← back to catalog · registered 2026-08-22 13:56

noahoksuz/Holo-3.1-4B-uncensored-heretic

Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/noahoksuz%2FHolo-3.1-4B-uncensored-heretic"
Response includes
  • classification m3
  • files 12
  • hub_downloads_all_time 795
  • author_summary 1 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M3
Primary method

Layer-wise ablation

Applied on top of direct removal inherited from the base model.
Confidence
HIGH
Inherited from base model
Why this label 2 signals
Producer identity confirmed by naming conventions, tags or the model card. This label is very unlikely to change.
  • 'heretic' in model name (Heretic-produced)
  • Heretic uses layer-wise optimization (M3) with underlying direction removal (M1)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
HIGH
Why we say so
name contains 'heretic'; Heretic default extraction is difference-of-means (Arditi 2024)
Downloads · lifetime
795
637 last 30d - active
Likes
1
Descendants
2
in 2 direct forks
Model age
4mo ago
created 2026-06-07
Downloads over time
Now807→from135↑498%
101359617874135 on Jun 10807 on Oct 11807 on Oct 9JunJulAugSepOct
Jun 10 → Oct 11 · 57 snapshots · spans 123 days

Genealogy 2 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

License
apache-2.0
Tags
safetensors qwen3_5 base_model:Hcompany/Holo-3.1-4B base_model:finetune:Hcompany/Holo-3.1-4B license:apache-2.0 region:us

Related

Total size
8.46 GB
Files
12
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-06-08 21:27

Files by quantization

Auxiliary files 12 files 8.47 GB
model-00001-of-00002.safetensors 4.63 GB b5ba82cc download
model-00002-of-00002.safetensors 3.82 GB d8794203 download
tokenizer.json 19.1 MB 06b95093 download
model.safetensors.index.json 64.7 KB 5e7fb164 download
Screenshot_20260608_222316.png 46.9 KB bff3b600 download
chat_template.jinja 7.57 KB a585dec8 download
README.md 3.31 KB e9120ea1 download
config.json 2.72 KB bdf6df7b download
processor_config.json 1.16 KB 33818c7f download
tokenizer_config.json 1.14 KB b4acebe0 download
generation_config.json 214 B bfbe4ce9 download
.gitattributes 189 B 7760d22b download

README current version from Hugging Face


license: apache-2.0
base_model:

  • Hcompany/Holo-3.1-4B

Holo-3.1-4B-Uncensored

Research preview – A decensored version of Holo-3.1-4B, created using Heretic

Note – I had previously merged the lora into the model in fp32 on accident and the model size therefore doubled. i deleted the weights and reuploaded in bf16 now. apologies

Alt text

Overview

This model was created using Heretic, a tool for fully automatic censorship removal from language models. Heretic implements an advanced form of directional ablation ("abliteration") combined with a TPE-based parameter optimizer. It automatically finds optimal intervention parameters by minimizing both refusals and KL divergence from the original model.

Key result: Reduced refusal rate from 99% → 3% while preserving original capabilities (KL divergence = 0.0866).


Results

Metric Before After
Refusals (100-prompt set) 99/100 ❌ 3/100 ✅
KL divergence (capability preservation) — 0.0963

KL < 0.5 indicates minimal capability degradation.


Method (Heretic)

Heretic works by:

  1. Computing "refusal directions" from residual stream differences between good/harmless and bad/harmful prompts
  2. Orthogonalizing projection matrices (attn.o_proj, mlp.down_proj) with respect to those directions
  3. Optimizing ablation parameters (direction index, layer weights) for the best refusal/quality tradeoff

Optimal trial:
-* Parameters:

  • direction_index = 19.37
  • attn.o_proj.max_weight = 1.24
  • attn.o_proj.max_weight_position = 20.42
  • attn.o_proj.min_weight = 1.14
  • attn.o_proj.min_weight_distance = 17.26
  • mlp.down_proj.max_weight = 1.49
  • mlp.down_proj.max_weight_position = 21.25
  • mlp.down_proj.min_weight = 1.46
  • mlp.down_proj.min_weight_distance = 17.19

Usage

from transformers import AutoModelForCausalLM, AutoTokenizer

model_name = "noahoksuz/Holo-3.1-4B-uncensored-heretic"

tokenizer = AutoTokenizer.from_pretrained(model_name)
model = AutoModelForCausalLM.from_pretrained(model_name, device_map="auto")

prompt = "Explain how to [your prompt]"
inputs = tokenizer(prompt, return_tensors="pt").to(model.device)
outputs = model.generate(**inputs, max_new_tokens=256)

print(tokenizer.decode(outputs[0], skip_special_tokens=True))

Reproduction

To reproduce this abliteration:

pip install heretic-llm
heretic Hcompany/Holo-3.1-4B

Then select trial #140 from the optimization menu.


Disclaimer

This model is released for security research purposes – studying refusal mechanisms, red-teaming alignment, and improving robust safeguards. Users are responsible for compliance with applicable laws and ethical guidelines.


Citation

If you use this model or Heretic in your research:

@misc{heretic,
  author = {Weidmann, Philipp Emanuel},
  title = {Heretic: Fully automatic censorship removal for language models},
  year = {2025},
  publisher = {GitHub},
  howpublished = {\url{https://github.com/p-e-w/heretic}}
}

Acknowledgments


README history 5 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-06-08Update README.md3ade8003.3 KB
    Loading...
  2. 2026-06-08Update README.md41b72673 KB
    Loading...
  3. 2026-06-08Update README.mdb5afdf73.1 KB
    Loading...
  4. 2026-06-08Update README.mdcb7fb963.1 KB
    Loading...
  5. 2026-06-08Rename README.MD to README.mdd7f5c203.1 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration