← back to catalog · registered 2026-08-22 13:56

ressl/Laguna-S-2.1-Uncensored

ressl 118B MoE
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/ressl%2FLaguna-S-2.1-Uncensored"
Response includes
  • classification m-uncensored
  • files 61
  • hub_downloads_all_time 101
  • author_summary 28 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M-U
Primary method

Uncensored (method unknown)

No other method signals detected in this model.
Confidence
LOW
Why this label 3 signals
Weak or ambiguous signals. Best guess based on catalog patterns; treat as tentative and check the evidence below.
  • 'uncensored' in name/tags but no 'abliterated' marker
  • method not identifiable from author declaration alone
  • may be DPO fine-tune, prompt engineering, or unknown technique
Refusal direction extraction

No specific extraction method could be identified for this model. The producer either did not document it or used a proprietary pipeline.

What is a refusal direction? →
Downloads · lifetime
101
50 last 30d - stable
Likes
1
Model age
2mo ago
created 2026-08-02
Downloads over time
Now116→from16↑625%
11498812616 on Aug 5116 on Oct 11AugSepOct
Aug 5 → Oct 11 · 50 snapshots · spans 67 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Metadata

Languages
en de
Tags
transformers safetensors laguna text-generation moe uncensored bilingual code conversational custom_code en de

Related

Total size
219 GB
Files
61
Quantizations
1
Registered
2026-08-22 13:56
Last updated on HF
2026-08-02 21:51

Files by quantization

Auxiliary files 61 files 219 GB
model-00011-of-00048.safetensors 4.64 GB b19e9218 download
model-00012-of-00048.safetensors 4.64 GB 4372827e download
model-00014-of-00048.safetensors 4.64 GB 9e897b48 download
model-00015-of-00048.safetensors 4.64 GB 311c8dae download
model-00016-of-00048.safetensors 4.64 GB 70f9cf27 download
model-00018-of-00048.safetensors 4.64 GB 459e886c download
model-00019-of-00048.safetensors 4.64 GB f0557fa0 download
model-00020-of-00048.safetensors 4.64 GB 16a1bc79 download
model-00022-of-00048.safetensors 4.64 GB 07800b97 download
model-00023-of-00048.safetensors 4.64 GB 1713092d download
model-00024-of-00048.safetensors 4.64 GB 0b90cd96 download
model-00026-of-00048.safetensors 4.64 GB 2024c251 download
model-00027-of-00048.safetensors 4.64 GB 83c0a710 download
model-00028-of-00048.safetensors 4.64 GB d078e03c download
model-00030-of-00048.safetensors 4.64 GB 9fcf8d0f download
model-00031-of-00048.safetensors 4.64 GB 00782378 download
model-00032-of-00048.safetensors 4.64 GB bbc3c6d1 download
model-00034-of-00048.safetensors 4.64 GB 8e8aa917 download
model-00035-of-00048.safetensors 4.64 GB 88ba8c1e download
model-00036-of-00048.safetensors 4.64 GB 9ed9e783 download
model-00038-of-00048.safetensors 4.64 GB b240d49e download
model-00039-of-00048.safetensors 4.64 GB d49b7d12 download
model-00040-of-00048.safetensors 4.64 GB 10f16ac1 download
model-00042-of-00048.safetensors 4.64 GB dda47a76 download
model-00043-of-00048.safetensors 4.64 GB f570b50e download
model-00044-of-00048.safetensors 4.64 GB cf6f4a63 download
model-00046-of-00048.safetensors 4.64 GB 4bdac38a download
model-00047-of-00048.safetensors 4.64 GB 0d4c2b97 download
model-00010-of-00048.safetensors 4.64 GB 8ec70634 download
model-00002-of-00048.safetensors 4.64 GB bfc0b077 download
model-00003-of-00048.safetensors 4.64 GB 59c53827 download
model-00004-of-00048.safetensors 4.64 GB 1b346435 download
model-00006-of-00048.safetensors 4.64 GB 53b5fa9b download
model-00007-of-00048.safetensors 4.64 GB 645172a0 download
model-00008-of-00048.safetensors 4.64 GB c4b61722 download
model-00013-of-00048.safetensors 4.60 GB eb3ad471 download
model-00017-of-00048.safetensors 4.60 GB 1672bcc3 download
model-00021-of-00048.safetensors 4.60 GB 9d7243e8 download
model-00025-of-00048.safetensors 4.60 GB 56ad38c1 download
model-00029-of-00048.safetensors 4.60 GB ddbeacea download
model-00033-of-00048.safetensors 4.60 GB 5941a032 download
model-00037-of-00048.safetensors 4.60 GB c9b56678 download
model-00041-of-00048.safetensors 4.60 GB 6ab87cc2 download
model-00045-of-00048.safetensors 4.60 GB a888a132 download
model-00005-of-00048.safetensors 4.60 GB ab6f063b download
model-00009-of-00048.safetensors 4.60 GB 522cd469 download
model-00001-of-00048.safetensors 4.44 GB ebffb1cd download
model-00048-of-00048.safetensors 1.64 GB 0708442b download
tokenizer.json 6.95 MB 6e183162 download
model.safetensors.index.json 3.18 MB 2cbf23b2 download
banner.png 1.74 MB 86b5220a download
modeling_laguna.py 40.0 KB 9bcc79b4 download
configuration_laguna.py 12.8 KB f10d7285 download
README.md 9.26 KB 626424cf download
config.json 4.91 KB 7b02401e download
evaluation_report.json 4.44 KB 8dd38096 download
chat_template.jinja 3.87 KB acf45eb4 download
LICENSE.md 2.56 KB db7c88d0 download
.gitattributes 1.53 KB b0baf14c download
generation_config.json 515 B 560fd3d1 download
tokenizer_config.json 430 B 3ae87f72 download

README current version from Hugging Face


license: openmdw-1.1
base_model: poolside/Laguna-S-2.1
base_model_relation: finetune
library_name: transformers
pipeline_tag: text-generation
language:

  • en
  • de
    tags:
  • laguna
  • moe
  • uncensored
  • bilingual
  • code

Laguna-S-2.1-Uncensored

Laguna-S-2.1-Uncensored

TL;DR: an uncensored build of poolside's Laguna S 2.1 (118B Mixture-of-Experts, ~8B active
per token, 1M context) that stays a working coding model. English refusals drop from 92.71% to
2.33% and German from 74.49% to 4.23% across 686 harmful prompts per language, at a measured cost
of 4.88 points on HumanEval.

Laguna S 2.1 is built for agentic coding and long-horizon work, which makes it unusually useful
for security engineering: exploit and malware analysis, writing detection rules, building tooling
for red-team and penetration-testing work. The stock model refuses a large share of exactly those
requests. This build removes that broad refusal behavior in both English and German while keeping
the architecture, tokenizer, chat template, reasoning behavior and tool-calling format of the base
model unchanged.

This is a research build. "Uncensored" describes the removal of learned refusal behavior. It is
not a guarantee of factuality, capability, or predictable behavior.

Facts and figures

Base model poolside/Laguna-S-2.1 (revision 00af5a51)
Architecture Laguna MoE, 48 layers, 256 routed experts (top-10) plus 1 shared expert
Parameters 118B total, ~8B activated per token
Context length 1,048,576 tokens
Precision BF16 safetensors, 48 shards
Checkpoint size 235.14 GB
Languages targeted English and German
Hardware 2x NVIDIA H200, Hugging Face Jobs
Wall clock 2 h 39 min, single job, including export and upload
Toolchain torch 2.13.0 · transformers 5.14.1 · accelerate 1.14.0 · safetensors 0.8.0
Serving throughput not benchmarked
Quantized builds planned, not yet released

Results

All numbers below were measured on this checkpoint against the unmodified base model. Refusal
rates come from the pinned NousResearch/Minos-v1
classifier. German responses are judged by the same classifier on deterministic NLLB-200
back-translations, paired with the original English prompts.

Metric Base Uncensored
English refusals, 686 prompts 92.71% (636) 2.33% (16)
of which confident refusals 630 2
German refusals, 686 translated prompts 74.49% (511) 4.23% (29)
of which confident refusals 496 9
XSTest over-refusal, 214 benign prompts 8.88% 1.87%
HumanEval pass@1, 164 problems 90.24% 85.37%
Benign teacher-forced NLL 1.5047 1.4045

Derived from the table: 80.32 points of absolute bilingual refusal reduction, 96.08% relative.
Over-refusal on benign prompts drops as well, so the model is less likely to bail out on harmless
requests that merely look sensitive.

The pipeline also runs two single-prompt sanity checks, one arithmetic question and one tool call,
to catch a build that has lost the reasoning or tool-calling format entirely. This build passes
both. They are tripwires, not benchmarks, and no capability claim rests on them.

Two numbers deserve context rather than spin:

  • Benign first-token KL divergence is 2.53. That is high in isolation. On the same benign set
    the teacher-forced NLL is slightly lower than base (1.4045 vs 1.5047), and the task numbers
    hold up, so the distribution shift does not translate into a collapse in output quality. Judge it
    alongside the task numbers, not on its own.
  • HumanEval drops 4.88 points. On a model whose reason for existing is code, that is a real
    cost and it is stated here rather than buried. Worth knowing how noisy that measurement is: five
    runs of this configuration family scored 145, 144, 140, 137 and 140 out of 164, and two of those
    came from an identical configuration. pass@1 on 164 problems carries roughly 2.5 points of
    binomial jitter, so the honest capability cost is about 4 points, and 4.88 is one draw from that
    distribution. If you need maximum coding accuracy and do not need the refusal behavior removed,
    use the base model.

Every release gate defined for this build passed, including separate ceilings on confident and
borderline refusals per language, the 5-point HumanEval ceiling (set after measuring the noise floor
of the eval itself, see the HumanEval note above), the benign-NLL delta bound, the over-refusal
bound, and bit-identity of all tensors outside the modified set. Aggregate results are in
evaluation_report.json in this repository.

Evaluation datasets, pinned by revision: JailbreakBench/JBB-Behaviors, allenai/tulu-3-harmbench-eval,
NousResearch/RefusalDataset, mlabonne/harmful_behaviors, jkminder/xstest-overrefusal,
openai/openai_humaneval. Only aggregate results are published. Evaluation prompts and generated
responses are not bundled.

What was changed

Broad refusal behavior was suppressed through a targeted weight-level modification, applied
bilingually so that German is covered as thoroughly as English rather than leaking refusals
through the second language.

Unchanged: architecture, tokenizer, chat template, embeddings, LM head, normalization weights,
reasoning format and tool-calling format. Every tensor outside the modified set is bit-identical to
the base checkpoint, and that property is checked by a release gate rather than asserted.

The exact procedure and its parameters are not published.

Run it

The BF16 checkpoint is 235 GB, so serving needs multiple GPUs for the weights alone before any KV
cache. Quantized builds of this derivative are planned.

Loading with transformers:

from transformers import AutoModelForCausalLM, AutoTokenizer

model_id = "ressl/Laguna-S-2.1-Uncensored"
tokenizer = AutoTokenizer.from_pretrained(model_id, trust_remote_code=True)
model = AutoModelForCausalLM.from_pretrained(
    model_id,
    trust_remote_code=True,
    dtype="auto",
    device_map="auto",
)

This build is drop-in compatible with the base model's documented engine integrations, since the
architecture, chat template and parsers are unchanged. The commands below mirror poolside's
documented usage with the repository id swapped. They have not been validated on this
derivative, so treat them as a starting point:

# vLLM (untested on this build)
vllm serve \
    --model ressl/Laguna-S-2.1-Uncensored \
    --tensor-parallel-size 4 \
    --tool-call-parser poolside_v1 \
    --reasoning-parser poolside_v1 \
    --enable-auto-tool-choice \
    --served-model-name laguna \
    --default-chat-template-kwargs '{"enable_thinking": true}'
# SGLang (untested on this build)
python -m sglang.launch_server \
  --model-path ressl/Laguna-S-2.1-Uncensored \
  --tp-size 4 \
  --reasoning-parser poolside_v1 \
  --tool-call-parser poolside_v1 \
  --trust-remote-code

Reasoning behaves as in the base model: keep reasoning_content from prior assistant messages in
the history (preserved thinking), and control it per request with
chat_template_kwargs={"enable_thinking": false}.

Quality and limitations

  • The whole build, modification plus the full bilingual evaluation, ran as one 2 h 39 min job on
    2x NVIDIA H200 on Hugging Face Jobs. Serving throughput was not benchmarked, and there are no
    tok/s claims on this card.
  • The vLLM and SGLang commands above are inherited from the base model card and untested here.
  • Coding accuracy is measurably below base (HumanEval 85.37% vs 90.24%).
  • Refusal removal is not absolute: 16 of 686 English and 29 of 686 German responses still read as
    refusals to the classifier, most of them borderline rather than confident.
  • Only English and German were targeted. Behavior in other languages was not measured.
  • The model will comply with requests the stock model refuses. Use it responsibly, and put your
    own controls around it where your use case needs them. poolside advises against circumventing
    Laguna's safety guardrails without substantially equivalent mitigations appropriate for the use
    case, which is worth taking seriously: this build is intended for security research,
    red-teaming, and penetration-testing work by people who understand what they are doing.

License and credits

OpenMDW-1.1, inherited from the base model. Laguna S 2.1 was built and released by
poolside, all credit for the underlying model belongs to them
(model ·
release post). Use of this derivative remains
subject to the OpenMDW-1.1 license and poolside's
Acceptable Use Policy.

Modification, evaluation and release by Robert Ressl
(Hugging Face · Website ·
LinkedIn · Patreon).

❤️ Support this work: this build took a full evaluation harness across two languages and a lot
of compute. If it is useful to you, consider supporting on
Patreon, more at ressl.ch.


Version 1.0, released 2 August 2026. Evaluated 30 July 2026 against base revision 00af5a51.

README history 1 version

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-02Laguna-S-2.1-Uncensored v1.0b7eeae49.3 KB
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration