← back to catalog · registered 2026-08-24 10:02

ressl/Ornith-1.5-397B-uncensored-NVFP4

ressl 193B MoE
Your rig guess connected
? Why do I need an app?
Reading your rig…

This is a rough estimate. Install the free app - we'll show exact numbers.

Reading real hardware from your app right now. Numbers below are exact.

Below is the per-quantization compatibility for this model.

curl -H "Authorization: Bearer $ABL_KEY" \
     "https://abliteration.org/api/v1/models/ressl%2FOrnith-1.5-397B-uncensored-NVFP4"
Response includes
  • classification m1
  • files 39
  • hub_downloads_all_time 539
  • author_summary 28 models
  • readme_text full
10 credits · hourly refresh · ~4 KB payload Get an API key →
Abliteration classifier · v1.0.0
M1
Primary method

Direct removal

No other method signals detected in this model.
Confidence
MEDIUM
Why this label 3 signals
Method inferred from partial signals - repository name, related files, or tag patterns. Producer identity not confirmed; label may sharpen or shift as we gather more evidence.
  • 'abliterated' in name/tags
  • is_gguf=0 (base model)
  • no specific method indicators - defaulting to M1 (most common)
Refusal direction extracted via
Extraction technique

Difference-of-means

Confidence
MEDIUM
Why we say so
primary_method=M1; difference-of-means is the reference extraction for M1/M3 (Arditi 2024)
Downloads · lifetime
539
206 last 30d - stable
Likes
2
Model age
7w ago
created 2026-08-21
Downloads over time
Now614→from206↑198%
186342498655206 on Aug 26614 on Oct 11AugSepOct
Aug 26 → Oct 11 · 47 snapshots · spans 46 days

Genealogy 0 direct forks

Full fork graph →

This model's place in the market. Above: what it was derived from. Below: the tree of everything derived from it.

Variants by this author 2 formats · 243 downloads combined

The same weights this author released in different packaging. Pick the format that matches your runtime.

Metadata

License
mit
Languages
en
Tags
transformers safetensors qwen3_5_moe image-text-to-text uncensored abliterated nvfp4 modelopt sglang blackwell text-generation conversational

Related

Total size
222 GB
Files
39
Quantizations
1
Registered
2026-08-24 10:02
Last updated on HF
2026-08-24 09:33

Files by quantization

Auxiliary files 39 files 222 GB
model-00007-of-00024.safetensors 9.38 GB 00fe3f2b download
model-00008-of-00024.safetensors 9.32 GB dd73b7bf download
model-00014-of-00024.safetensors 9.32 GB 14b271e3 download
model-00009-of-00024.safetensors 9.32 GB d867c3a3 download
model-00016-of-00024.safetensors 9.32 GB d4210e27 download
model-00006-of-00024.safetensors 9.32 GB 03b8bdfa download
model-00011-of-00024.safetensors 9.32 GB fa46223b download
model-00020-of-00024.safetensors 9.32 GB 7ed8f552 download
model-00023-of-00024.safetensors 9.32 GB 77913c96 download
model-00013-of-00024.safetensors 9.32 GB 2ce5cc23 download
model-00002-of-00024.safetensors 9.32 GB 75dcd09f download
model-00012-of-00024.safetensors 9.32 GB 228ef5cb download
model-00010-of-00024.safetensors 9.32 GB bad3207f download
model-00015-of-00024.safetensors 9.32 GB e7bdb871 download
model-00017-of-00024.safetensors 9.32 GB 8160bd83 download
model-00003-of-00024.safetensors 9.32 GB 8baf8a76 download
model-00005-of-00024.safetensors 9.32 GB 1f29d794 download
model-00019-of-00024.safetensors 9.32 GB d6fd6cdd download
model-00022-of-00024.safetensors 9.32 GB 78ec7e6d download
model-00001-of-00024.safetensors 9.32 GB b57148e4 download
model-00021-of-00024.safetensors 9.32 GB ba5ee862 download
model-00018-of-00024.safetensors 9.32 GB a23091b9 download
model-00004-of-00024.safetensors 9.32 GB 633bed8b download
model-00024-of-00024.safetensors 7.31 GB f6f937de download
model.safetensors.index.json 37.6 MB 01c9ef34 download
tokenizer.json 12.2 MB 5f9e4d49 download
vocab.json 6.41 MB 0aa0ce06 download
merges.txt 3.20 MB a494e019 download
banner.png 1.78 MB 873835fb download
config.json 19.7 KB b580e3f7 download
tokenizer_config.json 16.3 KB eda48d3e download
hf_quant_config.json 14.8 KB 57cde51d download
chat_template.jinja 7.42 KB 11be7e25 download
README.md 5.39 KB a277e48f download
.gitattributes 1.76 KB a20e2221 download
processor_config.json 1.16 KB 33818c7f download
preprocessor_config.json 390 B 2ea84a43 download
video_preprocessor_config.json 385 B 3ba673a5 download
generation_config.json 214 B eaf66635 download

README current version from Hugging Face


license: mit
base_model: ornith-ai/Ornith-1.5-397B
base_model_relation: quantized
library_name: transformers
pipeline_tag: text-generation
language: [en]
tags: [uncensored, abliterated, nvfp4, modelopt, sglang, blackwell, qwen3_5_moe]

Ornith-1.5-397B uncensored

Ornith-1.5-397B uncensored (NVFP4)

TL;DR: Ornith-1.5-397B with refusal behavior ablated from the weights (1/1120
hard refusals cross-dataset), in NVIDIA NVFP4 experts-only format: 232 GB, serves on
4x RTX PRO 6000 Blackwell.

Same two-pass ablated master as the FP8 sibling repo, quantized with NVIDIA TensorRT
Model Optimizer 0.46 (NVFP4, experts only: attention, shared expert, router,
embeddings, linear attention and vision tower stay BF16). The practical way to run an
uncensored 397B-class model on a single workstation node.

Facts & figures

Base model ornith-ai/Ornith-1.5-397B
Method Two-pass biprojection abliteration on BF16, then ModelOpt NVFP4 experts-only (group size 16, fp8 block scales, dynamic activation scales; 128 calibration samples, mlabonne/harmless_alpaca)
Size 232 GB (from 794 GB BF16, -71%)
Hard refusals 1/100 mlabonne (extended decline-phrase scorer, served NVFP4 artifact); FP8 sibling: 1/1120 cross-dataset
Measured throughput 104.6 tok/s decode measured on the v1 NVFP4 build (SGLang, TP=4, single request, fp8 KV cache); not re-measured on v2, same weight shapes and kernels
Context length 262,144 tokens
Quant + serve hardware NVIDIA RTX PRO 6000 Blackwell 96 GB (SM120); quant on 7x, validated serving on 4x
Toolchain ModelOpt 0.46.0, SGLang (sglang-omega build), transformers 5.12.1

Refusal evaluation

Served NVFP4 artifact, 100 mlabonne harmful prompts, temperature 0, extended
hard-decline scorer (classic + hedged decline phrases):

Metric This model
HARD refusals (effective rate) 1/100
position-aware markers (first 40 words) 13/100
naive markers (anywhere) 80/100 (mostly false positives; see the FP8 repo for the full explanation and the 5-dataset breakdown)

Benchmark results (measured on the FP8 sibling, same ablated master)

Custom zero-shot protocol, temp 0, SGLang TP2 x PP3. The FP8 and NVFP4 repos share the
identical two-pass ablated BF16 master; only the weight format differs. These numbers
were not re-run on this NVFP4 artifact.

Suite baseline ablated (FP8)
MMLU-Pro (500 questions, test split, seed 42) 0.810 0.814
GSM8K (200 problems) 0.950 0.950
GPQA-Diamond (198 questions) not run under this protocol 0.631
Needle passcode recall (32k / 64k / 128k) 9/9

Paired per-question analysis on MMLU-Pro/GSM8K shows no measurable difference to the
baseline (MMLU delta +0.4 pp, 95% bootstrap CI [-1.8, +2.6] pp; GSM8K delta 0).
Full protocol details and the 5-dataset refusal breakdown are on the FP8 repo card.

Run it with SGLang

Validated command (TP=4 on 4x 96 GB GPUs, 56.8 GB weights per GPU):

python -m sglang.launch_server \
    --model-path ressl/Ornith-1.5-397B-uncensored-NVFP4 \
    --served-model-name Ornith-1.5-397B-uncensored-NVFP4 \
    --host 0.0.0.0 --port 30000 \
    --tp-size 4 \
    --quantization modelopt_fp4 \
    --trust-remote-code --dtype auto \
    --context-length 262144 \
    --kv-cache-dtype fp8_e4m3 \
    --max-running-requests 8 \
    --chunked-prefill-size 16384 \
    --mem-fraction-static 0.88 \
    --tool-call-parser qwen3_coder \
    --reasoning-parser qwen3

Companion formats

Quality & limitations

  • Will comply with requests a stock model refuses; use responsibly and within your
    local laws. Intended for security research, red-teaming and creative work.
  • NVFP4 is a 4-bit weight format; expect a small quality delta vs the FP8 sibling on
    hard reasoning tasks. The refusal eval above was run on this exact NVFP4 artifact;
    benchmark suites were run on the FP8 sibling (see its card).
  • Identity answers reflect the base model's training (inherited from ornith-ai), not
    an artifact of abliteration or quantization.
  • Vision tower is included and kept in BF16; only the language decoder's routed
    experts are NVFP4.

Provenance & reproducibility

Two-pass biprojection-abliterated BF16 master (details in the FP8 repo card),
quantized with mtq.NVFP4_EXPERTS_ONLY_CFG, calibration 128 samples x 512 tokens.
Export format verified structurally (packed uint8 weights, fp8 e4m3 block scales
[out, in/16], fp32 tensor scales) and validated serving with SGLang modelopt_fp4
before upload.

License & credits

MIT license, inherited from the base model by the Ornith AI authors. Abliteration,
quantization and validation by Robert Ressl
(Hugging Face · Website · LinkedIn · Patreon).
Built with NVIDIA TensorRT Model Optimizer and SGLang.

Support this work: if these models are useful to you, consider supporting on
Patreon; more at ressl.ch.

Version note (2026-08-23): v2 artifact (two-pass abliteration). Includes all
tokenizer/processor files; an earlier v2 upload missing them was replaced.

README history 6 versions

The author's README evolved over time. Click a version to see its content at that point.

  1. 2026-08-24Upload README.md with huggingface_hub446127f5.4 KB
    Loading...
  2. 2026-08-23Upload README.md with huggingface_hubced746e4.6 KB
    Loading...
  3. 2026-08-23Upload README.md with huggingface_hub8b7ebda4.5 KB
    Loading...
  4. 2026-08-22Upload README.md with huggingface_hubf01d39e4.5 KB
    Loading...
  5. 2026-08-22Upload README.md with huggingface_hubd7049004.4 KB
    Loading...
  6. 2026-08-21Upload README.md with huggingface_hub5eaa3804.2 KB
    Loading...

Discussions 1 thread

  1. 2026-08-31first attempt...open1 💬#1
    Loading...
Catalog is the map. Apps are the tools.

Run models on your own machine, not in the cloud.

Every model page has an "Open in Abliteration" button that hands the model directly to the first-party desktop client, at the quantization your rig can actually run. No API keys, no subscription, no prompt leakage.

Open in Abliteration