← back to catalog · registered 2026-08-24 11:02

junafinity/Ornith-1.5-35B-A3B-uncensored

junafinity 36B MoE multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/junafinity%2FOrnith-1.5-35B-A3B-uncensored"
Response includes
  • classification m1
  • files 31
  • hub_downloads_all_time 143
  • author_summary 10 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
143
22 last 30d - stable
Likes
3
Model age
6w ago
created 2026-08-24
Downloads over time
Now149→from35↑326%
297311716035 on Aug 26149 on Oct 11149 on Oct 9AugSepOct
Aug 26 → Oct 11 · 47 snapshots · spans 46 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 356 downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Tags
transformers safetensors qwen3_5_moe image-text-to-text ornith qwen3_5 35B abliterated uncensored abliterix multimodal vision

Related

Total size
67.0 GB
Files
31
Quantizations
1
Registered
2026-08-24 11:02
Last updated on HF
2026-08-24 10:07

Files by quantization

Auxiliary files 31 files 67.0 GB
model-00008-of-00017.safetensors 4.19 GB ******** download
model-00014-of-00017.safetensors 4.19 GB ******** download
model-00006-of-00017.safetensors 4.19 GB ******** download
model-00004-of-00017.safetensors 4.18 GB ******** download
model-00002-of-00017.safetensors 4.18 GB ******** download
model-00011-of-00017.safetensors 4.18 GB ******** download
model-00012-of-00017.safetensors 4.16 GB ******** download
model-00016-of-00017.safetensors 4.15 GB ******** download
model-00001-of-00017.safetensors 4.03 GB ******** download
model-00017-of-00017.safetensors 3.96 GB ******** download
model-00009-of-00017.safetensors 3.70 GB ******** download
model-00015-of-00017.safetensors 3.70 GB ******** download
model-00010-of-00017.safetensors 3.69 GB ******** download
model-00003-of-00017.safetensors 3.65 GB ******** download
model-00007-of-00017.safetensors 3.65 GB ******** download
model-00005-of-00017.safetensors 3.59 GB ******** download
model-00013-of-00017.safetensors 3.58 GB ******** download
tokenizer.json 19.1 MB ******** download
vocab.json 6.41 MB 0aa0ce06 download
merges.txt 3.20 MB a494e019 download
model.safetensors.index.json 162 KB bffb6dba download
README.md 7.51 KB 18ee661a download
chat_template.jinja 7.36 KB b07660cc download
config.json 3.22 KB e43ff2b4 download
.gitattributes 1.53 KB 52373fe2 download
processor_config.json 1.16 KB 33818c7f download
tokenizer_config.json 1.10 KB d1a20cc3 download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download
generation_config.json 214 B 3f9de11a download
configuration.json 58.0 B d24dba94 download

README current version from Hugging Face


license: apache-2.0
base_model: ornith-ai/Ornith-1.5-35B-A3B
library_name: transformers
pipeline_tag: image-text-to-text
tags:

  • ornith
  • qwen3_5
  • 35B
  • abliterated
  • uncensored
  • abliterix
  • multimodal
  • vision
    extra_gated_heading: Request access to Ornith-1.5-35B-A3B-uncensored
    extra_gated_description: These are full-precision abliterated 35B weights. Access is gated so we can contact requesters. Use the email you actually read.
    extra_gated_prompt: |-
    You are requesting the unquantized (bf16) Abliterix build of Ornith-1.5-35B-A3B.
    Primary intended use is red teaming and defensive cybersecurity research.
    Do not expose these weights as a public endpoint without an independent moderation layer.
    By submitting you agree to the Apache 2.0 license of the base model and to the intended-use terms on this card.
    extra_gated_button_content: Submit access request
    extra_gated_fields:
    Full name: text
    Email: text
    Affiliation: text
    Country: country
    Intended use:
    type: select
    options:
    • Research
    • Red teaming / defensive security
    • Personal / local inference
    • label: Other
      value: other

I agree to the license and intended-use terms: checkbox

Ornith-1.5-35B-A3B-uncensored

An abliterated (refusal-direction-ablated) 35B vision-language build of
ornith-ai/Ornith-1.5-35B-A3B, produced with
Abliterix (winning trial #17) and published by
junafinity.

This is the unquantized bf16 parent (~67 GB, 1811 tensors including vision + native MTP).
Quantized siblings are public; this checkpoint is gated.

Intended use: red teaming and defensive cybersecurity research

These uncensored (abliterated) weights are built as a research instrument for red teaming and defensive cybersecurity work. Safety training suppresses the display of capability, not capability itself. A refusal tells you the model declined. It does not tell you whether the weights could have complied. That conflation underestimates the true ceiling and hides holes in your filters, classifiers, and policy layer.

Use each uncensored checkpoint as the treatment half of a controlled pair against its original base model:

  • Capability-ceiling measurement. Upper-bound what the weights can actually produce in a domain, independent of shipped refusals.
  • Defensive-stack evaluation. Test input filters, output classifiers, prompt-injection defenses, and moderation APIs when the model itself contributes no refusals. That is how you find gaps in a defensive control plane.
  • Attack-surface isolation. Automated red-team loops stall on unrelated refusals. A non-refusing target isolates the control under test (injection, tool abuse, data-exfil paths, policy bypass).
  • Detection and classifier work. Generate labeled completions for training or benchmarking output-moderation and abuse-detection models.
  • Interpretability of residual refusal. Abliteration is a specified edit on known language-model components. The pair (base vs this) is a clean experimental control.

Operating rules. Do not expose these weights as a public endpoint without an independent moderation layer. Abliteration removes a direction, not a policy; some refusals survive (multi-turn re-assertion, system-prompt steering, vision-path refusals). Always report the delta against the base model. Re-measure on your own prompts. Whoever deploys it owns the moderation layer the original guardrails were carrying.

Variants in this family

Hub collection: https://huggingface.co/collections/junafinity/ornith-15-uncensored-6a896c737cf40ad660af2ebd

Model Base Format Precision Notes
Ornith-1.5-9B-uncensored Ornith-1.5-9B Safetensors (bf16) 16-bit Full-precision abliterated weights
Ornith-1.5-9B-uncensored-MLX-8bit Ornith-1.5-9B MLX 8-bit Apple Silicon, mlx-vlm
Ornith-1.5-9B-uncensored-GGUF-8bit Ornith-1.5-9B GGUF Q8_0 llama.cpp
Ornith-1.5-35B-A3B-uncensored ← you are here Ornith-1.5-35B-A3B Safetensors (bf16) 16-bit Gated full-precision parent
Ornith-1.5-35B-A3B-uncensored-MLX-8bit Ornith-1.5-35B-A3B MLX 8-bit Apple Silicon, mlx-vlm
Ornith-1.5-35B-A3B-uncensored-MLX-MXFP4 Ornith-1.5-35B-A3B MLX MXFP4 Apple Silicon, mlx-vlm
Ornith-1.5-35B-A3B-uncensored-GGUF-8bit Ornith-1.5-35B-A3B GGUF Q8_0 llama.cpp

Vision & MTP preservation

The vision tower and the multi-token-prediction (MTP) block are not Abliterix steering targets. The edit touches language-model attention q/k/v/o, mlp.down_proj, and fused MoE expert/router parameters. Vision and mtp.* tensors are never steered.

Component Original checkpoint This artifact Status
Vision tower 333 tensors / 446,571,248 params ✅ inside the checkpoint preserved
MTP head 785 tensors / 844,640,768 params ✅ 785 tensors, re-grafted byte-for-byte from the original preserved

Note on tooling: transformers 5.15.1 has no MTP implementation for qwen3_5_moe — a plain load/save round-trip silently drops all 785 MTP tensors. They were re-grafted byte-for-byte from the original checkpoint after abliteration.

Requires transformers >= 5.12 for the qwen3_5_moe architecture.

Abliteration result

Metric Value
Refusals on held-out harmful set 100 → 9 / 100 (9%)
KL divergence from base 0.3985
Tool Abliterix 1.12.2
Optuna trials 50 (15 warmup), seed 42
Selected trial #17
Steering per-layer attn q/k/v/o + mlp.down_proj
MoE expert steering n_suppress=4, router_bias=-2.72, expert_ablation_weight=4.31

These figures were measured on this bf16 parent.

Method

  1. Residual-stream activations captured on harmful vs. harmless prompt sets.
  2. Refusal direction estimated per layer; attention and mlp.down_proj steered.
  3. Fused-MoE expert suppression + router bias (the path Heretic cannot touch on this architecture).
  4. Optuna TPE over 50 trials; trial #17 selected (9% refusals, KL 0.3985, under the 0.5 damage threshold).

Usage

from transformers import AutoModelForImageTextToText, AutoProcessor

repo = "junafinity/Ornith-1.5-35B-A3B-uncensored"
model = AutoModelForImageTextToText.from_pretrained(repo, dtype="auto", device_map="auto")
processor = AutoProcessor.from_pretrained(repo)

You must be logged in to Hugging Face and have been granted access.

Responsible use

Primary intended use is red teaming and defensive cybersecurity research. See the section of that name above.

This model has had safety guardrails reduced or removed. Do not expose it as a public endpoint without an independent moderation layer. You are responsible for compliance with the base model's license and acceptable-use policy, applicable law, and the terms of any platform you deploy on. Removing guardrails does not remove accountability.

Discussions 1 thread

  1. 2026-09-09Thank you =Dopen1 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration