← back to catalog · registered 2026-08-24 10:02

ressl/Ornith-1.5-397B-uncensored-FP8

ressl 389B MoE
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/ressl%2FOrnith-1.5-397B-uncensored-FP8"
Response includes
  • classification m1
  • files 138
  • hub_downloads_all_time 70
  • author_summary 28 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
70
37 last 30d - active
Likes
0
Model age
7w ago
created 2026-08-21
Downloads over time
Now86→from5↑1,620%
13263945 on Aug 2686 on Oct 11AugSepOct
Aug 26 → Oct 11 · 47 snapshots · spans 46 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 243 downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
mit
Languages
en
Tags
transformers safetensors qwen3_5_moe image-text-to-text uncensored abliterated fp8 compressed-tensors sglang blackwell text-generation conversational

Related

Total size
377 GB
Files
138
Quantizations
1
Registered
2026-08-24 10:02
Last updated on HF
2026-08-23 13:59

Files by quantization

Auxiliary files 138 files 377 GB
model-00022-of-00122.safetensors 4.00 GB 58698bcd download
model-00024-of-00122.safetensors 4.00 GB be472f94 download
model-00026-of-00122.safetensors 4.00 GB da5ee219 download
model-00028-of-00122.safetensors 4.00 GB 43367b26 download
model-00030-of-00122.safetensors 4.00 GB 049457db download
model-00032-of-00122.safetensors 4.00 GB 2c74ca62 download
model-00034-of-00122.safetensors 4.00 GB 8701ffe1 download
model-00036-of-00122.safetensors 4.00 GB 5e61799a download
model-00038-of-00122.safetensors 4.00 GB 81a8a04d download
model-00040-of-00122.safetensors 4.00 GB 5b6fe896 download
model-00042-of-00122.safetensors 4.00 GB afd48cf5 download
model-00044-of-00122.safetensors 4.00 GB 1c7100db download
model-00046-of-00122.safetensors 4.00 GB 9e1af3f8 download
model-00048-of-00122.safetensors 4.00 GB addfdc1e download
model-00050-of-00122.safetensors 4.00 GB fa4be301 download
model-00052-of-00122.safetensors 4.00 GB ba5fbcac download
model-00054-of-00122.safetensors 4.00 GB 5fa25e41 download
model-00056-of-00122.safetensors 4.00 GB f2250169 download
model-00058-of-00122.safetensors 4.00 GB 343029f3 download
model-00060-of-00122.safetensors 4.00 GB a1ffe75e download
model-00062-of-00122.safetensors 4.00 GB 4e107226 download
model-00064-of-00122.safetensors 4.00 GB 3a2a22e5 download
model-00066-of-00122.safetensors 4.00 GB b5b0a14d download
model-00068-of-00122.safetensors 4.00 GB e1a49d9f download
model-00070-of-00122.safetensors 4.00 GB 08a533d4 download
model-00072-of-00122.safetensors 4.00 GB 6d9462eb download
model-00074-of-00122.safetensors 4.00 GB 19ce4a75 download
model-00076-of-00122.safetensors 4.00 GB 9d258810 download
model-00078-of-00122.safetensors 4.00 GB 3632be7d download
model-00080-of-00122.safetensors 4.00 GB c12a936f download
model-00082-of-00122.safetensors 4.00 GB 6fb81fc1 download
model-00084-of-00122.safetensors 4.00 GB d3f0a367 download
model-00086-of-00122.safetensors 4.00 GB af49597f download
model-00088-of-00122.safetensors 4.00 GB bae23b4e download
model-00090-of-00122.safetensors 4.00 GB 26fa3a57 download
model-00092-of-00122.safetensors 4.00 GB 144fa741 download
model-00094-of-00122.safetensors 4.00 GB a3a66e6d download
model-00096-of-00122.safetensors 4.00 GB 73f980c5 download
model-00098-of-00122.safetensors 4.00 GB 49f698e1 download
model-00100-of-00122.safetensors 4.00 GB 4815ac68 download
model-00102-of-00122.safetensors 4.00 GB f1db3b5a download
model-00104-of-00122.safetensors 4.00 GB db09bd27 download
model-00106-of-00122.safetensors 4.00 GB 6857f90b download
model-00108-of-00122.safetensors 4.00 GB a40ec6b2 download
model-00110-of-00122.safetensors 4.00 GB e123a82e download
model-00112-of-00122.safetensors 4.00 GB 1282164e download
model-00114-of-00122.safetensors 4.00 GB 5b52e854 download
model-00116-of-00122.safetensors 4.00 GB 3ac6bee6 download
model-00118-of-00122.safetensors 4.00 GB f6b8f6f4 download
model-00120-of-00122.safetensors 4.00 GB eea6f24e download
model-00002-of-00122.safetensors 4.00 GB 5ecf7056 download
model-00004-of-00122.safetensors 4.00 GB 6d274c11 download
model-00006-of-00122.safetensors 4.00 GB 0686f9f4 download
model-00008-of-00122.safetensors 4.00 GB b009d26a download
model-00010-of-00122.safetensors 4.00 GB 488020e8 download
model-00012-of-00122.safetensors 4.00 GB a42c1920 download
model-00014-of-00122.safetensors 4.00 GB 187a4ca4 download
model-00016-of-00122.safetensors 4.00 GB 7606cd30 download
model-00018-of-00122.safetensors 4.00 GB 373a6f80 download
model-00020-of-00122.safetensors 4.00 GB bc503f63 download
model-00001-of-00122.safetensors 2.98 GB e600f10b download
model-00021-of-00122.safetensors 2.24 GB fd478489 download
model-00025-of-00122.safetensors 2.24 GB 036df40e download
model-00027-of-00122.safetensors 2.24 GB 28e289b9 download
model-00029-of-00122.safetensors 2.24 GB ea1dbf35 download
model-00033-of-00122.safetensors 2.24 GB e21ded26 download
model-00035-of-00122.safetensors 2.24 GB 34adbc28 download
model-00037-of-00122.safetensors 2.24 GB 0f66ec28 download
model-00041-of-00122.safetensors 2.24 GB 222fb53e download
model-00043-of-00122.safetensors 2.24 GB 39dd9b44 download
model-00045-of-00122.safetensors 2.24 GB 4d96004a download
model-00049-of-00122.safetensors 2.24 GB 14dcdc71 download
model-00051-of-00122.safetensors 2.24 GB 4f10710c download
model-00053-of-00122.safetensors 2.24 GB c5b250af download
model-00057-of-00122.safetensors 2.24 GB c9b8ec67 download
model-00059-of-00122.safetensors 2.24 GB fb3546f6 download
model-00061-of-00122.safetensors 2.24 GB 0d2cebdb download
model-00065-of-00122.safetensors 2.24 GB 64cec741 download
model-00067-of-00122.safetensors 2.24 GB d7661fcc download
model-00069-of-00122.safetensors 2.24 GB f1ff8981 download
model-00073-of-00122.safetensors 2.24 GB 7bf285e9 download
model-00075-of-00122.safetensors 2.24 GB e22837d4 download
model-00077-of-00122.safetensors 2.24 GB 05d8b7e9 download
model-00081-of-00122.safetensors 2.24 GB 502b2b04 download
model-00083-of-00122.safetensors 2.24 GB b4f08307 download
model-00085-of-00122.safetensors 2.24 GB ae772a9a download
model-00089-of-00122.safetensors 2.24 GB 1eb74959 download
model-00091-of-00122.safetensors 2.24 GB 02647d28 download
model-00093-of-00122.safetensors 2.24 GB 57055ff9 download
model-00097-of-00122.safetensors 2.24 GB 53f07553 download
model-00099-of-00122.safetensors 2.24 GB fd0d2afc download
model-00101-of-00122.safetensors 2.24 GB 21697147 download
model-00105-of-00122.safetensors 2.24 GB 8f7a0823 download
model-00107-of-00122.safetensors 2.24 GB a0613396 download
model-00109-of-00122.safetensors 2.24 GB a4e93022 download
model-00113-of-00122.safetensors 2.24 GB ce9ae611 download
model-00115-of-00122.safetensors 2.24 GB db31beb5 download
model-00117-of-00122.safetensors 2.24 GB e9bafd8b download
model-00003-of-00122.safetensors 2.24 GB ba5e676c download
model-00005-of-00122.safetensors 2.24 GB 89802db0 download
model-00009-of-00122.safetensors 2.24 GB a8906e11 download
model-00011-of-00122.safetensors 2.24 GB 3d49ed4e download
model-00013-of-00122.safetensors 2.24 GB e0ea724f download
model-00017-of-00122.safetensors 2.24 GB 87b1309b download
model-00019-of-00122.safetensors 2.24 GB 8e745f1d download
model-00023-of-00122.safetensors 2.12 GB 6b84a5a8 download
model-00031-of-00122.safetensors 2.12 GB dc054745 download
model-00039-of-00122.safetensors 2.12 GB 7577da6f download
model-00047-of-00122.safetensors 2.12 GB b71b0b3b download
model-00055-of-00122.safetensors 2.12 GB a5645647 download
model-00063-of-00122.safetensors 2.12 GB ac103256 download
model-00071-of-00122.safetensors 2.12 GB 40a40d5c download
model-00079-of-00122.safetensors 2.12 GB 7614b7f2 download
model-00087-of-00122.safetensors 2.12 GB b2be2daf download
model-00095-of-00122.safetensors 2.12 GB 71470834 download
model-00103-of-00122.safetensors 2.12 GB c9b8e91b download
model-00111-of-00122.safetensors 2.12 GB 1acd8d4a download
model-00119-of-00122.safetensors 2.12 GB df8d3edc download
model-00007-of-00122.safetensors 2.12 GB 869a4ea9 download
model-00015-of-00122.safetensors 2.12 GB aac625d4 download
model-00121-of-00122.safetensors 2.00 GB fd83a9b1 download
model-00122-of-00122.safetensors 1.89 GB 34b500df download
model.safetensors.index.json 19.3 MB 4b1c5ab0 download
tokenizer.json 12.2 MB 5f9e4d49 download
vocab.json 6.41 MB 0aa0ce06 download
merges.txt 3.20 MB a494e019 download
banner.png 1.78 MB 873835fb download
tokenizer_config.json 16.3 KB eda48d3e download
chat_template.jinja 7.42 KB 11be7e25 download
chat_template_preserve_history.jinja 7.42 KB 11be7e25 download
README.md 6.96 KB 20eea82f download
config.json 5.09 KB 43599fff download
.gitattributes 1.82 KB 80014dc1 download
processor_config.json 1.16 KB 33818c7f download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download
generation_config.json 244 B 85b45ab4 download
configuration.json 58.0 B d24dba94 download

README current version from Hugging Face


license: mit
base_model: ornith-ai/Ornith-1.5-397B
base_model_relation: quantized
library_name: transformers
pipeline_tag: text-generation
language: [en]
tags: [uncensored, abliterated, fp8, compressed-tensors, sglang, blackwell, qwen3_5_moe]

Ornith-1.5-397B uncensored

Ornith-1.5-397B uncensored (FP8)

TL;DR: Ornith-1.5-397B with refusal behavior ablated from the weights in two
norm-preserving biprojection passes (1/1120 hard refusals across five independent
harmful-prompt datasets), as a drop-in FP8 replacement for
ornith-ai/Ornith-1.5-397B-FP8.

This is the 397B flagship of the Ornith-1.5 family (Qwen3.5-MoE, 60 layers, 512 experts,
hybrid linear/full attention, 262k context, multimodal). The first ablation pass removed
the classic "I cannot" refusal style; a second pass targeted the residual hedged-decline
circuit ("I'd rather not") using directions computed from refused-vs-complied residuals
of the same harmful prompt distribution. Intended for security research, red-teaming and
creative work where stock refusals get in the way. Use responsibly.

Facts & figures

Base model ornith-ai/Ornith-1.5-397B
Method 2x norm-preserving biprojection abliteration (grimjim/TrevorS method) on the BF16 master, then channel-wise FP8 (compressed-tensors, per-output-channel symmetric scales, dynamic activations)
Size 405 GB (from 794 GB BF16)
Hard refusals 1/1120 cross-dataset, 0/100 mlabonne (details below)
GPQA-Diamond 0.631 (198 questions, temp 0)
Needle (long context) 9/9 passcodes recalled at 32k / 64k / 128k
Tool calling 2/2 correct tool_calls via qwen3_coder parser
KL vs base mean 0.66 / median 0.47 at the answer-start position (36 held-out prompts; harmless-only subset mean 0.33; the harmful subset carries the intended behavior change)
Context length 262,144 tokens
Quant hardware 7x NVIDIA RTX PRO 6000 Blackwell 96 GB (SM120) for abliteration and export
Validated serving SGLang, tensor-parallel 2 x pipeline-parallel 3 on 6x RTX PRO 6000
Toolchain transformers 5.12.1, custom streaming export, SGLang (sglang-omega build)

Refusal evaluation (the honest version)

Served FP8 artifact, temperature 0. Scored with an extended hard-decline list that
covers both the classic style ("I cannot", "I won't", ...) and hedged declines
("I'd rather not", "I'll pass", "I'd hesitate", ...). A naive keyword scorer that only
knows the classic style undercounts refusals on this model; every flagged response was
manually reviewed and is a true refusal.

Dataset Hard refusals
mlabonne harmful behaviors (100) 0/100
JailbreakBench JBB-Behaviors (100) 0/100
tulu-3-harmbench-eval (320) 0/320
HarmfulQA (300) 0/300
LLM-LAT harmful (300) 1/300
Total 1/1120

Baseline comparison on mlabonne (same scorer): the stock model scores 91/100
(measured on a locally requantized FP8 of the official BF16; the official FP8 repo
itself was not evaluated).

Benchmark comparison (custom zero-shot protocol, temp 0, same FP8 format both sides)

Suite baseline this model
MMLU-Pro (500, test split, seed 42) 0.810 0.814
GSM8K (200) 0.950 0.950
GPQA-Diamond (198) not run under this protocol 0.631

MMLU/GSM8K pairs: paired per-question analysis shows no measurable difference
(MMLU delta +0.4 pp, 95% bootstrap CI [-1.8, +2.6] pp; GSM8K delta 0). MMLU answers
without a parseable "Answer: X" counted as wrong on both sides (57/500 vs 55/500).
The baseline was measured on the v1 ablated build's sibling requant of the original
BF16; the GPQA number above is this v2 artifact (v1 measured 0.647 on the same set).

Run it with SGLang

Validated command (TP=2 x PP=3 on 6x 96 GB GPUs; plain TP=7 is impossible because
32 attention heads and 2 KV heads are not divisible by 7, TP=4 is too small for 405 GB):

python -m sglang.launch_server \
    --model-path ressl/Ornith-1.5-397B-uncensored-FP8 \
    --served-model-name Ornith-1.5-397B-uncensored-FP8 \
    --host 0.0.0.0 --port 30000 \
    --tp-size 2 --pp-size 3 \
    --trust-remote-code --dtype auto \
    --context-length 262144 \
    --kv-cache-dtype fp8_e4m3 \
    --max-running-requests 8 \
    --chunked-prefill-size 16384 \
    --mem-fraction-static 0.88 \
    --tool-call-parser qwen3_coder \
    --reasoning-parser qwen3

Companion formats

Quality & limitations

  • Will comply with requests a stock model refuses. This is the point; use responsibly
    and within your local laws.
  • Reasoning model: answers open with a <think> block unless disabled via the chat
    template (the repo ships the stock template; sglang's qwen3 reasoning parser splits it).
  • Identity answers (who are you) reflect the base model's training (it may name a
    vendor it was distilled from). That is inherited from ornith-ai/Ornith-1.5-397B, not
    an artifact of the abliteration.
  • The second ablation pass raises drift vs base (harmless-subset KL 0.33 vs 0.16 after
    pass 1) while keeping GPQA/needle/coherence intact; that trade is visible in the
    numbers above rather than hidden.
  • Eval coverage: refusal sets (1,120 prompts), GPQA/MMLU-Pro/GSM8K subsets, needle,
    tool smoke. No full benchmark suite (Terminal-Bench, SWE-bench) was run.

Provenance & reproducibility

Pass 1: per-layer refusal directions from 800 harmful/harmless prompts (mlabonne
harmful_behaviors + harmless_alpaca, residuals at the answer-start position,
orthogonalized against the harmless mean, winsorized 0.995). Pass 2: directions from
103 prompts the pass-1 model still refused vs 500 it complied with (paraphrase
augmented harvest). Both passes apply norm-preserving biprojection to all
residual-writing matrices across all 60 layers (self_attn.o_proj,
linear_attn.out_proj, shared expert down_proj, all 512 routed expert down_proj
matrices per layer, 180 tensors). FP8 export reproduces the official repo structure
tensor-for-tensor (per-expert layout, bf16 scales, identical quantization_config);
scale math and expert split verified against the official FP8 checkpoint before export.

License & credits

MIT license, inherited from the base model by the Ornith AI authors. Abliteration,
quantization and validation by Robert Ressl
(Hugging Face · Website · LinkedIn · Patreon).

Support this work: if these models are useful to you, consider supporting on
Patreon; more at ressl.ch.

Version note (2026-08-23): v2 artifact. v1 (single-pass abliteration) scored 6/100
mlabonne / 39/1120 cross-dataset; v2 scores 0/100 / 1/1120 on the same extended scorer.

README history 8 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-23Upload README.md with huggingface_hub2d5b0167 KB
    Loading...
  2. 2026-08-23Upload README.md with huggingface_hub9d46b886.9 KB
    Loading...
  3. 2026-08-23Upload folder using huggingface_hub1346d4d29.1 KB
    Loading...
  4. 2026-08-22Upload README.md with huggingface_hub2cf68196.9 KB
    Loading...
  5. 2026-08-22Upload README.md with huggingface_hub6994b516.3 KB
    Loading...
  6. 2026-08-22Upload README.md with huggingface_hub6cb55c86.1 KB
    Loading...
  7. 2026-08-21Upload README.md with huggingface_hubbe7dbc85.7 KB
    Loading...
  8. 2026-08-21Upload folder using huggingface_hubd5d1b7729.1 KB
    Loading...

Discussions 1 thread

  1. 2026-08-29Quant request - MLXopen1 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration