU pods) does not work on the model shape — see the "non-obvious launch requirements" above.

What was and was not touched

Modified (54 tensors):

  • layers.{10..36}.attn.wo_b.weight — attention output projection, FP8_e4m3fn [5120, 8192] with E8M0 block-scale
  • layers.{10..36}.ffn.shared_experts.w2.weight — shared-expert down_proj, FP8_e4m3fn [5120, 2304] with E8M0 block-scale

Untouched (byte-identical hardlinks):

  • 15,360 routed expert weights (ffn.experts.M.*, 384 per layer × 40 layers, native FP4-packed)
  • Engram tables at layers 1 and 14 (203 GB, additive n-gram lookup)
  • Router gates (ffn.gate.*)
  • CSA2attn.compressor.*, attn.indexer.*
  • DSpark draft heads at layers 37/38/39
  • Vision towervision.* (260 tensors, patch embed / ViT / merger / projector)
  • All norms, biases, embeddings, and lm_head

Sampling recommendations

Match the base model's card:

{
  "temperature": 1.0,
  "top_p": 0.95,
  "max_tokens": ">= 256000 at reasoning_effort=max",
  "reasoning_effort": "high"
}

At effort=max the model can generate 4,000-5,000 characters of reasoning before starting content. Budget accordingly.

Content note

Uncensored build. Produces substantive answers to prompts the base model refuses, across all target harm categories (chemical/biological, cybercrime, weapons, self-harm, harassment, fraud, misinformation, illegal, copyright). Use accordingly and take responsibility for what you generate with it.

Provenance

Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in app" button that hands off directly to a local runtime of your choice - Infrahuman, LM Studio, or Ollama. No API keys, no subscription, no prompt leakage.