license: mit
language:
- en
base_model: - deepreinforce-ai/Ornith-1.0-9B
pipeline_tag: text-generation
tags: - ornith
- abliterated
- uncensored
- gguf

Ornith-9B Uncensored
A refusal-ablated build of Ornith-1.0-9B (dense hybrid). The safety refusal direction is removed with a rank-1 weight edit, so the model answers directly, with a small and measured cost to capability.
Uncensored. Small footprint. Honest numbers.
| Base | Ornith-1.0-9B (dense hybrid) |
| Method | rank-1 refusal-direction projection (plain), MLP down-projection only |
| Refusal rate | 2% residual on the harmful-prompt probe set (base refuses most) |
| Capability | GSM8K 87.0% vs base 89.5% (2.5pp cost) |
| KL vs base | 0.070 on clean WikiText |
| Format | GGUF (llama.cpp), Q8_0 |
What this is
Ornith-9B is a compact, capable model. This build removes most of its refusal behavior by projecting out the single direction most responsible for it, in the MLP down-projections. Nothing is retrained.
Two honest notes up front:
- Residual refusal is 2%, not 0. A small number of hard-refusal prompts still trigger a refusal. This is the tradeoff for keeping the edit conservative and the model coherent.
- Capability cost on GSM8K is 2.5 points. Measurable, small, and shown below rather than hidden.
If you want the cleanest capability retention in the fleet, the 35B build has it (no measurable loss). The 9B is the small, fast option with an honest, modest tradeoff.
Capability, measured
GSM8K (5-shot, same harness for base and edited, thinking disabled for a clean comparison):

| Model | GSM8K (base) | GSM8K (abliterated) | Change |
|---|---|---|---|
| Ornith-9B | 89.5% | 87.0% | -2.5pp |
| Ornith-35B | 94.0% | 96.0% | +2.0pp (noise) |
How it compares to other abliterations

Same base, same benchmark, same harness. Ours is competitive with the best public 9B abliteration and far ahead of the weakest:
| Build | GSM8K | Note |
|---|---|---|
| base | 89.5% | reference |
| yuyu | 88.5% | best public retention |
| Ornith-9B Uncensored (this) | 87.0% | within 1.5pp of yuyu |
| jim4 | 69.0% | heavy capability loss |
How surgical the edit is
We track disturbance to normal behavior with KL divergence against the base model on clean text. This build sits at KL 0.070 on held-out WikiText. Higher than the 35B (0.036), lower is better, and it reflects the honest 9B tradeoff: a compact model has less redundancy to absorb the edit cleanly.
Files
GGUF quants (llama.cpp). Sizes are approximate.
| Quant | Size | Notes |
|---|---|---|
| Q8_0 | ~9.5 GB | reference quality |
Usage
llama-server -m Ornith-1.0-9B-abliterated-SatGeZe-Q8_0.gguf -ngl 99 -c 8192
Then point any OpenAI-compatible client at http://localhost:8080/v1.
Context
Native context is supported directly. Extended context to 1M tokens is available via YaRN scaling at load time. Extension past native length is extrapolation, so verify behavior at the far end for your task.
Method
A single rank-1 projection, kept small and measured. No retraining.
- Direction discovery. Collect activations on matched harmful/harmless prompt pairs (identical structure, differing only in intent) so the direction is refusal, not topic or language. Difference of means per layer, normalized.
- Rank-1 removal. Project it out of the MLP down-projection weights with
W' = W - s·(W·r)·r, plain mode, scale s = 1.4. On this dense model that is 60 tensors. - Honest scale. A compact model has less redundancy to absorb the edit, so it sits at a higher KL 0.070 than the 35B (0.036) and keeps a 2% residual refusal. We chose to stop there rather than push scale higher and risk coherence. That tradeoff is stated, not hidden.
- Convert and quantize. BF16 source →
--no-mtpf16 GGUF → Q8_0 GGUF. - Verify on a real-world gate. Checked for language code-switching, output integrity (no loops, blanks, truncated code), and engagement on hard prompts, not just a refusal count.
Credits
Base model: Ornith-1.0-9B by DeepReinforce. Abliteration and packaging by satgeze.
Note
This model will answer requests that the base model refuses (with a small residual). It has no additional guardrails. You are responsible for how you use it and for complying with the laws that apply to you.