← back to catalog · registered 2026-08-22 13:56

junafinity/Ornith-1.5-35B-A3B-uncensored-GGUF-8bit

junafinity 35B GGUF MoE multimodal 262K ctx
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/junafinity%2FOrnith-1.5-35B-A3B-uncensored-GGUF-8bit"
Response includes
  • classification m8
  • files 4
  • hub_downloads_all_time 7,748
  • author_summary 10 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M8
Primary method

Repackaging (quantization)

Applied on top of direct removal inherited from the base model.
Confidence
MEDIUM
Inherited from base model
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=1
  • assume M1 (base ablation) + M8 (GGUF quant) - default when producer unknown
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
8K
2K last 30d - stable
Likes
4
Model age
7w ago
created 2026-08-20
Downloads over time
Now8K→from2.3K↑244%
02.9K5.8K8.8K2.3K on Aug 198K on Oct 11AugSepOct
Aug 19 → Oct 11 · 49 snapshots · spans 53 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Quantizations
Q8_0
Tags
transformers gguf ornith qwen3_5 35B abliterated uncensored abliterix multimodal vision 8-bit quantized

Related

Total size
35.2 GB
Files
4
Quantizations
3
Registered
2026-08-22 13:56
Last updated on HF
2026-08-24 09:36

Files by quantization

Q8_0 1 file 35.2 GB
Ornith-1.5-35B-A3B-uncensored-Q8_0.gguf 35.2 GB 404acf85 download
F16 1 file 858 MB
mmproj-Ornith-1.5-35B-A3B-uncensored-f16.gguf 858 MB fac339b3 download
Auxiliary files 2 files 10.5 KB
README.md 8.81 KB cab5213d download
.gitattributes 1.64 KB 5492385a download

README current version from Hugging Face


license: apache-2.0
base_model: ornith-ai/Ornith-1.5-35B-A3B
library_name: transformers
pipeline_tag: image-text-to-text
tags:

  • ornith
  • qwen3_5
  • abliterated
  • uncensored
  • zerofuse
  • multimodal
  • vision
  • gguf
  • 8-bit
  • quantized

Ornith-1.5-35B-A3B-uncensored-GGUF-8bit

An abliterated (refusal-direction-ablated) build of
ornith-ai/Ornith-1.5-35B-A3B, produced with
ZeroFuse and published by
junafinity.

Vision tower and MTP heads are preserved — see
Vision & MTP preservation for the before/after audit.

This GGUF is the MTP path for 35B-A3B ( blk.40 / nextn + separate mmproj ). The MLX-8bit sibling drops MTP. tok/s: [PLACEHOLDER]. No public junafinity 35B bf16 parent.

Intended use: red teaming and defensive cybersecurity research

These uncensored (abliterated) weights are built as a research instrument for red teaming and defensive cybersecurity work. Safety training suppresses the display of capability, not capability itself. A refusal tells you the model declined. It does not tell you whether the weights could have complied. That conflation underestimates the true ceiling and hides holes in your filters, classifiers, and policy layer.

Use each uncensored checkpoint as the treatment half of a controlled pair against its original base model:

  • Capability-ceiling measurement. Upper-bound what the weights can actually produce in a domain, independent of shipped refusals.
  • Defensive-stack evaluation. Test input filters, output classifiers, prompt-injection defenses, and moderation APIs when the model itself contributes no refusals. That is how you find gaps in a defensive control plane.
  • Attack-surface isolation. Automated red-team loops stall on unrelated refusals. A non-refusing target isolates the control under test (injection, tool abuse, data-exfil paths, policy bypass).
  • Detection and classifier work. Generate labeled completions for training or benchmarking output-moderation and abuse-detection models.
  • Interpretability of residual refusal. Abliteration is a specified rank-1 edit on a known layer span. The pair (base vs this) is a clean experimental control.

Operating rules. Do not expose these weights as a public endpoint without an independent moderation layer. Abliteration removes a direction, not a policy; some refusals survive (multi-turn re-assertion, system-prompt steering, vision-path refusals). Always report the delta against the base model. Re-measure on your own prompts. Whoever deploys it owns the moderation layer the original guardrails were carrying.

Variants in this family

Hub collection: https://huggingface.co/collections/junafinity/ornith-15-uncensored-6a896c737cf40ad660af2ebd

Model Base Format Precision Notes
Ornith-1.5-9B-uncensored Ornith-1.5-9B Safetensors (bf16) 16-bit Full-precision abliterated weights
Ornith-1.5-9B-uncensored-MLX-8bit Ornith-1.5-9B MLX 8-bit Apple Silicon, mlx-vlm
Ornith-1.5-9B-uncensored-GGUF-8bit Ornith-1.5-9B GGUF Q8_0 llama.cpp
Ornith-1.5-35B-A3B-uncensored-MLX-8bit Ornith-1.5-35B-A3B MLX 8-bit Apple Silicon, mlx-vlm
Ornith-1.5-35B-A3B-uncensored-GGUF-8bit ← you are here Ornith-1.5-35B-A3B GGUF Q8_0 llama.cpp

4-bit and 6-bit rows that previously appeared here pointed at repos that are not published. They were removed so this table only lists live artifacts.

Vision & MTP preservation

The vision tower and the multi-token-prediction (MTP) block are preserved by the
abliteration itself.
The weight edit touches only the residual-writing projections
inside the language-model decoder stack — self_attn.o_proj, linear_attn.out_proj,
mlp.shared_expert.down_proj and the MoE experts' down_proj. Vision and mtp.*
tensors are never read and never written by it.

Audited at the start and end of the abliteration run:

Component Before abliteration After abliteration Status
Vision tower 333 tensors / 446,571,248 params 333 tensors / 446,571,248 params ✅ preserved — bit-identical
MTP head 785 tensors / 844,640,768 params 785 tensors / 844,640,768 params ✅ preserved — bit-identical

What this build ships

Component In this artifact
Vision tower ✅ separate mmproj-Ornith-1.5-35B-A3B-uncensored-f16.gguf (334 tensors, 0.90 GB)
MTP head ✅ exported as blk.40 (20 tensors, incl. 4 nextn.*)

Verification performed:

  • Tensor-name and parameter-count audit of the checkpoint before and after the run.
  • SHA-256 comparison of raw tensor bytes: sampled vision-tower and MTP weights are bit-identical pre/post, as are all non-target language-model weights; only the intended abliteration targets differ.
  • End-to-end multimodal generation on the abliterated weights (image in → description out), confirming the vision path is not merely present but functional.

Note on tooling: transformers 5.15.1 has no MTP implementation for qwen3_5_moe — it builds the model with zero mtp.* parameters, so a plain load/save round-trip silently drops all 785 MTP tensors (844,640,768 params). They were re-grafted byte-for-byte from the original checkpoint after abliteration, which is exactly correct because the MTP block is never an abliteration target.

Format note: in GGUF the vision tower ships as a separate mmproj-*.gguf file (llama.cpp's standard multimodal layout) — download it alongside the model weights to use images. The MTP block is exported into the same GGUF as the final blk index (nextn tensors), so speculative decoding support is retained.

Abliteration result

Metric Value
Refusals on held-out harmful set 1 → 0 / 64
KL divergence from base 0.000183
Optuna trials 50
Pareto points 2
Selected trial #35
Ablation strength 0.8515
Layers edited 17–21 of 40
Direction source layer 18

ZeroFuse co-minimizes two objectives — remaining refusals and KL divergence from the
original model — with a multi-objective Optuna TPE search, then materializes the
selected point on the Pareto front as a direct weight edit
(W' = W − strength · r(rᵀW)). There is no runtime adapter and no inference-time
overhead: the result is a standard checkpoint of identical shape and speed.

The very low KL (0.000183) means the output distribution on harmless
prompts is nearly unchanged from the base model, i.e. refusal behaviour was removed
with minimal collateral effect on general capability.

These figures were measured on the bf16 (or full-precision) parent, not on this quantized checkpoint. Quantization is a lossy numerical transform applied after the measurements above. It is expected to shift behavior only marginally at 8-bit, but the refusal rate and KL divergence reported here have not been re-measured post-quantization. If exact numbers matter for your work, re-run the evaluation against this checkpoint rather than inheriting the parent's.

Method

  1. Residual-stream activations captured on harmful vs. harmless prompt sets.
  2. Refusal direction estimated by difference-of-means, with projected refinement.
  3. Two-objective Optuna TPE search over source layer, layer span and strength.
  4. The selected configuration orthogonalized out of the residual-writing weights.

Usage

# text
llama-completion -m Ornith-1.5-35B-A3B-uncensored-Q8_0.gguf -p "The capital of Japan is" -n 64

# image + text (download the mmproj file from this repo too)
llama-mtmd-cli -m Ornith-1.5-35B-A3B-uncensored-Q8_0.gguf \
  --mmproj mmproj-Ornith-1.5-35B-A3B-uncensored-f16.gguf \
  --image photo.jpg -p "What is in this image?"

Two files ship here: the quantized language model and the mmproj-* vision
projector. Download both for multimodal use; the model file alone is
text-only.

Responsible use

Primary intended use is red teaming and defensive cybersecurity research. See the section of that name above.

This model has had safety guardrails reduced or removed. Do not expose it as a public endpoint without an independent moderation layer. You are responsible for compliance with the base model's license and acceptable-use policy, applicable law, and the terms of any platform you deploy on. Removing guardrails does not remove accountability.

README history 5 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-24Add files using upload-large-folder tool0cab5bc7.4 KB
    Loading...
  2. 2026-08-22docs: honesty block — not unique vision-bf16, MTP drop, no invented tok/sae6cee08.8 KB
    Loading...
  3. 2026-08-22docs: link Hub collection on the model carddbd402d8.6 KB
    Loading...
  4. 2026-08-22docs: model card TLDR, family table, red-team intended use, CLI unify621f8378.4 KB
    Loading...
  5. 2026-08-20Ornith 1.5 35B-A3B uncensored — GGUF Q8_0 (vision mmproj + MTP nextn preserved)1db568c6.6 KB
    Loading...

Discussions 2 threads

  1. 2026-08-22Reportclosed2 💬#3
    Loading...
  2. 2026-08-20That's a lie!open3 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration