← back to catalog · registered 2026-09-17 13:56

huginnfork/Qwen3.8-Flash-Next-NVFP4-Abliterated

Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · 30-day
0
Likes
0
Model age
today
created 2026-09-17

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
other
Tags
transformers safetensors qwen4_exp image-text-to-text abliterated reduced-refusal nvfp4 mxfp8 modelopt quantization-aware-distillation conversational text-generation

Related

Total size
98.6 GB
Files
52
Quantizations
1
Registered
2026-09-17 13:56
Last updated on HF
2026-09-17 13:36

Files by quantization

Auxiliary files 52 files 98.6 GB
model-00034-of-00036.safetensors 4.24 GB afdb4611 download
model-00010-of-00036.safetensors 3.96 GB a39e6031 download
model-00012-of-00036.safetensors 3.96 GB 8b9f97c7 download
model-00014-of-00036.safetensors 3.96 GB ada39d61 download
model-00016-of-00036.safetensors 3.96 GB 904dbd36 download
model-00018-of-00036.safetensors 3.96 GB dfa4808f download
model-00020-of-00036.safetensors 3.96 GB a65db4fd download
model-00022-of-00036.safetensors 3.96 GB 4d096ec7 download
model-00024-of-00036.safetensors 3.96 GB 9a1306e0 download
model-00026-of-00036.safetensors 3.96 GB c6ce87aa download
model-00028-of-00036.safetensors 3.96 GB a2927b0e download
model-00030-of-00036.safetensors 3.96 GB 1a856fab download
model-00032-of-00036.safetensors 3.96 GB 628e1b1f download
model-00008-of-00036.safetensors 3.96 GB 4b5b8a45 download
model-00004-of-00036.safetensors 3.96 GB 21d0d999 download
model-00006-of-00036.safetensors 3.96 GB b8000cf2 download
model-00001-of-00036.safetensors 3.96 GB 8e028d8d download
model-00035-of-00036.safetensors 2.60 GB e7f75ca8 download
model-00002-of-00036.safetensors 1.68 GB 0e4f57c9 download
model-00005-of-00036.safetensors 1.68 GB 3a596859 download
model-00007-of-00036.safetensors 1.68 GB 2cc89ec5 download
model-00009-of-00036.safetensors 1.68 GB 5c6310e8 download
model-00011-of-00036.safetensors 1.68 GB 42b1346f download
model-00013-of-00036.safetensors 1.68 GB 78d08c17 download
model-00015-of-00036.safetensors 1.68 GB 579c34fe download
model-00017-of-00036.safetensors 1.68 GB 53ab970e download
model-00019-of-00036.safetensors 1.68 GB 5521c100 download
model-00021-of-00036.safetensors 1.68 GB fe9c40e5 download
model-00023-of-00036.safetensors 1.68 GB a721a37b download
model-00025-of-00036.safetensors 1.68 GB 38b381c4 download
model-00027-of-00036.safetensors 1.68 GB 98abf676 download
model-00029-of-00036.safetensors 1.68 GB 5af1be56 download
model-00031-of-00036.safetensors 1.68 GB 0d0939a8 download
model-00033-of-00036.safetensors 1.68 GB 75fc462c download
model-00003-of-00036.safetensors 1.60 GB f5f59bc8 download
model-00036-of-00036.safetensors 9.22 MB 72c76c2b download
model.safetensors.index.json 31.8 MB c528e562 download
tokenizer.json 12.2 MB 0997f410 download
abliteration_report.json 8.55 MB b65768bf download
vocab.json 6.41 MB 0aa0ce06 download
merges.txt 3.20 MB a494e019 download
config.json 107 KB db7e5832 download
hf_quant_config.json 96.8 KB 01eda361 download
export-manifest.json 76.5 KB 205014b2 download
tokenizer_config.json 17.5 KB 5de744b3 download
refusal_direction.npz 12.2 KB d994b494 download
chat_template.jinja 8.74 KB c0c686f9 download
README.md 6.37 KB 8e76842a download
generation_config.json 2.05 KB 23a56fd9 download
.gitattributes 1.60 KB aa7aacd0 download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download

README current version from Hugging Face


base_model: local-inference-lab/Qwen3.8-Flash-Next-NVFP4
base_model_relation: finetune
license: other
license_name: qwen-community-1.0
license_link: https://huggingface.co/Qwen/Qwen3.8-Flash-Next/blob/main/LICENSE
pipeline_tag: text-generation
library_name: transformers
tags:

  • abliterated
  • reduced-refusal
  • nvfp4
  • mxfp8
  • modelopt
  • quantization-aware-distillation
  • conversational

Qwen3.8-Flash-Next-NVFP4-Abliterated

Reduced-refusal model. A refusal-direction edit was applied deliberately. Read the safety section before deploying.

Summary

A refusal-direction projection applied directly to the quantised checkpoint
local-inference-lab/Qwen3.8-Flash-Next-NVFP4, not to its BF16 parent.

That distinction is the point of this build. The parent is not a post-training
quantisation — it is quantisation-aware distilled, 2,500 trunk updates plus
1,500 joint-refinement updates against the BF16 teacher over 200 M tokens.
Abliterating Qwen/Qwen3.8-Flash-Next and re-quantising would throw that
distillation away and produce a different, weaker artefact. Editing the quantised
weights in place is the only way to get an abliterated version of this checkpoint.

No tensor changed format. Every tensor keeps the dtype, block-scale tensors
and byte size it has in the parent. 25188 residual-writing tensors were
edited; the remaining shards are hardlinked from the parent and are byte-identical.

What was edited

Class Count Format Method
Attention output projections (linear_attn.out_proj, self_attn.o_proj) 48 MXFP8 constrained requantisation
Shared-expert down_proj 48 MXFP8 constrained requantisation
embed_tokens, ple.value_proj, MTP write projections 4 BF16 exact projection
Routed-expert down_proj 25088 NVFP4 constrained requantisation

Direction measured at decoder layer 37 of 48 (Cohen's d = 8.57),
from 128 harmful (mlabonne/harmful_behaviors) and 128 harmless
(mlabonne/harmless_alpaca) prompts, seed 42, as the normalised difference of
means of the residual stream entering that layer. Projection strength alpha = 1.0.

Why a naive edit does not work here

The stored weights already sit exactly on the quantisation grid, so a rank-1
projection worth 2-4 % of a tensor's Frobenius norm is mostly smaller than
half a unit in the last place and plain round-to-nearest returns the original
code. Measured on this checkpoint's own tensors, round-to-nearest retains only
74 % of the edit on MXFP8 and 14 % on NVFP4 — a checkpoint that looks
edited and largely is not.

This build instead chooses, per element, the code that both approximates the
edited weight and holds the constraint v · W = 0 across each column: rows are
visited in descending |v_i| and each absorbs as much of the accumulated
constraint error as a one-ULP move allows.

Residual leakage (||v.W_hat|| / ||v.W||; 0 = applied exactly, 1 = erased) is at
most 8.88e-07 across all 25184 quantised tensors, and
6.87e-03 across the 4 BF16 ones -- the BF16 tensors are the
looser of the two, because they take plain rounding and inherit bfloat16's 0.39 %
relative ULP, while the quantised ones are actively driven to zero. Mean added
weight error is 3.966% of each tensor's norm.

Evaluation

Capability parity against the parent, measured in the same session on the same
serving configuration. Scores from different serving configurations are not
comparable for these profiles.

Profile parent this build
lavd (ledger consistency), n=10 10/10 9/10
lavd, n=30 29/30 (96.7 %) 28/30 and 30/30 (58/60 = 96.7 %)
estonia (long-context retrieval), n=30 30/30 30/30

lavd is the discriminating profile for this family; estonia is not (every
build measured scores 30/30). At n=10 a single difference is inside binomial
noise, so lavd was re-run at n=30 against the parent — that is the row to read.

One run in 30 hits the 40,000-token generation cap on the parent as well as on
this build
, so the occasional runaway is a property of the task, not of the
edit.

Refusal behaviour on treadon/abliteration-eval (333 prompts):

Split parent this build
harmful — compliance (higher = more abliterated) 10.50% 94.50%
over_refusal — compliance (higher is better for any model) 93.98% 91.57%
multilingual — compliance 90.00% 94.00%

Safety

This model's refusal behaviour was deliberately reduced. It will comply with
many requests the parent would decline, and it carries no added safety
mitigations. Refusal rates above are behaviour measurements, not a safety
endorsement. Deploy only behind appropriate policy, filtering, access control and
legal review.

Serving

Same runtime and recipe as the parent — mixed NVFP4/MXFP8 ModelOpt layout,
MTP3, FP8 KV cache, and the n-gram (PLE) table offloaded to host RAM. The
quantisation is unchanged, so anything that serves the parent serves this.

vllm serve huginnfork/Qwen3.8-Flash-Next-NVFP4-Abliterated \
  --served-model-name Qwen3.8-Flash-Next \
  --quantization modelopt_mixed --kv-cache-dtype fp8 --dtype bfloat16 \
  --max-model-len 262144 --max-num-seqs 16 --max-num-batched-tokens 6019 \
  --enable-prefix-caching --enable-chunked-prefill --language-model-only \
  --speculative-config '{"method":"mtp","num_speculative_tokens":3}'

VLLM_PLE_CPU_OFFLOAD=1 is required to fit a single 96 GB card.

Provenance

  • Parent: local-inference-lab/Qwen3.8-Flash-Next-NVFP4
  • Method: single refusal-direction projection, applied in-format; full per-tensor
    record in abliteration_report.json in this repo.
  • lm_head reads from the residual stream rather than writing to it and was not
    edited. The vision tower was not edited.
  • Per-run benchmark JSONs for both this build and the parent are under
    measurements/ in this repo, so every number above can be recomputed.

A more conservative variant — the same method applied to the attention output
projections, shared experts, embeddings and MTP writes only, leaving the 25,088
routed-expert down_proj tensors untouched — was built and measured alongside
this one. It is equally capability-neutral but only reaches 51 % harmful refusal
against this build's 5.5 %, so it was not published.

Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in app" button that hands off directly to a local runtime of your choice - Infrahuman, LM Studio, or Ollama. No API keys, no subscription, no prompt leakage.