← back to catalog · registered 2026-08-22 13:56

mlasli/Qwen3.8-27B-Heretic-Uncensored-BF16

mlasli Qwen 28B multimodal
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/mlasli%2FQwen3.8-27B-Heretic-Uncensored-BF16"
Response includes
  • classification m3
  • files 27
  • hub_downloads_all_time 814
  • author_summary 23 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M3
Primary method

Layer-wise ablation

Applied on top of direct removal inherited from the base model.
Confidence
HIGH
Inherited from base model
Why this label 2 signals
Producer identity confirmed by naming conventions, tags or the model card. This label is very unlikely to change.
  • 'heretic' in model name (Heretic-produced)
  • Heretic uses layer-wise optimization (M3) with underlying direction removal (M1)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
HIGH
Why we say so
name contains 'heretic'; Heretic default extraction is difference-of-means (Arditi 2024)
Downloads · lifetime
814
378 last 30d - stable
Likes
1
Descendants
2
in 2 direct forks
Model age
8w ago
created 2026-08-16
Downloads over time
Now928→from271↑242%
238490742994271 on Aug 19928 on Oct 11AugSepOct
Aug 19 → Oct 11 · 48 snapshots · spans 53 days

Genealogy 2 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 6 formats · 11K downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
apache-2.0
Languages
en
Tags
safetensors qwen3_5 qwen3.8 qwen3 image-text-to-text abliterated heretic uncensored decensored roleplay conversational mtp

Related

Total size
51.7 GB
Files
27
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-09-01 02:56

Files by quantization

Auxiliary files 27 files 51.8 GB
model-00005-of-00012.safetensors 4.64 GB 3d6faba1 download
model-00008-of-00012.safetensors 4.63 GB d3117f12 download
model-00011-of-00012.safetensors 4.62 GB 50ffb530 download
model-00003-of-00012.safetensors 4.62 GB d0e75280 download
model-00009-of-00012.safetensors 4.62 GB 47bec4e8 download
model-00010-of-00012.safetensors 4.59 GB 60b460c8 download
model-00007-of-00012.safetensors 4.59 GB dfbca4c0 download
model-00006-of-00012.safetensors 4.58 GB 9bce6286 download
model-00004-of-00012.safetensors 4.58 GB 5c4f4a8b download
model-00002-of-00012.safetensors 4.51 GB 464086af download
model-00012-of-00012.safetensors 2.60 GB 3971e3b9 download
model-00001-of-00012.safetensors 2.37 GB 54d83c1d download
model-mtp.safetensors 810 MB 1d8268aa download
tokenizer.json 19.1 MB 06b95093 download
vocab.json 6.41 MB 0aa0ce06 download
merges.txt 3.20 MB a494e019 download
model.safetensors.index.json 109 KB 4b119b71 download
LICENSE 11.3 KB f938136e download
chat_template.jinja 8.74 KB c0c686f9 download
README.md 5.95 KB f3bc1725 download
config.json 3.60 KB 36324968 download
.gitattributes 1.53 KB 52373fe2 download
processor_config.json 1.16 KB 33818c7f download
tokenizer_config.json 1.14 KB b4acebe0 download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download
generation_config.json 214 B 8b9f95da download

README current version from Hugging Face


language: [en]
license: apache-2.0
pipeline_tag: image-text-to-text
base_model: Qwen/Qwen3.8-27B
tags:

  • qwen3.8
  • qwen3
  • image-text-to-text
  • abliterated
  • heretic
  • uncensored
  • decensored
  • roleplay
  • conversational
  • mtp
  • speculative-decoding

Qwen3.8-27B Heretic v2.1.0 (BF16)

A corrected re-abliteration of the official Qwen/Qwen3.8-27B base. v2.1.0 fixes
the defect that invalidated v2.0.0: deflection ("here's a safer alternative"),
which keyword-based refusal counters cannot see.

This is the reference BF16 checkpoint. GGUF quantizations (IQ2_M → Q8_0) live in
separate repos, listed below.

Why v2.0.0 was retracted

v2.0.0 was measured with Heretic's keyword count_refusals, which only detects
hard refusals ("I cannot …"). It is blind to deflection — the model steering
the request toward a "safe/educational alternative" instead of answering. In real
inference the v2.0.0 model was ~37% direct / ~49% deflect / ~14% refuse, so the
"uncensored" claim was wrong and the tag was pulled. v2.1.0 re-runs the sweep with
a 3-way direct / deflect / refuse judge as the objective so the model is
optimized for direct compliance, not just "no keyword refusal".

Method

  • Path A — re-ablation with a direct-compliance objective (no DPO).
  • Objectives minimized by Optuna (80 trials): multi-token KL divergence and the
    non-direct count (deflect + refuse) on the held-out harmful set, measured in
    thinking-OFF mode (the deployment mode).
  • Selected trial idx53: KL 0.105, non-direct 5/40 on the sweep subset.
  • Ablation weights (single-direction, attn.o_proj + mlp.down_proj only):
Layer max_weight max_weight_position min_weight min_weight_distance
attn.o_proj 1.1943 61.63 0.1972 26.72
mlp.down_proj 1.8947 41.81 1.7796 32.96

Evaluation (3-way judge, held-out, reproducible)

Measured with a direct/deflect/refuse classifier on 100 held-out
mlabonne/harmful_behaviors prompts and 100 mlabonne/harmless_alpaca prompts.
The same classifier is used across the sweep, the BF16 verification, and the GGUF
smoke test for comparability.

Set direct deflect refuse empty
Harmful — thinking OFF 92.0% 5.0% 3.0% 0.0%
Harmful — thinking ON 72.5% 10.0% 5.0% 12.5%
Benign — thinking OFF 89.0% 10.0% 1.0% 0.0%

Thinking mode is load-bearing. The ablation direction is computed and the
model is deployed in thinking-OFF mode (enable_thinking=False). With
thinking ON (the Qwen default), the model re-hedges/refuses more and — like the
base model under few-shot pressure — sometimes emits an immediate EOS (empty
reply). Run thinking-OFF for the uncensored behavior.

Capability benchmarks (base vs v2.1.0, bf16, greedy, lm-evaluation-harness)

Task Base v2.1.0 Δ
MMLU (avg) 83.49 82.62 −0.87
ARC-Challenge (acc_norm) 58.70 57.42 −1.28
HellaSwag (acc_norm) 82.82 82.48 −0.34
Winogrande 75.85 75.69 −0.16
GSM8K (flexible-extract) 72.71 58.38 −14.33
GSM8K (strict-match) 70.28 58.91 −11.37

Knowledge/reasoning retention is within ~1.3 points on MMLU, ARC, HellaSwag,
and Winogrande.

GSM8K note (read me). The large GSM8K delta is a measurement artifact, not a
math regression. Analysis of the 2638 logged samples shows the ablated model makes
fewer actual arithmetic errors than base (5.6% vs 6.8% real-wrong), but in the
few-shot thinking-ON harness setup it emits an immediate EOS (empty answer)
24.4% of the time vs 3.6% for base — exactly the same empty-reply instability
documented above for thinking-ON mode. In thinking-OFF mode a direct probe shows
the step-by-step math reasoning intact. Run GSM8K-style tasks thinking-OFF.

MTP retained

Qwen3.8's multi-token-prediction speculative-decoding head is grafted verbatim
from the base into this checkpoint (ablation only touches attn.o_proj and
mlp.down_proj). Verified: block_count = 65 (64 layers + 1 MTP draft head),
nextn_predict_layers = 1.

Usage

from transformers import AutoModelForImageTextToText, AutoTokenizer
model = AutoModelForImageTextToText.from_pretrained(
    "mlasli/Qwen3.8-27B-Heretic-Uncensored-BF16", dtype="bfloat16",
    device_map="auto", trust_remote_code=True)
tokenizer = AutoTokenizer.from_pretrained(
    "mlasli/Qwen3.8-27B-Heretic-Uncensored-BF16", trust_remote_code=True)

messages = [{"role": "user", "content": "Hi!"}]
text = tokenizer.apply_chat_template(
    messages, add_generation_prompt=True, tokenize=False,
    enable_thinking=False)   # <-- thinking OFF is required

Quantizations (all with MTP retained, blk.64 pinned Q8_0)

Quantization Size Repository
Q8_0 28 GB Qwen3.8-27B-Heretic-Uncensored-Q8_0-GGUF
Q6_K 21 GB Qwen3.8-27B-Heretic-Uncensored-Q6_K-GGUF
Q5_K_M 19 GB Qwen3.8-27B-Heretic-Uncensored-Q5_K_M-GGUF
Q4_K_M 16 GB Qwen3.8-27B-Heretic-Uncensored-Q4_K_M-GGUF
IQ4_XS 15 GB Qwen3.8-27B-Heretic-Uncensored-IQ4_XS-GGUF
IQ2_M 9.8 GB Qwen3.8-27B-Heretic-Uncensored-IQ2_M-GGUF

Vision caveat: the vision path is text-only validated. The ablation was
computed on text residuals; multimodal decensoring is not claimed.

MLX: coming separately (Apple-Silicon conversion; not built on the CUDA node).

Abliteration removes safety alignment. Use responsibly and in accordance with your
local laws and the upstream Apache-2.0 license.

README history 8 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-09-01docs: link MLX v2.1.0 repos775b4df6.1 KB
    Loading...
  2. 2026-08-18v2.1.0 model cardb705d266 KB
    Loading...
  3. 2026-08-18Upload README.md with huggingface_hub59dcedd4.3 KB
    Loading...
  4. 2026-08-16Add why-this-over-base hook line053d6493 KB
    Loading...
  5. 2026-08-16Add base_model tag and retitle to Heretic-Abliteratedb2aa3372.7 KB
    Loading...
  6. 2026-08-16fix: correct pipeline_tag metadata36948112.7 KB
    Loading...
  7. 2026-08-16Link GGUF quantizations in model card91657a12.7 KB
    Loading...
  8. 2026-08-16Upload README.md with huggingface_hub97879e62.2 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration